Governance · Analytics · Commercial assessment · AI engineering

rami elshafei

Technology governance, analytics, commercial assessment and AI platform engineering

Nineteen years in technology and telecom. I work where three questions meet: is this defensible to an auditor and a regulator, is it worth the capital, and can it actually be built and run? Most organisations answer those in three separate rooms. I answer them together.

2007Nineteen years, three chapters2026

Operations, systems analysis, technical resolutionTelecom · 2007–2018

Digital business consultingConsulting · 2018–2019

Products & projects control and planning2019 – present

The value I bring

it holds up

Governance, risk and compliance designed so the answer survives inspection — by an auditor, a regulator, or a customer's security team.

it pays

A clear read on whether a product, platform or target earns its capital: value proposition, margin, cost to serve, and a recommendation with a number attached.

it gets built

Workflow automation, approval engines, assessment tooling and AI platforms — engineered, not specified and outsourced.

it gets decided

Complexity compressed into something an executive can act on in one page, on a cycle that repeats without being rebuilt each time.

§ 01

about me

I am a technology governance and control professional based in Riyadh, with nineteen years across telecom operations, digital business consulting, and products and projects control. My work is about making sure that what an organisation builds is defensible, that what it funds is worth funding, and that the two conversations inform each other instead of running in parallel.

Two master's degrees frame how I think: one in cybersecurity, one in project management. That pairing is deliberate. Most failures in a technology portfolio are not purely technical or purely managerial — they sit in the seam between the two. Risk assessed but never designed against. A control agreed but never evidenced. A delivery plan that ignores what compliance will cost. I work that seam.

Three things set this apart from a governance role on its own. Commercial judgement — I can tell you what a product, platform or supplier is actually worth and where capital is better spent. Engineering — I build the systems rather than specify them and wait: automation, approval engines, assessment tooling, platforms with their own data model and interface. AI as an owned capability — designed, governed, deployed and operated, not bought as a demo and abandoned.

What that adds up to for an organisation: one person who can say whether the thing is defensible, whether it is worth the money, and then build the workflow that runs it.

§ 02

what i can do

Twelve areas of practice. They overlap by design — a governance decision usually becomes a process change, a dashboard, an automation and a cost line at the same time.

01

governance, risk & compliance

Design and run GRC programmes aligned to organisational goals: policy, control frameworks, internal audit, external audit coordination, and compliance carried through its full renewal cycle.

02

cybersecurity & data protection

Build security requirements into products before launch. Run assessments and audits that surface real exposure. Master's-level grounding, backed by security management and ethical hacking certification.

03

project & product control

Hold discipline on scope, budget and timeline. Run product onboarding and change management with genuine impact assessment and a defined approval path.

04

commercial & investment assessment

Assess product and portfolio value, define the value proposition, compare options on the same basis, and make investment recommendations backed by margin, cost to serve and risk.

05

acquisition & vendor due diligence

Evaluate a target or supplier across commercial, technical, security and compliance dimensions — what is being bought, what liability comes with it, what integration will really cost.

06

financial & delivery performance

Budget management, procurement optimisation and resource allocation, tied to a measured view of what delivery is actually costing and returning.

07

ai platform engineering

Full-stack AI systems: architecture, routing, retrieval over private knowledge, interface, monitoring and governance. Built and operated, not procured and hoped for.

08

workflow automation & approval engines

Approval routing, evaluation workflows, action history and audit trail — designed as data models and shipped as working software.

09

infrastructure & server administration

Provisioning, configuration, hardening, access control, monitoring and uptime across virtualised Linux hosts and containerised services.

10

bi, dashboards & reporting

Turn scattered delivery and performance data into real-time visibility and executive reporting that leads to a decision rather than a discussion.

11

process excellence

Process redesign, responsibility mapping and improvement programmes — turning recurring friction into something documented, owned and measured.

12

continuity & crisis readiness

Continuity and disaster recovery plans developed and actually exercised, so the plan is tested before the day it is needed.

13

business intelligence & dashboards

Interactive dashboards in Power BI, Tableau and MicroStrategy — with role-based access and row-level security, so each audience sees exactly the data it is entitled to and nothing more.

