Sahl AI Strengthens Healthcare Data Security with ISO 27001 & KSA PDPL Compliance
Overview
Sahl AI partnered with Sahl GRC with AI to establish a robust information security and data protection framework that supports the secure processing of sensitive healthcare data.
Through a unified compliance programme covering ISO 27001 and Saudi Arabia’s Personal Data Protection Law (KSA PDPL), Sahl GRC with AI helped Sahl AI strengthen its security posture, implement governance controls, and successfully complete its compliance journey.
Client
Sahl AI
Industry:
Healthcare AI / MedTech
Frameworks:
ISO 27001 & KSA PDPL
Project Status:
Successfully Completed
Client Overview
Sahl AI is a Riyadh-based healthcare technology company that leverages artificial intelligence to automate clinical documentation. Its platform converts Arabic conversations between doctors and patients into structured clinical notes, reducing administrative workload and allowing healthcare professionals to focus more on patient care.
Operating within Saudi Arabia’s regulated healthcare ecosystem, Sahl AI required a compliance framework capable of protecting sensitive patient information while supporting the continued growth of its AI-powered platform.
Note: Sahl AI is an independent healthcare AI company and is separate from Sahl GRC with AI, which served as its compliance partner throughout this engagement.
The Challenge
As a healthcare AI platform processing sensitive patient information and clinical documentation, Sahl AI needed to demonstrate that its information security and privacy practices aligned with both international standards and Saudi regulatory requirements.
The organisation required a structured Information Security Management System (ISMS), comprehensive data protection controls, and documented governance processes to safeguard sensitive healthcare data while maintaining compliance with Saudi Arabia’s evolving regulatory landscape.
The Sahl Solution
Sahl GRC with AI delivered an end-to-end compliance programme covering information security, privacy, and regulatory readiness.
ISO 27001 Implementation
Sahl supported the design and implementation of an Information Security Management System (ISMS), including risk assessments, security policies, access management, and governance controls aligned with ISO 27001 requirements.
KSA PDPL Compliance
Patient data flows, clinical documentation, and personal information processing activities were assessed against the requirements of the Kingdom of Saudi Arabia’s Personal Data Protection Law (PDPL). Appropriate organisational and technical controls were implemented to support regulatory compliance.
Compliance Programme Management
Sahl coordinated the complete compliance engagement, including readiness assessments, documentation, policy development, evidence management, and audit support across both frameworks.
Results
The engagement concluded successfully, with Sahl AI achieving compliance with both ISO 27001 and KSA PDPL.
The implementation established a formal governance framework for information security and data protection, enabling Sahl AI to securely manage sensitive healthcare information while strengthening confidence among healthcare providers, partners, and regulatory stakeholders.
Key Outcomes
- Successfully achieved ISO 27001 compliance.
- Successfully implemented KSA PDPL compliance requirements.
- Established a formal Information Security Management System (ISMS).
- Strengthened governance for sensitive healthcare and patient data.
- Enhanced trust with healthcare organisations, partners, and regulators.
Frequently Asked Questions
What compliance frameworks did Sahl AI achieve?
Sahl AI successfully completed compliance with ISO 27001 and Saudi Arabia’s Personal Data Protection Law (KSA PDPL) with support from Sahl GRC with AI.
Why were ISO 27001 and PDPL important for Sahl AI?
As a healthcare AI platform handling sensitive patient information and clinical documentation, Sahl AI required internationally recognised information security controls alongside compliance with Saudi data protection regulations.
What does Sahl AI do?
Sahl AI develops an AI-powered medical documentation platform that converts Arabic doctor–patient conversations into structured clinical notes, helping healthcare professionals reduce administrative workload.
Is Sahl AI part of Sahl GRC with AI?
No. Sahl AI is an independent healthcare AI company. Sahl GRC with AI served as the compliance partner responsible for delivering the ISO 27001 and KSA PDPL compliance programme.
Build Trust Through Security & Compliance
Whether you’re developing an AI platform, healthcare application, or data-driven service, Sahl GRC with AI helps organisations implement ISO 27001, achieve KSA PDPL compliance, and establish a strong foundation for information security and privacy across the enterprise.

