The decisions our AI is not allowed to make.
Ebra is an AI-first company collecting debt from people under financial pressure. That combination obliges us to be specific about where the software stops. This page is that list — not a disclaimer.
- Version
- 1.0
- In effect from
- 1 August 2026
- Next scheduled review
- 1 February 2027, and on any material model change
- Accountable owner
- Head of Risk & Compliance, Ebra
Superseded versions are kept and available on request. If we change what the AI is permitted to do, this page changes first and the version number moves.
Seven decisions a model never makes at Ebra.
Each of these is taken by a named person with the authority to take it. The model may prepare, summarise, rank or recommend. It cannot conclude. Where a decision is reserved, the system will not execute without a recorded human approval — the approval is a required field, not a convention.
Decision
Who decides
- 1
Whether a dispute is upheld
If you say the debt is not yours, was already paid, or the amount is wrong — the outcome is decided by a case handler who reviews your evidence.
Disputes case handler
- 2
Whether hardship is granted, and on what terms
Affordability outcomes, reduced instalments and payment holidays are human decisions. A model may compute what you can afford; it does not decide what you are offered.
Hardship specialist
- 3
The size of a discount or write-off
Settlement authority sits with the creditor and, within delegated limits, with a human at Ebra. No model has discount authority.
Creditor, or authorised Ebra officer within a written limit
- 4
Whether a file is escalated to legal or enforcement
Referral to legal action is never automated and never triggered by a score.
Legal & Recovery lead, on the creditor's instruction
- 5
What is reported to a credit bureau
Credit-bureau content is a matter of record accuracy and law, not inference. A model does not decide what appears on your credit file.
Operations, under the creditor's reporting obligations
- 6
Whether someone is treated as vulnerable
Software may raise a flag from something you wrote or said. Only a trained person confirms it, and the flag is reviewed rather than acted on automatically.
Customer Care specialist
- 7
Whether to close, suspend or reinstate a file
Including releasing an obligation. A closure is a legal statement about your position and is made by a person.
Operations supervisor
This list is exhaustive as at the version date above, not illustrative. If a decision is not on it, that does not mean a model takes it — it means you should ask us, and we will answer in writing.
Two different technologies, doing two different jobs.
"AI" is usually used to mean one thing. It is two, they carry different risks, and collapsing them is how vague promises get made. So here they are separately.
Orchestration — when, which channel, what next
Machine learning
Statistical models trained on outcomes, deciding the sequence of contact rather than its substance.
Permitted
- Which channel to use, from how you have responded before
- What time of day to send, inside the permitted window
- Which of several approved messages to send
- What the next step in a journey should be
Not permitted
- Score whether you deserve a discount
- Rank you for legal escalation
- Set a price or an instalment amount
Language — drafting, summarising, answering
Large language models
Generative models that produce or interpret text, always inside a boundary a person set.
Permitted
- Draft messages from templates a compliance officer approved
- Answer routine questions with an immediate route to a person
- Summarise a conversation for the handler who picks up your file
- Translate between Arabic and English, and read Saudi dialects
Not permitted
- Write freely to you without a reviewed template behind it
- Decide the outcome of anything on the reserved list
- Negotiate an amount
You can always get a human, and there is a time on it.
An opt-out with no timeframe is not an opt-out. These are the commitments, and they are measured.
If you think a model got something wrong
Tell us and we will have a person re-examine it, explain the basis for the outcome in plain language, and correct it if it is wrong. Verifying our output is our job, not yours.
Ask once, in any channel
Reply to any message with a request to speak to a person — in Arabic or English, in whatever words you use. You do not need a keyword and you do not need a reason.
A person, within one working day
A named handler takes your file over. Automated contact on that file stops as soon as the request is logged, not when the handler picks it up.
It stays that way
The preference is on the file, not the conversation. You do not have to ask again next month.
Every reserved decision is reviewed by a person anyway
The opt-out changes who talks to you. It does not change who decides — that was already a person.
Things we will not do with this technology.
No synthetic voice pretending to be a person
If you are speaking to an automated system, it says so at the start of the call. We do not imitate a human agent.
No emotional pressure engineered by a model
We do not optimise messages for shame, fear or urgency. Approved templates are reviewed for tone before a model is allowed anywhere near them.
No inference about you from outside your file
We do not buy behavioural data, scrape social media, or profile you from anything other than the file the creditor passed to us and your dealings with us.
No training on your conversations without a lawful basis and a record
Where we improve a model, the data is minimised and de-identified first, and the basis is documented. Your credit data is not used to train models.
No black boxes in the loop
If we cannot reconstruct why a system did something, it does not go into production. Every automated decision on a file is logged with the rule or model version that produced it.
No third-party model gets your data without a written agreement
Sub-processing is named, contracted and disclosed before it begins.
The instruments behind these commitments.
Two notes on honesty, because the alternative is the kind of vagueness this page exists to avoid. First: SAMA has not issued a dedicated rule on artificial intelligence — we checked its Rulebook, including the archive, by exact phrase. Second: SDAIA's AI Ethics Principles are a national framework with opt-in compliance and no penalty provision. They are advisory. We hold to them anyway, and we do not claim a certification that does not exist.
SDAIA AI Ethics Principles
SDAIA-P114E · Version 1 · May 2025
Seven principles: fairness; privacy and security; humanity; social and environmental benefits; reliability and safety; transparency and explainability; accountability and responsibility. Advisory, not enforceable. Adopted here as our own standard.
SAMA Counter-Fraud Framework
Ref 000044021528 · 11 October 2022 · In force
§3.8 requires that where machine learning or AI is used, the system is not a black box and is capable of being audited. Binding on supervised institutions, and the reason our decision logs exist in the form they do.
SAMA circular on PDPL adherence
Ref 43045328 · 23 December 2021 · In force
Directs supervised institutions to align with the PDPL and with SDAIA's policies, controls and rules. This is what carries SDAIA's framework into regulated financial services.
Personal Data Protection Law
Royal Decree M/19, amended by M/148 · effective 14 September 2023
Credit data carries a heightened standard: explicit consent, and notification to you when a request to disclose your credit data is received. A documented impact assessment is required where processing involves automated decision-making.
SAMA Debt Collection Regulations and Procedures
Ref 106889333 · 6 March 2025 · In force
Applies to creditors and to third parties acting for them. We are told at the start of a call that it is recorded because this requires it, and records are kept for not less than ten years.
A ladder with deadlines on every rung.
Escalation routes that end in "contact us" are not routes. This one ends outside Ebra, on purpose.
- 1
Raise it
Same working dayIn the app, by phone, or through the complaint form. You get a reference number and the name of the person handling it.
- 2
Acknowledgement
Within 3 working daysWritten, with what we understood the complaint to be, so you can correct us early if we have it wrong.
- 3
Substantive answer
Within 30 daysThe outcome, the reasoning, and — where a model was involved — what it did and who reviewed it.
- 4
Final answer, or an explanation of the delay
Within 90 daysIf it is still open we tell you why and what is outstanding, rather than letting it go quiet.
- 5
Escalate past us
Your right at any pointYou can take it to the creditor's own complaints function and to the Saudi Central Bank. We will give you what you need to do that, including our file reference.
The 30-day and 90-day figures follow SAMA's Regulations for Consumer Financing (ref 351000116619, Article 23), which requires a creditor to respond within thirty days of a dispute notice and resolve within ninety. We hold ourselves to the same clock.
Questions about any of this?
If you are a customer and something here does not match what happened to you, tell us — that is a defect and we want it. If you are a creditor doing diligence on us, ask for the model inventory and the impact assessments.