Human accountability, verified outputs, restricted decisions.
Responsible AI is not a values statement. It is a set of controls that can be pointed at, argued with and audited after go-live.

Fourteen controls, applied per engagement.
Not every control is relevant to every workflow. The scope of work records which ones apply, how they are configured and who owns them.
Human accountability
Every workflow has a named owner who remains responsible for its output.
Appropriate use cases
We decline work where the failure cost outweighs the operational benefit.
Data minimisation
Only the information the workflow genuinely needs is made available to it.
Confidentiality
Approved sources, restricted access and agreed retention for anything sensitive.
Bias awareness
Where output affects people, we test for patterns that would be unacceptable if a person produced them.
Output verification
Review points sit before anything customer-facing, contractual or financial.
Restricted decisions
High-impact categories are excluded from automated decision-making entirely.
Transparency
Users are told when they are interacting with an assistant and how to reach a person.
Security
Access control, secret management, environment separation and logging.
Monitoring
Sampling and exception review after go-live, not only during the build.
User feedback
A route for staff and customers to flag a wrong answer, and an owner who acts on it.
Incident handling
An agreed path for stopping a workflow, notifying and correcting the record.
Model and vendor risk
Written record of which providers are used, for what, and what changes if one is withdrawn.
Employee training
Nobody is asked to operate a workflow they were never shown how to check.

Oversight that continues once the project team has left.
Sampling, exception review and a change log are what keep a workflow honest in month six.
High-impact decisions
AI should not independently make final decisions in these areas. It may prepare, summarise, route or draft — a qualified and authorised person decides.
- Employment and recruitment outcomes
- Credit and lending decisions
- Insurance eligibility and claims outcomes
- Medical diagnosis or treatment
- Legal rights and obligations
- Regulatory eligibility or status
- Immigration and visa outcomes
- Access to public services
- Criminal allegations or investigations
- Safety-critical operational decisions
What we will not claim
- We do not hold or claim security or compliance certifications on your behalf.
- We do not guarantee accuracy, uptime or business outcomes from an AI workflow.
- We do not publish accuracy percentages that we have not measured on your data.
- We do not present example material as client results.
- We do not use identifiable client information in marketing without written authorisation.
If a claim matters to your procurement process, ask us for it in writing during scoping. We would rather decline it than dress it up.

Controls we implement — described without embellishment.
Access control, permissions, secret management, logging, retention settings and environment separation are configured to what your systems support, and documented at handover.
Where a control cannot be implemented in your environment, we record that as a known limitation rather than leaving it implied.
Data and security detail →Governance work can be scoped on its own.
Acceptable-use policy, responsibility mapping and a usage register are useful even before your first workflow.