What we solve ·How do I fix the way we decide?
Taskforce · Sustain
Who answers for what your AI decides, and with what evidence?
The regulator asks why that case was rejected and nobody can reconstruct it.
What a machine decides inside your organization, with what consequence, who answers for each decision and what evidence is left behind.
Automated decision governanceSend this page to whoever decides
Use this today, without hiring anyone
The single decision test, which is how this actually gets audited and you can run it this week. Pick one real automated decision from the last thirty days and follow these five steps.
- Ask them to reconstruct it for you. What went in, what came out and why. Time how long they take. If it goes past an hour, you already have your gap.
- Ask who answers for that decision. A name, not a department. If the answer is "the system" or "the vendor", nobody answers.
- Find out under what conditions that machine stops deciding. If there is no written threshold, it decides always, including when it should not.
- Ask what credential it used and who can revoke it. It is the question that most often goes unanswered.
- Check how long that record is kept. A record that gets deleted at ninety days is no use for a question that arrives at six months.
And the inventory that decides the outcome: list the decisions that were automated without any committee approving them. They exist in every organization and they are the ones that weigh most when someone asks.
This sounds like you if
- You have models or agents deciding things in production.
- An auditor asked about a specific decision and the traceability was not available.
- The automations piled up area by area, each one with its own credentials.
How we solve it
The method, not the promise.
- The automated decisions are inventoried, including the ones nobody registered, which are the ones that matter.
- They are classified by consequence: what happens if that decision goes wrong for the customer, for the balance sheet and for the regulator.
- A named human role is assigned to each one. A department is not a person who answers.
- The evidence is designed backwards, from the question a third party will ask six months from now.
- It gets tested on a real decision of yours: if it cannot be reconstructed, the design does not work yet.
What you receive
- The inventory of automated decisions with their consequence classification.
- The named responsibility matrix: who answers for each one.
- The non human identity policy and the intervention and exception tree.
- The evidence logging specification, tested against a real decision of yours.
The proof that applies here
- Eight years of operation under regulatory supervision with zero findings.
- Regulatory audit over an infrastructure of 60,000 servers.
- Resilience leadership in a financial institution regulated in two countries.
Before you hire
The evidence gets prepared and the criteria get documented. When your contract requires a certification, an accredited auditor issues it over that same evidence.
What decides this is whether the design survives a specific question six months later. It gets checked before the work is accepted, with the reconstruction test on a real decision of yours: if the decision cannot be reconstructed in under an hour, you already have your gap and you have not paid anything yet.
Can you reconstruct for a third party, in under an hour, why your system rejected one specific case?
If the problem is a different one
The agent no longer just answers: it executes. Nobody defined how far it can go on its own.
Agentic operation guardrails
We have service accounts with privileges and nobody knows who answers for them.
Non-human identity governance
The integrator says it works and I am the one who signs.
Independent implementation review