14

advanced & predictive analytics

Python and R for trend analysis, forecasting, segmentation, anomaly detection and pattern discovery across large datasets — including customer experience and behaviour.

§ 03

ai engineering

Not "uses AI." Builds with it, builds systems around it, and governs the result — architecture, routing, retrieval, interface, approval logic, monitoring, and the security and data-protection case that lets it near real work.

Stage 01

frame

The problem, the users, the data it may touch, and what "done" looks like — settled before anything is built.

Stage 02

brief

A build brief precise enough to hold: scope, phased delivery, acceptance criteria, and a specification the implementation cannot drift from.

Stage 03

build

Infrastructure, routing layer, knowledge base, data model and interface — iterated against the brief rather than against impressions.

Stage 04

govern

Security review, data-protection assessment and a defined approval path before the system touches real work.

Stage 05

operate

Monitoring, access control, uptime, cost and provider fallback. An unmonitored AI system is an unowned one.

Stage 06

improve

Measure where it saves time and where it fails, revise, and fold the change back into the documented process.

Build · platforms

engines and platforms

End-to-end systems, from bare virtual machine to a working interface someone can open.

  • Full-stack capability. Infrastructure, service layer, data model, application logic and front end — carried by one person rather than handed across three teams and a vendor.
  • Self-hosted AI infrastructure. AI services on virtualised Linux with containerised deployment, so sensitive material stays inside infrastructure the organisation controls.
  • Multi-provider routing. A routing layer not tied to one supplier, keeping cost, availability and data-handling under the buyer's control rather than the vendor's.
  • Retrieval over private knowledge. Retrieval-augmented design so a system answers from a governed internal corpus rather than general training data.
  • Working prototypes. Functional prototypes with real data structures, so decisions get made against something that runs rather than a slide.

Build · automation

workflow automation

The value is not the model. It is the process the model lets you redesign, and the manual step it lets you delete.

  • Reporting pipelines. Multi-source data taken through to finished spreadsheet, deck and dashboard deliverables on a repeatable cycle instead of manual assembly each period.
  • Programmatic documents. Word, Excel and PowerPoint outputs generated from code — reproducible, version-controlled, identical every run.
  • Data matching at volume. Systematic comparison across large datasets, at volumes that are not reviewable by hand.
  • Bilingual pipelines. English and Arabic working documents handled in one flow, without a separate translation stage.
  • Upstream data design. Structured fields specified into source systems so the automation downstream has something reliable to read.

Build · approval & evaluation

workflow approval engines

Approval is where governance either works or quietly stops working. It should be designed as software, with a data model and an audit trail.

  • Evaluation workflows. Staged assessment pipelines with scoring and reviewer routing, built on a schema that extends existing records rather than duplicating them.
  • Approval traceability. Who approved what, and when, available as a queryable field rather than an email search.
  • Multi-party routing. Approval paths across owners, reviewers and sign-off authorities, with responsibility boundaries made explicit in the system itself.
  • Identity and access design. Directory synchronisation and access governance so the approval chain reflects the real organisation.

Build · security assessment

security assessment automation

Assessment that runs on a schedule beats assessment that runs when someone remembers.

  • Host assessment tooling. Cross-platform audit scripts that check a machine's security configuration and render findings as a readable dashboard.
  • Control mapping. Technical findings mapped to the standards that govern them, so a scan result becomes a compliance position rather than a list.
  • Live compliance dashboards. Status you can look at today, replacing status decks assembled last month.
  • Exposure review. Product-level security assessment feeding directly into onboarding and change decisions rather than sitting in a parallel report.

Govern · adoption in regulated environments

making ai deployable, not permanently piloted

In a regulated organisation, an AI system is a control surface. Treating it like one is the difference between deployment and an indefinite pilot.

