Nazor.ai

The risk you manage is not the risk you have.

Nazor.ai helps banks, payment providers and humanitarian organisations across Uzbekistan and Central Asia find the exposures their frameworks were never built to catch — in operations, in compliance, and in the technology arriving faster than the controls around it.

N

Three places risk hides

Whether the organisation is a bank in Tashkent or an aid programme running cash transfers across a border, the same gaps recur.

Frameworks that don't fit

A risk framework translated from a European parent or a donor template describes an organisation that isn't yours. It passes review and catches nothing.

Systems nobody governs

Scoring models, fraud engines, beneficiary databases and payment rails deployed quickly, bought from vendors, and owned by no one in the second line.

Controls that exist on paper

Assessment cycles run because they are required. The findings don't change decisions, and the residual risk ratings haven't moved in three years.

Who we work with

Two sectors, and genuine depth in both — twenty years split between commercial banking and international humanitarian assurance.

Financial institutions

Banks, payment providers, microfinance and fintech

Institutions modernising under regulatory pressure, adopting technology faster than governance can follow, and answering to supervisors who are still writing the rules.

  • Operational risk frameworks aligned to Basel principles and CBU expectations
  • Payment operations risk, settlement controls and third-party dependencies
  • AI and model governance for scoring, fraud and onboarding systems
  • RCSA design, control testing and audit readiness
  • AML and sanctions control assessment
  • Board and risk committee reporting management can act on

NGOs and humanitarian organisations

INGOs, UN agencies and donor-funded programmes

Organisations delivering in difficult environments under donor scrutiny, where a compliance failure costs the grant and the operation behind it.

  • Donor compliance reviews against USAID, EU, UN and institutional requirements
  • Enterprise risk frameworks that field teams will actually use
  • Sanctions exposure and cash transfer controls in fragile contexts
  • Partner and sub-grantee due diligence
  • Fraud prevention, investigation support and lessons-learned processes
  • Internal audit and assurance for country and regional offices

How we're engaged

Scoped to a defined outcome and a fixed fee. No open-ended retainers to start, and no team of juniors learning on your time.

Risk framework work
Both sectors

Assessment of what exists against the standard that applies to you, then design and embedding of what is missing. Built around how the organisation actually operates rather than lifted from a template.

  • Gap assessment
  • Framework design
  • RCSA methodology
  • Risk registers
  • KRI libraries
  • Policy drafting
AI and technology governance
Organisations adopting AI

Where AI enters the organisation, what it decides, and who answers when it decides wrong. Vendor assessment, model controls, and the governance structure a regulator or donor will eventually ask to see.

  • AI risk taxonomy
  • Model governance
  • Vendor risk
  • Data protection review
  • Board briefings
Compliance and assurance
Second and third line

Control testing, audit readiness and independent review. Twenty years on both sides of the audit table, including regional internal audit across four countries and focal point for institutional and donor reviews.

  • Control testing
  • Audit readiness
  • Donor compliance review
  • Independent assessment
  • Remediation planning
Training
Teams, management and boards

Working sessions rather than slide decks. Risk and audit teams leave with methodology they can run themselves; boards and senior management leave knowing which questions to put to their own people.

  • Operational risk practice
  • RCSA facilitation
  • AI risk for directors
  • Donor compliance for field staff
  • English or Arabic

Where we work

Registered and operating in Uzbekistan. Expanding by following the work rather than announcing it first.

Uzbekistan
Registered and operating

Home market. The firm is registered in Tashkent and delivers here directly, in person, with no intermediary.

Kazakhstan and CIS
Active — local registration follows the first engagement

An active focus across the region. A local branch is registered once an engagement is signed, rather than maintained ahead of demand.

Middle East
Expertise network

Specialist partners across the Gulf and Levant join engagements where sanctions exposure, Islamic finance or donor compliance calls for it. Regional presence follows demand.

Who runs it

You will be working with Mashal Sabti. Not an account manager, and not a team of consultants two years out of university.

Twenty years in risk and compliance, split between commercial banking and international humanitarian assurance. Seven of those across two periods at Standard Chartered, the second ending as Head of Governance and Control after leading consumer banking operations and technology risk.

