No Model Reaches Production Without Evidence and Approval
Every fine-tuning engagement runs through a structured gate system — from use-case registration to signed release — so nothing ships on trust alone.
Structured around recognized AI risk frameworks
Our internal controls are informed by established frameworks — this describes how we structure our process, not a claim of formal third-party certification.
NIST AI RMF
Structured around the Govern, Map, Measure, and Manage functions, extended for generative-AI-specific risks.
ISO/IEC 42001 & 23894
AI management system and AI risk guidance inform our internal control design.
ISO/IEC 27001
Information security practices applied to training data, model artifacts, and access control.
EU AI Act
Risk-tiered classification aligned with EU AI Act obligations for deployments that fall within EU scope.
Eight gates between a request and production
Every engagement passes through the same sequence — the depth of review at each gate scales to the use case's risk tier, but no gate is skipped.
Commercial Qualification
Is the request lawful, technically feasible, and within EADPAG policy before any work begins?
Use-Case Approval
Is the intended purpose precise and acceptable? Vague purposes like "general AI assistant" are rejected at this gate.
Data Approval
Do we have documented authority for every dataset — owner, source, license, and permitted use — before it enters our training zone?
Training Approval
Are the base model, training code, compute environment, and evaluation criteria pre-approved and recorded?
Evaluation Approval
Has the model passed independent performance, reliability, safety, privacy, fairness, and security evaluation layers?
Domain Approval
Has a qualified human — clinical, legal, financial, or security specialist as relevant — validated it against realistic scenarios and edge cases?
Production Approval
Is the complete compliance package signed off by an independent Model Approval Board — not the engineer who built it?
Continued-Operation Approval
Does ongoing monitoring confirm the model remains safe, accurate, and within its approved scope?
Proof of rigor, not just a policy
Advisory by design
Systems recommend. Humans decide. That boundary is architectural, not a disclaimer in the footer.
One certified artifact
A single approved build runs everywhere it's deployed — no silent forks between what was validated and what ships.
Nothing ships un-recorded
Every training run, evaluation, and approval is logged well enough to survive an external audit.
One ID, full history
Every engagement carries a single traceable reference linking its specification, data, model, and certification — one lookup surfaces the complete history, not a search across separate systems.
The level of review scales to what's at stake
A low-risk internal tool doesn't need the same review as a healthcare or financial recommendation engine — but every tier still passes through all eight gates.
| Risk Level | Example | Control Level |
|---|---|---|
| Minimal | Internal text formatting or tooling | Basic controls |
| Limited | Customer-support assistant | Transparency and monitoring |
| Significant | Contract, property, or operational recommendations | Formal evaluation and human review |
| High-Consequence | Healthcare, finance, recruitment, security, critical infrastructure | Independent validation and strict release gate |
We decline engagements involving manipulative, unlawfully surveillant, or discriminatory use cases outright — these aren't a control level, they're a no.
Clearly divided, not assumed
Ambiguity about who's responsible for what is where compliance breaks down. These divisions go into the service agreement, not just internal documentation.
EADPAG Responsibilities
- Secure training and data isolation
- Reproducibility and technical evaluation
- Safety testing and model documentation
- Registry, version control, and deployment safeguards
- Incident assistance and asset deletion/return
Client Responsibilities
- Lawful data collection and authority to provide it
- Accurate declaration of intended use
- Domain validation and user disclosures
- Human oversight and local regulatory approvals
- Production access management and misuse reporting
Common questions
No — review depth scales to risk tier. A minimal-risk internal tool moves through the gates quickly; a healthcare or financial recommendation engine gets the full independent validation the stakes require.
Every change goes through a change-control category — patch, minor, or major — with review scope matched to what actually changed. A base-model swap or a shift in purpose triggers a full reassessment, not a quiet update.
Our internal controls are structured around NIST AI RMF and ISO/IEC 42001, 23894, and 27001 guidance — this describes how we operate, not a claim of formal third-party certification. Ask us directly if a specific engagement requires a certified provider.
Use-case registration includes a jurisdiction classification step specifically for this — where obligations are unclear, we escalate for legal review before data or training work begins.