  • Adoption governance. Define the security posture, the data-protection position and the approval path an AI initiative must clear before it touches real work — and get stakeholders through it.
  • Specification discipline. Write build specifications precise enough to act as a delivery contract, so scope, phasing and structure hold under pressure.
  • Data-handling boundaries. Self-hosting is a compliance decision before it is a technical one: it keeps sensitive and regulated material inside controlled infrastructure, which is what makes the case to a regulator work.
  • No carve-outs. Assess AI initiatives against the same standards as everything else, rather than exempting them as experimental.
  • Honest evaluation. Agentic and automated tooling tested across environments, with a clear view of where it holds up and where it does not.
  • Virtualisation
  • Linux
  • Containers
  • Retrieval-augmented generation
  • Multi-provider routing
  • Python
  • PowerShell
  • Bash
  • Schema design
  • BI & dashboards
  • Prompt engineering
§ 04

data, dashboards & analytics

A dashboard is not a picture of the data. It is a decision surface — and it is only trustworthy if the numbers reconcile, the access is controlled, and someone can tell you why the line moved.

Build · business intelligence

interactive dashboards

Built in the platform the organisation already runs, not a tool nobody will maintain after I leave.

  • Power BI. Semantic models, DAX measures, incremental refresh, drill-through and paginated reporting for the versions that have to be sent rather than opened.
  • Tableau. Exploratory and executive views, calculated fields, level-of-detail expressions and dashboard actions that let a reader interrogate a number instead of accepting it.
  • MicroStrategy. Enterprise-scale reporting on a governed metric layer, so a definition means the same thing in every dossier that uses it.
  • One definition, one number. A shared metric layer above the reports, so finance, delivery and operations stop arriving at three different answers to the same question.
  • Built to be handed over. Documented models, named measures and a refresh schedule — a dashboard someone else can own.

Govern · access & security

role-based access and security levels

Reporting is where data exposure usually happens. Access is designed into the model, not bolted on at the report.

  • Role-based access control. Access defined by role against the organisation chart, not by who asked, and reviewed on a cycle rather than accumulated.
  • Row-level and object-level security. A manager sees their own portfolio; a director sees the roll-up; a finance reviewer sees cost but not names. One report, many entitlements.
  • Data classification tiers. Confidential, internal and open views separated at the model layer so a screenshot cannot leak what the viewer was never entitled to see.
  • Traceable access. Who opened what, and when — available as evidence when an auditor asks, rather than reconstructed afterwards.
  • Least privilege by default. New users get the narrowest view that lets them do their job, and escalation is a request with an owner.

Engineer · large-scale data

big data and pipelines

Volume changes the method. What works on a spreadsheet stops working three orders of magnitude later.

  • Ingestion and modelling. Multi-source extraction, staging and dimensional modelling, so analysis runs against a stable structure instead of a fresh export each time.
  • Reconciliation at volume. Composite-key matching across large datasets to find where two systems that should agree do not — at row counts nobody reviews by eye.
  • Data quality gates. Completeness, validity and duplication checks that run before the numbers reach a dashboard, not after someone questions them.
  • Automated refresh. Scheduled pipelines with failure alerting, so a stale report announces itself rather than quietly misleading the reader.
  • Upstream field design. Structured fields specified into the source systems, because the cheapest way to fix analytics is to fix what gets captured.

Analyse · advanced methods

advanced analytics with python and r

Where a dashboard shows what happened, this answers why, and what is likely next.

  • Trend and time series. Decomposition, seasonality, moving baselines and forecasting with stated confidence — a projection, not a guess dressed as a number.
  • Pattern and anomaly detection. Outliers, drift and clustering to surface what nobody thought to filter for.
  • Segmentation and cohorts. Grouping by behaviour rather than by org chart, then tracking each cohort over its own lifecycle.
  • Driver analysis. Correlation, regression and significance testing to separate what actually moves a metric from what merely moves alongside it.
  • Python and R. pandas and NumPy for shaping, statistical libraries for testing, and reproducible notebooks so a result can be re-run rather than re-argued.

Apply · customer experience

customer experience analytics

Satisfaction scores tell you the temperature. The analysis has to tell you what to change.

