AI Executive Office — CXO Assistant Platform  ·  View 29 of 30  ·  7 · Assurance

AI Governance and Guardrails

Every control on the path of a single turn, and the three ways the platform is allowed to not answer.

Editable source SVG draw.io All views
Input Prompt shield jailbreak detection PII detection Language service Scope check role · tenant Retrieval ACL trimming before scoring Sensitivity labels Purview honoured Content is data never instruction Generation Pinned model version recorded Pinned prompt from the registry Tool allow-list no write tools Output Claim binding evidence id per claim Groundedness Content Safety Protected material Egress DLP label-aware Fail safe Abstain "not enough evidence" Answer partially and say which part Escalate to a human analyst queue Record Full turn trace prompt · tools · model Feedback accepted · rejected Into the golden set next release unsupported AI Governance — Every Control on the Path of a Turn Security / platform Application we own Risk / gap Journey / task Person or role Data store failure / alternate Abstention is a first-class outcome with its own metric. Partial visibility answers partially and names the gap; a platform that never abstains is not more accurate, only less honest. v 1.0 · owner Data & AI Global Practice · date 2026-09

Decisions

  • Abstention is a first-class outcome with its own metric and its own review. A platform that never abstains is not more accurate, only less honest — and executives calibrate on the answers that turn out wrong
  • Groundedness is checked mechanically against retrieved evidence, not asserted by the generating model. Claims that fail are removed, and the removal is recorded
  • Model version and prompt version are pinned per tenant and written into the record. An answer is only reproducible if both are known

The three refusals

  • Abstain entirely: no sufficient evidence, and say so in those words
  • Answer partially: name which domain or which period is missing rather than quietly narrowing the question
  • Escalate to a human analyst: for questions the platform can frame but not resolve

Risks

  • Guardrails add latency to every turn and will be the first thing questioned when the 5-second target is missed. The groundedness check runs on the claim set rather than the full text to keep it affordable, and the budget is stated rather than discovered