Fursah policies

Responsible AI Policy

Version 2.0 · Effective 19 August 2026 · Last updated 19 August 2026

Fursah produces automated readiness scores and candidate–role match rankings that influence education and employment decisions. This policy states how those systems work, what they may and may not be used for, how they are monitored, and how you contest a result. It is written against SDAIA's Principles and Controls of AI Ethics and treats employment-facing AI as high-risk.

ITU-T Y.3172 clause 8.1 · pipeline node

Governing documents shown beneath each node

  1. SRC

    Source

    Evidence documents, employer role requirements, university offerings

    PDPL · NDMO data classification

  2. C

    Collector

    Role-scoped ingestion through APIs, identity federation and institutional integration

    NCA ECC & CCC · DGA interoperability

  3. PP

    Preprocessor

    Extraction, normalisation to the skill taxonomy, consent enforcement

    PDPL data minimisation · DPIA

  4. M

    Model

    Deterministic scoring engine + grounded language model

    SDAIA AI Ethics · ISO/IEC 42001 & 23894

  5. P

    Policy

    Consent rules, review thresholds, suppression floor, and the human override that binds M

    SDAIA human oversight · PDPL rights

  6. D

    Distributor

    Releases each result only to the role authorised to receive it; aggregates suppressed below 5 students

    National Data Governance · cloud hosting rules

  7. SINK

    Sink

    Student, employer, university and policy interfaces

    DGA accessibility (WCAG 2.1 AA) · Arabic-first

Human review carried by the P node overrides any output of the M node, and the override is logged.

Node names and their order are those defined in ITU-T Y.3172 clause 8.1; the text beneath each names what Fursah runs at that node and the policy governing it. The M node is split: the deterministic engine produces every score that affects a person, and the language model only reads documents and explains results. It never ranks anyone.

1. Risk classification

We classify Fursah as a high-risk AI system. It supports decisions about access to employment and to education pathways, which is the category treated as high-risk both under SDAIA's four-tier risk classification and, internationally, under Annex III of the EU AI Act.

We adopt that classification voluntarily and hold ourselves to the obligations attached to it: documented risk management, human oversight, transparency to the affected person, record-keeping, and continuous monitoring. We do not rely on the platform's prototype status to claim a lower tier.

2. What the system actually is

Honesty about the mechanism is part of explainability, so we state it plainly. Fursah has two distinct components, and the boundary between them is the most important design decision in the platform.

Every score about a person uses deterministic rules with published weights. This includes the Career Readiness Score, gap analysis, and candidate-to-role match. These scores do not use a machine-learning model trained on past hiring decisions.

This is a deliberate architectural choice. A model trained on past hiring outcomes learns past hiring preference, including its inequities. A weighted rule engine cannot silently acquire a bias from history, because it has no history to learn from; its inputs are the skills, certifications, experience, and projects a candidate can evidence, and its weights are visible, versioned, and auditable.

The trade-off is that the engine cannot discover patterns nobody encoded. We accept that limitation in exchange for a system whose every output can be reconstructed and challenged.

2a. Where the language model sits, and where it does not

The platform also uses a general-purpose language model, and we are specific about its role because a vague claim of “AI-powered” would obscure exactly what a reader of this policy needs to know.

The model does two things: it extracts structured details from evidence documents you upload, and it answers questions in the in-platform assistant. It does not compute any score, does not rank candidates, and does not decide whether evidence is accepted.

Both uses are grounded. The model is given facts already produced by the deterministic engine and is instructed to answer only from them; it is not asked to reason about a person from raw data. Its extraction output is a proposal carrying a confidence value and the supporting text, submitted to a human reviewer who accepts or rejects it.

This division is deliberate. Language models are well suited to reading a document and explaining a result, and poorly suited to being the reason a person did or did not get an opportunity. Placing the model on the explanatory side of the boundary keeps every consequential number reconstructible, which is the property the rest of this policy depends on.

The assistant's data access is limited by role before a request leaves our systems. An automated test verifies this boundary. It confirms that a university assistant cannot receive an individual student's record.

Any future introduction of a learned component into scoring itself would require bias auditing and a published impact assessment before deployment.

3. The weights we score on

We publish the weightings rather than describing them in general terms. A Career Readiness Score is composed of:

  • Technical skills matched against the target career track: 35%.
  • Certifications held, counting only those verified: 20%.
  • Relevant experience, measured in months against the track's recommended duration: 20%.
  • Soft skills matched against the track: 15%.
  • Projects evidencing applied work: 10%.

4. How a match score is composed

A candidate–role match score is composed of required skills at 55%, required certifications at 25%, and experience against the role's stated minimum at 20%. Within the skills component, requirements the employer marked essential carry 80% and preferred requirements 20%, so a candidate is not penalised for lacking a nice-to-have as though it were a prerequisite.

Scores are banded for interpretation: 80 and above is presented as Career Ready, 55 to 79 as Developing, and below 55 as Early Stage. A band is a description of evidence on file, never a statement about a person's ability or worth.

5. Every result carries its reasoning

No score is displayed without an accompanying explanation. A Reasoning Card names which required skills were matched and which were missing, which certifications are absent, and how many months of experience separate the candidate from the stated minimum.

Explanation is generated as part of scoring rather than reconstructed afterwards. This matters: a post-hoc rationalisation can be plausible and still not be the actual reason for the output. Because the engine is rule-based, the explanation and the computation are the same object.