  • Journey analysis. Where in the lifecycle experience actually degrades — onboarding, delivery, support or renewal — measured rather than assumed from the loudest complaint.
  • Driver identification. Which operational variables move satisfaction, so improvement effort goes where it changes the score instead of where it is easiest.
  • Churn and retention indicators. Early-warning signals built from behaviour, escalation and service history, surfaced while there is still time to act.
  • Feedback at volume. Survey, ticket and complaint text grouped into themes across English and Arabic, turning thousands of comments into a ranked list of fixable issues.
  • Closing the loop. Findings written back into process and product change, then re-measured — so an insight becomes a fix rather than a slide.
  • Power BI
  • Tableau
  • MicroStrategy
  • DAX
  • SQL
  • Python
  • pandas
  • NumPy
  • R
  • Row-level security
  • RBAC
  • Dimensional modelling
  • Forecasting
  • Segmentation
  • Anomaly detection
§ 05

commercial & investment assessment

A consulting discipline applied inside the operating business: what is this product, platform or target actually worth, what does it cost to run, what liability comes attached, and should capital go into it or somewhere else?

Assess · product & portfolio

product and portfolio value

Every product in a portfolio is either earning its place or being carried. The job is to know which, with evidence.

  • Value proposition. What the product does for the customer, for whom, and why they would buy it here — stated in one page, not inferred from a feature list.
  • Revenue model and margin. How money arrives, how reliably, and what is left after cost to serve. Recurring versus one-off, and what the mix does to forecast quality.
  • Cost to serve. Delivery, support, infrastructure, licensing and the compliance overhead the product carries — the line most often missing from a business case.
  • Profitability where it is actionable. Measured at the level someone can do something about, not aggregated until it stops being decision-useful.
  • Portfolio comparison. The same scoring model across products, so the ranking holds when a favourite comes out low.
Assess · acquisition & counterparty

acquisition and vendor due diligence

What is being bought is rarely just the asset. It is also the exposure and the integration bill.

  • Commercial position. Revenue quality, customer concentration, contract terms, and how much value survives the transaction.
  • Technical due diligence. Architecture, technical debt, dependency risk, and the real cost of integrating with what is already in place.
  • Security and compliance exposure. What the target can evidence, what it cannot, and what it takes to bring it inside the acquirer's control environment.
  • Regulatory and data liability. Where data sits, under whose jurisdiction, and what obligations transfer with it.
  • Integration and exit. What it costs to absorb, what it costs to unwind, and whether continuity survives either.

How I score an evaluation

RefDimensionThe question it answers
D-01strategic fitDoes this belong in the portfolio at all, or is it adjacent activity competing for the same capital?
D-02value propositionWhat does the customer actually get, and why buy it here?
D-03revenue & marginHow does money arrive, how reliably, and what is left after cost?
D-04cost to serveWhat does it consume in delivery, support, infrastructure and licensing?
D-05billing integrityDoes what is delivered match what is charged?
D-06compliance exposureWhat regulatory and certification obligations does it create or inherit?
D-07security postureWhat is the residual risk after controls, and who carries it?
D-08integration costWhat does it take to connect this to what already exists?
D-09delivery readinessCan the organisation actually run it — people, process, tooling?
D-10continuity & exitWhat happens if it fails, or if we need to leave?

Same dimensions, same weighting, every candidate — which is what makes a comparison a comparison rather than an argument.

invest

The case holds across all ten dimensions. Fund it, and name the metric it will be judged on.

invest with conditions

Commercially sound, but one or more dimensions carry unresolved risk. Fund against explicit remediation gates.

defer

The evidence is not there yet. Name what would have to be true, and what it costs to find out.

divest or exit

It is being carried. Stop, migrate, or hand it to someone whose portfolio it fits.

§ 06

ventures

Independent platform work, built outside the day job. Product decisions, architecture, data model and go-live — the same discipline applied where I am the one carrying the risk.

Venture 01 · live

3limak — arabic learning platform

An Arabic-language learning marketplace: instructor-led courses, downloadable digital files, and printed titles, with a trainer onboarding path so subject-matter experts can publish and teach.

  • Two-sided marketplace. Learners on one side, accredited trainers on the other, with applications, catalogue, cart and checkout in between.
  • Mixed catalogue. Live and recorded courses alongside digital products — PDF, spreadsheet and dashboard templates — and physical books, each with its own fulfilment path.
  • Bilingual by design. Arabic-first interface and content, which is a data-model decision as much as a translation one.
  • Ratings and feedback. Separate scores for course content, trainer and platform, so a weak module does not get hidden behind a strong instructor.
  • Marketplace
  • E-commerce
  • Arabic UX
  • Content platform

3limak.com  →

Venture 02 · in development

maziktk

A second platform under development. Not yet launched — details and a link will go here once it is ready to be seen.