Then four years building risk functions from nothing — first as Executive Manager for operational risk and information security at Egyptian Arab Land Bank, then across branches and subsidiaries as AVP of operational risk at Jordan Ahli Bank. Two years of independent consulting followed, advising and training risk teams across several industries.

Most recently, Risk and Assurance Manager for the International Committee of the Red Cross, covering the Near and Middle East region and then Afghanistan from a base in Uzbekistan. That work involved sanctions exposure, cash controls in conflict environments, and partner due diligence where the cost of getting it wrong went well beyond an audit finding.

Alongside the practice, a law degree and a master's in international commercial law and technology from the University of Manchester. That combination is unusual in this field, and it is why the advice covers where liability actually sits — in the contract, in the vendor agreement, in the regulation — and not only where the control gap is.

2024–26ICRCRisk & Assurance Manager — Afghanistan, then Near & Middle East
2023–24World Vision InternationalRisk & Compliance Manager — Jordan, Syria, Türkiye
2020–22Independent practiceRisk management consulting and training across multiple industries
2018–19Jordan Ahli BankAVP Operational Risk Management
2015–17Egyptian Arab Land BankExecutive Manager, Operational Risk & Information Security
2010–15Standard Chartered BankHead of Governance & Control; Head of Consumer Banking Operations; Head of Risk, Technology & Operations
2008–10ACTEDRegional Internal Auditor — Middle East
2006–07Standard Chartered BankUnit Operational Risk Manager, Wholesale Banking

Education

2024–26LLM, International Commercial Law & TechnologyUniversity of Manchester
2020–23LLB, Bachelor of LawsMiddle East University
2003–06MBA, FinanceNew York Institute of Technology
1999–2003BA, EconomicsAl-Balqa Applied University

Certification

2020ISO 31000 Senior Lead Risk ManagerCertified risk management practitioner
2019Training of TrainersFrankfurt School of Finance & Management

How an engagement runs

Most begin with a scoped assessment. It costs less, proves the value, and tells both of us whether the larger piece of work is worth doing.

A conversation, at no cost

An hour on what you are facing. If the answer is that you do not need outside help, that is a legitimate outcome and I will say so.

A written proposal

Scope, deliverables, timeline and a fixed fee. No hourly billing, and no scope that expands after signature.

Fieldwork

On site with your teams. Document review, process walkthroughs, control testing and interviews — done in person, because the risk that matters rarely appears in the documentation.

Findings and a plan

What was found, ranked by exposure, with remediation sequenced by what is urgent and what is achievable. Presented to management and, where useful, to the board.

Support through implementation

Recommendations that sit in a report change nothing. Continued support is available where you want the work embedded rather than delivered.

Insights and publications

Writing on risk, regulation and emerging technology in Central Asian and frontier markets.

ArticleIn preparation

Why translated risk frameworks fail in Central Asian banks

Frameworks imported from European parent institutions describe a business model, a regulatory environment and a risk profile that do not match the market they land in.

Coming soon
ArticleIn preparation

Who owns the model? AI governance gaps in emerging market banks

Scoring and fraud tools arrive through procurement, not through risk. By the time the second line is asked about them, they are already making decisions.

Coming soon
GuideIn preparation

Cash transfer controls in sanctioned and fragile environments

What donors expect, what field reality allows, and how to build a control set that survives both an audit and an operating environment that changes weekly.

Coming soon

News

Announcements, engagements and speaking.

2026

Nazor.ai begins operations in Uzbekistan

The firm is registered in Tashkent and open for engagements with financial institutions and humanitarian organisations across Uzbekistan and the wider region.

Start with a conversation

Tell me what you are dealing with — a framework that is not working, a system nobody can explain, a supervisory finding, a donor audit coming. The first conversation costs nothing and carries no obligation.

Emailmashal.sabti@nazor.ai Phone+998 77 741 15 78 Based inTashkent, Uzbekistan Working languagesEnglish, Arabic EntityRegistered in Uzbekistan