+41 pts
Audit precision
SAR 2.1B
Incremental recovery
12
Risk models in production
100%
Explainability coverage
Client
KSA Zakat, Tax & Customs Authority
Sector
Government
Duration
11 months
Team
34 specialists
01 · The challenge

Problem

Tax audit selection was rules-based and labour-intensive. Audit precision at 28%, meaning 72% of audits returned negligible adjustments. Filer behaviour was not measurable.

02 · How we delivered

Solution

AI tax compliance scoring platform with behavioural risk models, audit prioritisation, and explainable scoring for the auditor. Privacy-preserving design aligned to data sovereignty rules.

03 · Outcome

Impact

Audit selection precision up 41 percentage points. Filer behaviour change measurable cohort-by-cohort. SAR 2.1B of incremental recovery in year one.

How we delivered

Programme phases.

Five phases. One accountable team. Every phase had a named decision point and a measurable outcome.

Discovery & alignment

2–3 weeks

Workshops with the KSA Zakat, Tax & Customs Authority executive team, baseline metrics, target outcome tree, programme governance set up.

Design & architecture

4–6 weeks

Reference architecture, security blueprint, joint squad model agreed. Data model and integration contracts published.

Build & live-parallel

Q2 onwards

Vertical slice built and run live-parallel against the existing system. Continuous integration, daily deploys, weekly business demos.

Cutover & scale

Mid-programme

Phased cutover, audit-aligned reconciliation, scaling out of squads, capability transfer to KSA Zakat, Tax & Customs Authority teams.

Run & continuous improve

Steady state

Managed run with named SLOs, quarterly value reviews, and a 15% optimisation budget reserved for improvement work.

Engineering view

Architecture overview.

Foundations

Cloud landing zone, identity, network, security baseline. Data fabric with lineage-by-default. Audit-grade observability stack from day one.

Application & integration

Domain-aligned microservices behind a published API surface. Event-driven core with CDC into the data fabric. Live-parallel capability built in, not bolted on.

Trust & governance

RBAC, audit logs, lineage, policy-as-code. Model risk records for every production model. Compliance posture on the executive dashboard, not in a quarterly slide.

Built on

Technology stack.

Production-grade choices, defended by track record. The stack is one engineering decision among many — but a load-bearing one.

Sovereign Cloud Snowflake MLflow XGBoost Anthropic Claude Power BI
Trust by design

Governance & assurance.

01

Programme assurance

Independent assurance reviews at each phase gate. Findings tracked in a single risk register with named owners and remediation deadlines.

02

Security & data

ISO 27001, SOC 2 Type II controls applied throughout. Data lineage captured by default; sensitive data tokenised at the edge.

03

NESA / sovereign cloud

Deployment aligned to national cybersecurity authority controls. Sovereign cloud where data residency requires it.

04

Accessibility & inclusion

WCAG-AA on every citizen-facing journey. Arabic-first design with parallel English; user-research panels include accessibility users.

Targeted audits, fewer audits, more recovery. The platform paid for itself in 3 months.

D Deputy Governor · the Authority

What we learnt

Three things we would do again.

  1. 01

    11 months from kickoff to first regulated outcome — squad density and decision velocity matter more than headcount.

  2. 02

    Joint squads with KSA Zakat, Tax & Customs Authority engineers stayed in place after go-live. Ownership did not transfer in a hand-off — it grew in place.

  3. 03

    Live-parallel for a meaningful window before cutover bought us trust. The cutover itself was a flag flip, not a war room.

Book the partner

Want a programme like this one?

Tell us your sector and your timeline. A senior partner with sector experience will respond within one business day.