Skip to content

Governance and operations

Data security, access and approvals.

We define which data the AI system can access, how its output is tested and which actions require approval. We also agree who handles errors, updates and support after launch.

Controls to agree

Data and system controls.

We review source permissions, model selection, action limits and support responsibilities with your IT, security and business teams. Requirements are documented for the specific project.

Data access

Which data can the system use?

  • List of approved sources and permitted uses
  • Collection of only the personal data needed
  • Retention and deletion rules
  • Access permissions by role

AI models

Which tools are approved and how are they tested?

  • Approved models and providers
  • Version history for prompts and models
  • Tests using representative tasks
  • Review of errors and bias

Actions and approvals

Which actions require a person’s approval?

  • Permissions for each connected tool
  • Approval before publishing or changing budgets
  • Usage and spending limits
  • Rollback or manual fallback procedures

Source and change history

Can a reviewer check how the output was produced?

  • Links to supporting sources
  • Model assumptions and uncertainty
  • Records of approvals and manual changes
  • A retained history of inputs and outputs

Support and maintenance

Who handles errors and changes after launch?

  • Named business and technical owners
  • Agreed quality and response targets
  • Error reporting and support process
  • A process for updates and retirement

Boundaries

What remains outside scope?

Record excluded sources and actions, unsupported markets and cases that must use the manual process. A missing permission must stop the relevant action.

Human review

Human review and approval.

A research summary and a public product claim have different consequences. The following scenarios describe possible review arrangements; your policy owners approve the actual design.

Summarise approved research

The system may draft a summary with citations. An analyst reviews the source material before using it to support a material recommendation.

Check: citation accuracy and access permissions

Adapt campaign assets

The system may generate drafts from approved inputs. Brand, local-market and rights reviewers approve the assets before they leave the production queue.

Check: claims, brand requirements and usage rights

Prepare regulated communication

The system may retrieve evidence and route a draft. Authorised specialists retain responsibility for approving claims and required disclosures.

Check: substantiation, jurisdiction and approval record

Recommend a budget change

The system may compare scenarios. The budget owner reviews assumptions, uncertainty and limits before authorising any reallocation.

Check: measurement validity and financial authority

Evaluation before release

Testing before launch.

Representative test cases should include missing data, conflicting sources, expired rights, unsupported claims and requests outside scope. Measure whether the system stops or escalates correctly as well as whether it produces a useful result.

After launch, monitor quality, cost, response times and manual overrides. Define which changes require reevaluation and who can pause the workflow.

Release checklist

  • Named business and technical owners
  • Approved source access and action permissions
  • Representative evaluation set and agreed acceptance thresholds
  • Manual fallback and tested rollback procedure
  • Exception alerts, support contacts and response expectations
  • Versioned configuration and retained review records
  • Baseline and date for the post-launch evaluation

Sample approval record

Content approval history.

This illustrative record shows how a claim moves through review. It is sample interface data, not a live client record or a certification.

Content review / CR-0942Illustrative interface · Sample record
AssetProduct page · Draft 18
ApproverRegional claims reviewer
StatusApproved with amendment
  1. Draft received

    The asset version and permitted market are recorded.

  2. Evidence attached

    Three approved sources are linked to the draft claims.

  3. Review required

    One claim falls outside the approved wording. Publication remains blocked.

  4. Human decision

    The reviewer amends the claim and approves the revised version.

  5. Release authorised

    The approved version, reviewer and evidence are retained together.