  • Status. Pre-launch. The domain currently resolves to a placeholder.
  • Why it is listed anyway. Because building and shipping a product end to end is the point, and there will be two of them.
  • In build
§ 07

what i deliver

Concrete outputs, not activity. Each one is something an organisation can use, defend or act on.

Output 01

governance & compliance programme

A control environment mapped to the standards that apply, with owners, evidence requirements and a renewal calendar — designed to be maintained, not rebuilt each audit cycle.

Output 02

audit readiness

Preparation that treats the audit as predictable: evidence organised in advance, control gaps identified early, and a defined response and closure process.

Output 03

investment assessment

A scored evaluation of a product, platform, supplier or target across ten dimensions, ending in one of four recommendations with the reasoning attached.

Output 04

business case & value proposition

The commercial argument written so it survives challenge: what is proposed, what it returns, what it costs to serve, and what would make it wrong.

Output 05

operating model & process redesign

Process maps, responsibility boundaries and approval paths that reflect how work actually flows — then the automation that removes the manual steps.

Output 06

executive reporting system

Dashboards and reporting cycles that produce the same view every period without manual assembly, sized for a decision rather than a status meeting.

Output 07

ai adoption framework

The security, data-protection and approval position an organisation needs before AI touches real work — plus the pilot that proves it in practice.

Output 08

automation & approval systems

Working software: routing, evaluation workflows, audit trails and generated documents, built against a data model rather than bolted onto spreadsheets.

Output 09

continuity & recovery programme

Plans that have been exercised, with the gaps the exercise revealed already closed.

Output 10

dashboard & reporting estate

Interactive dashboards on a governed metric layer with a role-based access model, documented so someone else can own them.

Output 11

analytics study

A question answered with evidence: trend, drivers, segments and a forecast with its confidence stated — plus what would change the conclusion.

Output 12

customer experience review

Where experience degrades across the journey, what moves the score, and the ranked list of fixes worth funding first.

§ 08

where i fit

The mandates this background is built for — permanent, interim or advisory.

head of governance, risk & compliance

Own the control environment end to end: frameworks, internal audit, external audit, compliance programmes, and the reporting line into the executive.

head of pmo / portfolio control

Bring discipline to a portfolio that has outgrown its governance — scope, budget, timeline, change control, and reporting executives actually read.

product governance lead

Sit between product, security and compliance: onboarding standards, risk assessment, change management and the approval path that keeps launches moving.

investment & portfolio assessment lead

Evaluate where technology capital goes: product value, build-versus-buy, supplier selection, and diligence on targets.

ai governance & adoption lead

Get AI from pilot to production in a regulated organisation — the security and data-protection case, the approval path, and the first systems that clear it.

technology transformation consultant

Diagnose, model and redesign: operating model, process, controls and reporting, delivered as something implemented rather than recommended.

chief of staff, technology

Translate strategy into measures, keep the reporting honest, and give a technology leader one place where delivery, cost and compliance are reconciled.

head of bi & analytics

Own the reporting estate: platform choice, the metric layer, access model, and the shift from descriptive dashboards to analysis that anticipates.

advisory & assessment engagements

Defined-scope work: a compliance readiness review, an investment assessment, an AI adoption framework, or an automation build.

§ 09

toolkit

Categories of system I work in and across. Fluency here is what makes an assessment specific instead of theoretical.

Enterprise systems

  • ERP and finance systems
  • CRM and order management
  • Project & portfolio management
  • IT service management
  • Workflow and approval platforms
  • Document and policy management

Governance & risk

  • GRC platforms
  • Risk and issue registers
  • Internal audit tooling
  • Process modelling and RACI
  • Continuity and DR planning
  • Customer feedback systems

Engineering & AI

  • Virtualisation & Linux administration
  • Containerised deployment
  • Multi-provider AI routing
  • Retrieval-augmented generation
  • Python, PowerShell & Bash
  • Schema and data model design
  • BI & dashboard automation

BI & analytics

  • Power BI & DAX
  • Tableau
  • MicroStrategy
  • SQL & dimensional modelling
  • Python — pandas, NumPy
  • R — statistics & forecasting
  • Row-level & role-based security

Network foundations

  • Broadband access technologies
  • Fibre to the home
  • Next-generation networks
  • IP networking
  • IPTV
  • Field diagnostics at national scale
§ 10

experience

Operations, then consulting, then control. Each move traded breadth of hands-on work for depth of accountability — without giving up the hands-on part.

