Skip to content

Every claim on the other AI pages depends on this one. If learner data is not handled properly, if a model decides someone's certification unsupervised, or if nobody has checked whether scores differ by language group, then the capability is a liability rather than an advantage.

The problem

AI arrives in most organisations faster than the governance for it. A pilot runs on a vendor platform, employee conversations leave the boundary nobody defined, a score starts influencing a promotion, and the first time anyone examines it is during an audit or a grievance. The technology is rarely the failure; the absence of an agreed decision rule is.

What we put in place

  • Data boundary. Named storage, defined retention, no use of client data to train public models, and a documented deletion path. Written into the contract, not the brochure.
  • Role-based access. Learners see their own results; facilitators see their cohort; managers see their team; clients on outsourced programmes see their scoped population. Every reveal of personal data is logged.
  • Human decision points. AI scores practice and formative assessment. People decide certification, promotion, performance management and exit, with the AI evidence visible to them and their decision recorded.
  • Bias testing. Score distributions examined across gender, region and language group during the pilot, with findings reported to the client — including the uncomfortable ones.
  • Consent and alternatives. Learners are told in advance what is recorded and scored. Anyone declining AI practice gets facilitator-observed practice instead and is assessed by a human, with no disadvantage.
  • Audit trail. What was scored, against which rubric, by which model version, moderated by whom, decided by whom. Reconstructable months later.

Working with your security team

We expect and welcome the information-security review. Our team completes vendor questionnaires, supplies architecture and data-flow documentation, and agrees the boundary before a single learner is enrolled. Where a client requires deployment inside their own environment, that is a supported option rather than an exception.

What changes at work

Practically: legal and security stop being the blocker, because their questions were answered before the pilot. Employees engage with AI practice rather than avoiding it, because they have been told what happens to the recording. And the organisation can defend a decision six months later, which is the test that matters when someone challenges an outcome.

What we will not do

We will not let a model decide something consequential on its own, we will not use your employees' conversations to improve a product sold to someone else, and we will not claim an accuracy figure we have not measured on your data. If a proposed use of AI cannot pass those three, we will tell you it is a bad idea before quoting for it.

Frequently asked

Where does our data go?

Into your instance, within a boundary agreed in the contract: named storage regions, defined retention, role-based access. Learner conversations and assessment responses are not used to train public models. We complete your information-security review before a pilot, not after it.

Who decides when AI and a human disagree?

The human, and the disagreement is recorded. Consequential outcomes — certification, promotion, performance management, exit — always rest on a person's decision. The AI score is evidence presented to that person, never the decision itself.

How do you handle bias?

Two ways. Rubrics are written and reviewed by your subject-matter experts, because most bias enters through the rubric rather than the model. Then we test score distributions across gender, region and language group during the pilot and report the differences we find — including when they are uncomfortable.

What about learners who do not want to be recorded?

They get an alternative route: facilitator-observed practice and human-marked assessment. Participation in AI practice is disclosed in advance and consent is explicit. A learner who declines is not disadvantaged in assessment.

Which regulations does this address?

India's DPDP Act obligations around consent, purpose limitation and retention are built into the design, and the controls map onto ISO 27001-style reviews that most of our enterprise clients run. We provide the documentation your security and legal teams need rather than a marketing statement.

Tell us about the team you want to develop.

We come back within one working day with a first-cut approach — content, facilitation, technology and analytics in the right mix.

Request a proposal