DENQ
DEContact
Home / Governance & security

AI governance: information security and compliance as part of the solution architecture.

This page is aimed at the functions that share in deciding whether AI applications are approved: information security, data protection, legal and employee representatives. We involve them from the first architecture draft and provide them with the documentation they need for their approval.

Painting of a classical temple with columns by the sea
CORE PRINCIPLES
Security by designFROM THE START
Compliance by designALIGNED WITH EU AI ACT, GDPR
TraceabilityFULLY LOGGED
Principles01

Five principles that apply to every solution from the start.

Principle of least privilege
Each agent receives only the permissions its task requires. Read, write and execute rights are granted and documented separately for each system.
Approval processes
Critical actions are subject to defined human-in-the-loop controls. Every approval includes the recommended action, the reasoning, the underlying data and the risk.
Traceability
All actions, decisions, tool calls and approvals are logged completely and traceably, and each is assigned to a responsible person.
Data classification
We define which data may be sent to language models, where it is processed and which retention and deletion periods apply.
Safeguards
We protect agents that process external content such as emails or documents against manipulation, for example by separating read rights from action rights.
Autonomy levels02

Responsibility grows with proven performance.

The Agent Board decides on the move to the next level based on defined KPIs. Not every process is suitable for a higher level.

LEVELNAMEROLE OF THE AGENTROLE OF THE HUMANPREREQUISITE
1AssistAnalysis and recommendationDecision and implementationIntroduction
2PrepareDrafts, analyses, data recordsReview and approvalConsistent output quality
3Execute after approvalImplementation after confirmationConfirmation or cancellationLow correction rate
4Autonomous executionImplementation within defined limitsSpot checks and exceptionsAgent Board decision
Stakeholder involvement03

What we provide to your specialist functions for approval.

FOR
Privacy policy
Documentation of data flows and processing purposes, data classification, and a retention and deletion concept for each agent.
FOR
Information security
Permission concept, logging, safeguards against manipulation and alignment with existing security policies.
FOR
Employee representatives
A clear description of the scope of functions and changes to roles, and of the analyses that are explicitly not intended.
FOR
Legal and compliance
Preparation of the technical and organisational basis for legal assessment by your specialist functions.

Legal assessments are carried out by your legal department or your external legal counsel. We provide the technical and organisational basis for them.

Agent Board04

The Agent Board decides on the approval, permissions and autonomy level of every agent.

An interdisciplinary body replaces decentralised individual decisions with a single structure for decisions and accountability across all AI applications in the company.

Prioritisation and approval of use cases
Based on business value, risk profile and feasibility.
Autonomy levels and permissions per agent
Set and adjusted based on defined KPIs.
Performance and risk monitoring
Ongoing evaluation through the integrated value tracking.
Scaling, adjustment or decommissioning
Decision on the further use of each solution.
Operation05

For every failure case, how the agent responds is defined before go-live.

In operation, data goes missing, interfaces fail, and some cases fit no rule. We define with your IT how the agent responds in each case and test it before go-live.

Which language models and data centres are used is agreed with your IT and your data protection team for each engagement and documented.

Incomplete dataThe agent asks for clarification or hands over to the responsible person instead of guessing to fill gaps.
Conflicting sourcesThe defined primary source applies. The discrepancy is documented and submitted for clarification.
Interface timeoutLimited retries, then handover to a person and notification of IT.
Duplicate eventBefore every action, the agent checks whether the case has already been processed.
Missing permissionThe action is cancelled and reported. There is no workaround via other rights.
Partially executed actionThe intermediate state is logged and then resumed or rolled back in a controlled way.
Uncertain resultThe case is flagged as an exception and approved by a human.

Documents for your information security and data protection teams.

We provide your specialist functions with a compact overview of our governance approach.

Book an initial callRequest documents