The Sharia AI Compliance Framework: A Dual-Authority Governance Architecture for Islamic Finance
Abstract
Two clauses accompany this framework everywhere, and they are stated before anything else. No Shariah Supervisory Board has reviewed or endorsed this specification. It is an engineering proposal for how binding Shariah authority can be integrated into AI lifecycle governance, offered for scholarly and institutional review. The specification makes no Shariah determination and must not be read as making one. It specifies the architecture by which an existing Shariah authority reaches an AI system; what is permissible is for that authority to decide. An Islamic financial institution operates under two binding authorities. A financial supervisor determines what it may do in law. A Shariah Supervisory Board determines what it may do in conscience, and in most such institutions the board's determinations are binding rather than advisory. Both authorities predate artificial intelligence and neither has specified how its authority reaches an AI system. The institution therefore builds a second process. The AI system passes the civil governance machinery, and then, separately and usually later, a Shariah review conducted by different people, on different evidence, producing different records. That improvisation carries three costs that compound: the record sets diverge and must be reconciled after the fact; the second review arrives once redesign is expensive, which exerts steady pressure toward findings that can be accommodated; and disagreement has no defined behaviour, because a dispute between two committees is not a governance outcome. This specification proposes that the second process is unnecessary and that building it is the error. Its central move is structural: the Shariah Supervisory Board is constituted as an authority source at the Regulatory Floor of the MESA Framework, alongside the financial supervisor, so that its determinations cascade downward through the same governance machinery as civil regulation rather than running beside it. An institution operating this framework has one governance system with two authority sources at its floor, and a disagreement appears as an unsatisfied floor obligation rather than as a dispute between functions. The framework surfaces such a conflict before a system is built; it does not claim to resolve it, and says so. Beneath that constitution sit a Maqasid risk frame, which classifies what an AI decision may harm in the vocabulary of the authority's own discipline rather than in that of a risk register, and three threads into machinery the institution already operates: dual validation into model risk management, where a civil track and a Shariah track run concurrently and both must close before approval; the Halal data certification chain into data governance, where an unattested hop breaks the chain; and Shariah screening into vendor risk, where the attestation must record whether it rests on the vendor's own statement. Escalation is concurrent rather than sequential, so that the board's determination shapes the response rather than reviewing one already chosen. The specification is explicit about its own standing. The Halal data certification chain is author methodology that no standard-setter recognizes. The relevant standing instruments are IFSB-10 (2009) and IFSB-31 (July 2025); IFSB-31 was examined for this specification and contains no treatment of artificial intelligence. AAOIFI has issued no standard or exposure draft on artificial intelligence. That the field is open is what makes this worth submitting as candidate input, and equally why it carries no authority behind it, and a reader should hold both facts at once. No institution has been observed operating the framework, and the author is not a Shariah scholar, which is stated as a limitation on what the document can be relied on for. It is a specification, not a certification scheme, and no conformity assessment body operates against it.
// Source
Authors: Nabeel A. Khan
Institutions: Instituto Superior Manuel Teixeira Gomes