1. Human oversight
A person remains accountable for consequential decisions. AI outputs support decisions; they do not replace the authority, judgment or responsibility of the people and institutions that use them. Escalation and override paths are part of the design.
2. Risk assessment
Before development we assess purpose, affected populations, plausible failure modes and the impact of an error. Higher-impact contexts require stronger controls, narrower scope and explicit authorization.
3. Appropriate explainability
The level of explanation is matched to the decision at stake: what the system does, which data it uses, what its limits are and how to contest an outcome. We avoid presenting statistical outputs as certainty.
4. Security
Models and pipelines are treated as attack surface: access control, integrity of data and prompts, protection against misuse and abuse, and monitoring proportional to risk.
5. Privacy
Data minimization, purpose limitation and separation of environments. Personal data is not repurposed for training without a legal basis and an explicit decision.
6. Bias mitigation
We examine data representativeness, evaluate outcomes across relevant groups where lawful and feasible, and document residual limitations rather than hiding them.
7. Traceability
Versioning of models, datasets, parameters and decisions, with records that allow an outcome to be reconstructed and audited.
8. Legitimate use
We do not design systems whose purpose is unlawful discrimination, disproportionate surveillance, manipulation of people, or evasion of oversight. Legitimate purpose, proportionality and legal authorization are conditions for engagement.
[CONFIRM] Alignment of this framework with the specific regulatory regimes applicable to each client jurisdiction.
Questions about this document? Write to us through the contact form.
Contact