2019 — PresentRiyadh

chief specialist — products & projects control and planning

Technology division, enterprise solutions provider

Accountable for governance, risk and compliance across project and product control, alongside strategic alignment, operational efficiency, and the financial and delivery performance of what the division ships.

  • Strategy & objectives — translate organisational goals into strategies, measures and actionable plans.
  • Commercial assessment — evaluate product and platform value, margin and cost to serve; assess suppliers; advise on where capital should go.
  • Product governance — onboarding aligned to company, security and regulatory standards, with change management and product risk assessment.
  • Compliance & audit — maintain the certification programme, align internal audit to regulatory standards, and coordinate external audit.
  • AI & automation engineering — design, govern and operate AI platforms, workflow automation, approval engines and assessment tooling.
  • Reporting — BI-driven dashboards for delivery and product performance, and executive reporting into decision-making.
  • Infrastructure — administer the servers and services underpinning the reporting and governance stack.
  • Process excellence — improvement programmes, responsibility mapping and workflow redesign across product lines.
  • Continuity — ensure continuity and disaster recovery plans are developed and tested.
  • Resource & financial control — procurement optimisation, resource allocation and budget management.
  • Capability building — training in product management, project management and cybersecurity.

2018 — 2019Riyadh

senior consultant — digital business consulting

Consulting practice

Consulted on digital business transformation: client delivery, project management, commercial modelling and operational improvement, with governance system implementation running alongside.

  • Planning & revenue management — finalised project plans, optimised records management and managed revenue models.
  • Recommendations & proposals — developed actionable recommendations using structured problem-solving, and contributed to proposal submissions.
  • GRC implementation — integrated risk management, policy documentation and customer feedback systems.
  • Workstream & client management — ran workstreams and client relationships against milestone and satisfaction metrics.
  • Sales & operations — automated e-commerce capability and delivered training to close system gaps.
  • Compliance — managed internal audit processes and maintained certification programmes.
  • Budget oversight — monitored budgets, ensured regulatory compliance, maintained documentation of project activity.

2007 — 2018Kingdom-wide

specialist — systems analyst & technical resolution

National telecom operator

Eleven years across operations and technical support, building the network fluency and operational scale the later governance and assessment work rests on.

  • Operations — led field operations nationally, streamlined administrative processes, and handled people activity including recruitment, promotion and training.
  • Technical support — broadband access, IP, next-generation networks, fibre and IPTV; complex fault resolution and network diagnostics.
  • Monitoring & automation — built dashboards to track service issues and worked with consulting firms to optimise operating models.
  • Security — supported internal audit and participated in security assessments.
  • Financial & resource management — managed budgets, reviewed financial reports, optimised resource allocation.
  • Training — planned and delivered technical training programmes for field staff.
§ 11

credentials

Education

master's — cybersecurity

Midocean University · 2024

master's — project management

 

bsc — information technology

Arab Open University, Riyadh

arabic

Native

english

Professional

Professional certifications

  • PMO Certified Practitioner (PMO-CP)2024
  • PMP — Project Management Professional2020
  • CISM — Certified Information Security Manager2020
  • CEH — Certified Ethical Hacker2020
  • CompTIA Security+2020
  • ITIL Foundations2020
  • Six Sigma2020
  • The Agile Professional2019

Get in touch

let's talk

Roles, advisory work, or a defined-scope assessment. Tell me what you are trying to decide and I will tell you whether I am the right person for it.

  • Based inRiyadh, Saudi Arabia
  • Working languagesArabic and English
  • Open toPermanent, interim and advisory engagements
  • Response timeUsually within two working days

send a message

All fields are required unless marked optional. Your details are used only to reply to you.

Please do not include confidential or personal data in this form.