Human accountability throughout the workflow
AI can help search, extract, connect, analyze and prepare a recommendation. Approving or interpreting a requirement, approving a policy, making a decision and executing an action remain the responsibility of authorized people under the organization's policies and delegation limits.
An automated recommendation does not grant new authority or establish that a regulatory interpretation or compliance conclusion is correct. Review requirements should reflect the sensitivity, impact and uncertainty of the use case.
Planned design principles
Human-in-the-Loop
Allow people to review and correct requirements, links and recommendations, and route sensitive or unclear cases to the appropriate specialist.
Human Approval
Separate proposed outputs from approved outputs and define the authorized approver and approval conditions before institutionally significant actions are executed.
Traceability
Link outputs to the documents and versions used, processing context, model or rule version, and subsequent reviews and changes.
Source Attribution
Show the source, date, document, quotation and location, and check whether the evidence supports the conclusion. A link or quotation alone does not prove that a recommendation is correct.
Explainability
Explain the evidence and assumptions behind a proposed link or recommendation, with gaps, alternatives and explanation limits. A generated explanation is not independent evidence.
Accountability
Assign a use-case owner, reviewer, authorized decision-maker and action owner, with a process to challenge, correct and escalate outputs.
AI Risk Management
Maintain a register of use cases, models and vendors; assess privacy, bias, security and accuracy risks; test changes and monitor operation.
Audit Trail
Record the output, source, review status, edits, approval, action and outcome, with appropriate access permissions, retention rules and log protection.
AI limitations
Models may produce inaccurate information, incomplete interpretations, inappropriate links or quotations that do not support a conclusion. Results depend on document quality, currency, context, language and access to sufficient sources.
A proposed confidence indicator is not a correctness guarantee or a proven accuracy percentage unless its method has been defined, calibrated and validated. A higher indicator does not turn a recommendation into an approved decision.
Confidence values and statuses in the demo are illustrative. They do not evaluate an operational model or establish performance on actual data.
Handling unreliable outputs
Make uncertainty visible
Flag outputs with insufficient evidence or conflicting information and identify what needs further review.
Pause approval and execution
Do not pass an uncertain output into a consequential action before verification. Route it to an authorized specialist with its source and context.
Verify and correct
Check the original document and applicable version, review the quotation and proposed link, and correct or reject the recommendation with a recorded reason.
Record and learn
Capture the issue, review decision and outcome, then assess whether data, rules or the model need adjustment and retesting.
From an illustrative prototype to responsible use
The next phase targets a bounded use case: a new regulatory document, requirement extraction, policy links, evidence and gaps, followed by human review, an action and a recorded outcome. Launching an MVP will not make every capability in the broader vision operational.
Any actual pilot needs authorized data use, access control, isolation and audit controls, a use-case risk assessment, and output quality verification before expansion.
Explore Security & Trust