Built for auditors. Five control layers ship with every engagement — not bolted on after. This is what lets a PE firm, a portfolio company CFO, and counsel say yes without a separate risk review.
Generates, recommends, flags, drafts. Never approves, executes, transfers, or posts. The human is always the approver. Stated explicitly in every SOW.
Every output passes deterministic checks before a human sees it: cross-reference against system-of-record, completeness, range vs historical norms, format. Flagged → human review. Clean → through.
Every output logged with timestamp, model & prompt version, input hash, validation result, reviewer, and action (approved/edited/rejected). Queryable, immutable. This is the SOX evidence when the auditor asks “how was this number produced?”
Configurer ≠ approver. Prompt changes require peer review and approval. Model version updates follow change management: test → stage → approve → deploy.
Weekly automated holdout check: current prompts vs baseline on known-good documents. Accuracy drop >5% triggers investigation. Provider version change auto-flags re-validation.
| Risk | Examples | Approach |
|---|---|---|
| Low | Invoice coding suggestions, first-draft variance | Frontier model, human-reviewed |
| Medium | Contract extraction, covenant monitoring | Frontier + validation layer |
| High | Board narrative, investor comms | Frontier + human-in-loop + approval workflow |
| Critical | Journal approval, disbursement | Deterministic only — no AI execution |
If you need the full controls memo (SOW guardrails, SOC-adjacent logging schema, segregation matrix, and change management flow), I provide it in diligence — it's part of the engagement package. The five layers above are the summary your audit committee will want on one page.