Consequential actions are written to an audit log recording the actor, the action, the entity affected, the version of the model or ruleset applied, and the explanation given at the time. This is what makes a past decision reviewable rather than merely remembered.

6. Human oversight, and what would defeat it

Fursah is decision-support. Its outputs are advisory inputs to a decision an accountable person makes. No student is rejected, shortlisted, or graded by the platform alone.

We recognise the most likely quiet failure of this design: human review that has become a rubber stamp. A reviewer who approves every recommendation provides oversight in name only, and the system then makes consequential decisions while appearing not to.

We therefore treat override and disagreement rates as monitored indicators rather than incidental statistics. An anomalously low override rate is investigated as a warning sign, not welcomed as agreement. Reviewers are trained to read a Reasoning Card as something to interrogate, not as reassurance that the answer is already correct.

7. Your right to contest a result

You may challenge any automated output that affects you, and you do not need to show that it is wrong before you are entitled to a review. Four categories can be appealed: a readiness score, a job match, an evidence decision, and a data use or correction.

An appeal goes to a human reviewer, whose decision overrides the model's output. The outcome is recorded with the reviewer's identity, the resolution reached, and the time it was made.

Where a review reveals that the engine handled a legitimate form of evidence badly, the correction is fed back into the taxonomy and the rules, so that the next candidate in the same position is not failed the same way.

8. Fairness

Protected characteristics are excluded from ranking inputs. As set out in the Privacy Policy, they are not collected at all, which is a stronger guarantee than excluding them at scoring time.

Excluding an attribute does not exclude a proxy for it. Institution name, region, and career interruption can all stand in for characteristics we never collect. We therefore monitor outcomes for uneven impact across institution and region, and treat a disparity we cannot explain by evidence of skill as a defect in the system rather than a fact about the candidates.

Employers may enable blind review on an opportunity, which withholds identifying details from the reviewer at the screening stage.

A low score means the evidence on file is incomplete, and the interface is required to say so in those terms. A candidate who is self-taught, who trained through a bootcamp, or who is returning after an interruption may hold real competence the pipeline was not built to read. Alternative evidence (portfolio, practical assessment, employer attestation) feeds the same taxonomy for exactly this reason.

9. Monitoring

The platform records monitoring snapshots against each model version, capturing sample size, average score, realised outcome rate, score drift, and outcome drift, and assigns a status of healthy, watch, paused, or insufficient data.

Drift is measured against realised employment outcomes, not against the system's own past predictions, because a model can be perfectly consistent with itself and steadily further from reality. Where safeguards fail, the correct response is to pause or roll back the ruleset, and the monitoring model carries a paused state so that this is an available action rather than a hypothetical one.

10. Separation of commercial interest from ranking

This clause binds us in advance, before there is any commercial pressure to reason around it.

Ranking is never for sale. Fursah will not accept payment from an employer for improved visibility within match results, and will not accept payment from a training provider for placement inside a student's gap analysis or roadmap.

Should sponsored content ever appear on the platform, it must be labelled as such, must be visually distinct from evidence-based recommendations, and must be excluded from the match computation entirely. Because a Reasoning Card must disclose every input that produced a recommendation, a commercial input could not be introduced quietly; it would either appear in the explanation or make the explanation false.

Breach of this clause triggers suspension of the commercial feature and remediation under this policy.

11. Prohibited uses

The following are prohibited on Fursah, by us and by any institution using it:

  • Using a readiness score or match score as the sole basis for rejecting a candidate or denying access to a programme.
  • Using inferred signals (readiness weaknesses, gap patterns, socioeconomic or accessibility proxies) for advertising, for targeting, or for any form of profiling unrelated to the purpose for which the data was given.
  • Disclosing platform data to a third party for advertising or profiling, under any commercial arrangement.
  • Re-identifying individuals from aggregate institutional reporting, or combining aggregates to defeat the suppression threshold.
  • Presenting a score to a candidate without its accompanying explanation.
  • Using the platform to rank candidates on any attribute this policy and the Privacy Policy exclude.

12. Escalation

Where a breach of this policy involves personal data or a discriminatory outcome, our response is not limited to internal correction. We will suspend the offending feature, notify affected individuals through the platform, revoke any third-party data sharing involved, and refer the matter to SDAIA and to the relevant sector regulator where the breach warrants it.

Individuals affected retain, at all times and independently of anything we do, the right to withdraw consent and to request deletion of their data through their own privacy controls.

13. Governance and review

This policy is reviewed at least annually and whenever the scoring logic, weights, or data inputs change materially. The specific figures published in clauses 3 and 4 are versioned with the engine, so that a score computed last quarter can be interpreted against the rules that actually produced it.

Governance scenarios raised against the platform are recorded with the risk level, the issues detected, the action proposed, and the human decision reached, including where a human overrode the proposed action, since an oversight mechanism that never disagrees is not evidence of oversight.

Supporting documentation

The full technical and governance report behind this policy. It maps every stage of the Fursah pipeline (sources, connectivity, pre-processing, models, human oversight, analytics, and interfaces) to SDAIA's Principles and Controls of AI Ethics, the PDPL, national data-governance standards, and the Human Capability Development Programme, and works through the scenarios in which the system could be contested.

AI Readiness Report (PDF)