This is the full framework behind the AI-Native Readiness Scorecard. It explains what the six dimensions measure, why they predict enterprise outcomes for MENA, and gives the specific 90-day action plan for each of the three tiers. Use it as the reference document for your board briefing, your CxO sync, or your next internal quarterly review.
The diagnostic uses twenty questions across six dimensions. Each dimension is weighted to predict one of the things enterprises in KSA and UAE consistently get wrong when they attempt AI-native transformation at scale. Three dimensions measure governance foundations. Three measure execution readiness. Both halves have to be present before an enterprise-scale engagement makes sense.
Is there a named executive owner, a documented AI strategy paper, and a board-minuted mandate? Scored highest when the CEO plus one other C-level has signed off on AI-native as a direction, not just a budget line.
Depth of in-house AI/data talent and the organizational literacy to operate AI-native workflows. Includes whether line managers can distinguish RAG from fine-tuning, not just whether data scientists exist.
Cloud posture, API maturity, identity/SSO, observability, and the specific KSA-region infrastructure questions (data residency via Riyadh regions) that compliance-gate enterprise deployments.
PDPL (KSA) and UAE data protection compliance, DPO designation where the employee-count trigger applies, cross-border transfer policy, and the documented lineage Riyadh auditors request in year-two audits.
Documented sectoral contribution to V2030 pillars, SDAIA alignment, and the board-facing narrative that decides whether MCIT, PIF, or strategic-partner conversations happen in year two, or never.
Is capital allocated and committee-approved, not just "available"? Scored highest when Year-1 opex + capex are already ring-fenced and Year-2 scale budget has a trigger defined in writing.
71-100 · GREEN. Top quartile of MENA enterprises we've assessed in 2025-2026. Governance foundations present, execution readiness strong, board already aligned. Next step is a scoping conversation, not a diagnostic: AI-Native Enterprise Transformation, scoped per engagement, from $65,000.
40-70 · YELLOW. Modal band. 64% of KSA enterprises sit here. Foundation pieces present but specific gaps that close in 6-12 months. Next step is the Revenue Audit: $1,500, one day, which names the best-fit engine and the roadmap, then the build at $16,000 to $28,000 over 8 to 12 weeks.
<40 · RED. Early-stage. Enthusiasm exceeds readiness. Over-investing here compounds risk rather than value. Next step is the AI Audit: $1,500, one day, ranking where AI pays most by value against effort, so the three prerequisites close before any build is bought.
The pattern: board mandate present, designated CxO, KSA-region infrastructure live, PDPL documented, V2030 narrative documented to SDAIA standard, budget committee-approved. You don't need to validate that AI-native is right for you, which is why the $1,500 audit day is the wrong purchase at this score. You need to decide which partner to bet on for the next 18 months, and on what scope.
The 90-day action plan:
Common patterns in this band. Budget allocated but PDPL data-residency gaps create commercial risk · OR · V2030 alignment claimed but not documented to SDAIA standards · OR · strong technical team without clear AI-native mandate from the board · OR · board mandate present but no designated executive owner accountable for outcome.
The 90-day action plan:
The pattern: enthusiasm exceeds readiness. Pilots exist but no mandate. Vendors engaged but no DPO. Budget discussed but not committee-approved. Buying a build before these close compounds risk. The right move is one fixed-price day that ranks where AI actually pays, then the three prerequisites.
The 90-day action plan:
Western AI-readiness frameworks assume Delaware-incorporated, English-speaking, enterprise SaaS-centric organizations. They systematically underweight the three things that decide enterprise outcomes in KSA and UAE: WhatsApp as business spine, Gulf-dialect customer closure, and the compliance layer (PDPL, ZATCA, Saudization, V2030 documentation). They overweight what MENA enterprises already have locked in (cloud adoption, cybersecurity budget, CxO titles).
This framework is calibrated against sixty-plus MENA enterprise assessments run in 2025-2026. The dimension weights, tier cutoffs, and 90-day plans reflect what actually predicts the next twelve months of outcome, not what reads well in a McKinsey deck.
The practical consequence: if you've been told you're "AI-native ready" by a Tier-1 consultancy but you scored YELLOW here, the consultancy is probably grading on the Western frame. The board will find out in year two during the V2030 compliance audit. Better to find out now.
For the YELLOW band, the common path after the audit day is one engine, built as an operating system and transferred. The shape is the same whether it is the B2B Revenue Engine at $28,000 over 12 weeks, the Expert Engine at $16,000 over 8 weeks, a Revenue MicroSaaS at $22,000 over 10 weeks, or a Revenue Operating System at $7,500 per process.
Every price on this page is published in full at smorchestra.ai/pricing, and the $1,500 audit day is credited back against any engagement started within 60 days.
GREEN goes straight to an enterprise scoping conversation. YELLOW and RED start with one audit day at $1,500, the Revenue Audit or the AI Audit, credited in full against any engagement started within 60 days. Both doors are below.
See the audit day → Book 15 minutes →