AI GOVERNANCE & COMPLIANCE

No Model Reaches Production Without Evidence and Approval

Every fine-tuning engagement runs through a structured gate system — from use-case registration to signed release — so nothing ships on trust alone.

The governing rule behind every engagement.

No dataset enters training, no model enters production, and no model update is released without recorded evidence and approval. This applies to every fine-tuning engagement we run — no exceptions for deadline pressure or client urgency.

Capable is not the same as cleared. A model earns the right to act only after it has earned the right to be trusted — and those are proven separately, never assumed together.

FRAMEWORK ALIGNMENT

Structured around recognized AI risk frameworks

Our internal controls are informed by established frameworks — this describes how we structure our process, not a claim of formal third-party certification.

NIST AI RMF

Structured around the Govern, Map, Measure, and Manage functions, extended for generative-AI-specific risks.

ISO/IEC 42001 & 23894

AI management system and AI risk guidance inform our internal control design.

ISO/IEC 27001

Information security practices applied to training data, model artifacts, and access control.

EU AI Act

Risk-tiered classification aligned with EU AI Act obligations for deployments that fall within EU scope.

THE GATE STRUCTURE

Eight gates between a request and production

Every engagement passes through the same sequence — the depth of review at each gate scales to the use case's risk tier, but no gate is skipped.

G0

Commercial Qualification

Is the request lawful, technically feasible, and within EADPAG policy before any work begins?

G1

Use-Case Approval

Is the intended purpose precise and acceptable? Vague purposes like "general AI assistant" are rejected at this gate.

G2

Data Approval

Do we have documented authority for every dataset — owner, source, license, and permitted use — before it enters our training zone?

G3

Training Approval

Are the base model, training code, compute environment, and evaluation criteria pre-approved and recorded?

G4

Evaluation Approval

Has the model passed independent performance, reliability, safety, privacy, fairness, and security evaluation layers?

G5

Domain Approval

Has a qualified human — clinical, legal, financial, or security specialist as relevant — validated it against realistic scenarios and edge cases?

G6

Production Approval

Is the complete compliance package signed off by an independent Model Approval Board — not the engineer who built it?

G7

Continued-Operation Approval

Does ongoing monitoring confirm the model remains safe, accurate, and within its approved scope?

HOW WE HOLD THE LINE

Proof of rigor, not just a policy

01

Advisory by design

Systems recommend. Humans decide. That boundary is architectural, not a disclaimer in the footer.

02

One certified artifact

A single approved build runs everywhere it's deployed — no silent forks between what was validated and what ships.

03

Nothing ships un-recorded

Every training run, evaluation, and approval is logged well enough to survive an external audit.

04

One ID, full history

Every engagement carries a single traceable reference linking its specification, data, model, and certification — one lookup surfaces the complete history, not a search across separate systems.

RISK-TIERED BY DESIGN

The level of review scales to what's at stake

A low-risk internal tool doesn't need the same review as a healthcare or financial recommendation engine — but every tier still passes through all eight gates.

Risk LevelExampleControl Level
MinimalInternal text formatting or toolingBasic controls
LimitedCustomer-support assistantTransparency and monitoring
SignificantContract, property, or operational recommendationsFormal evaluation and human review
High-ConsequenceHealthcare, finance, recruitment, security, critical infrastructureIndependent validation and strict release gate

We decline engagements involving manipulative, unlawfully surveillant, or discriminatory use cases outright — these aren't a control level, they're a no.

SHARED RESPONSIBILITY

Clearly divided, not assumed

Ambiguity about who's responsible for what is where compliance breaks down. These divisions go into the service agreement, not just internal documentation.

EADPAG Responsibilities

  • Secure training and data isolation
  • Reproducibility and technical evaluation
  • Safety testing and model documentation
  • Registry, version control, and deployment safeguards
  • Incident assistance and asset deletion/return

Client Responsibilities

  • Lawful data collection and authority to provide it
  • Accurate declaration of intended use
  • Domain validation and user disclosures
  • Human oversight and local regulatory approvals
  • Production access management and misuse reporting
FAQ

Common questions

No — review depth scales to risk tier. A minimal-risk internal tool moves through the gates quickly; a healthcare or financial recommendation engine gets the full independent validation the stakes require.

Every change goes through a change-control category — patch, minor, or major — with review scope matched to what actually changed. A base-model swap or a shift in purpose triggers a full reassessment, not a quiet update.

Our internal controls are structured around NIST AI RMF and ISO/IEC 42001, 23894, and 27001 guidance — this describes how we operate, not a claim of formal third-party certification. Ask us directly if a specific engagement requires a certified provider.

Use-case registration includes a jurisdiction classification step specifically for this — where obligations are unclear, we escalate for legal review before data or training work begins.

Have a use case that needs this level of rigor?

Tell us the business problem and the data you have — we'll map it to the right risk tier before any training begins.

Talk To Our Experts

We use cookies. We use necessary, functional, analytics, performance, and advertisement cookies to run this site and understand how it's used. Choose what you're comfortable with.