OPERATING PRINCIPLES
Responsible AI and Data Handling
Practical controls should match the workflow, risk, data, and decisions involved.
Human accountability
AI-assisted workflows should have a clear business owner. High-impact or sensitive actions should include suitable review, approval, escalation, and fallback paths rather than relying on unchecked automation.
Purpose and access
Systems should use data for an agreed operational purpose and limit access according to user responsibilities. Integration permissions, logs, and retention should be considered during implementation.
Testing and monitoring
AI outputs should be evaluated against the intended workflow before deployment. Accuracy, failure modes, user feedback, and operational usage should be reviewed in proportion to the risk of the use case.
No automation for its own sake
We begin with the workflow and expected business value. A simpler process improvement or conventional automation may be more appropriate than an AI model.
