Why use this record
An AI policy is not enough to govern a real workflow. Firms need a practical record that makes the use case understandable to business owners, Technology, Risk, Compliance, Internal Audit and senior leadership.
Use this template for priority workflows that influence customer, financial, compliance or operational outcomes. It supports consistent internal governance and does not constitute legal advice, a regulatory assessment or certification.
1. Use-case profile
- Use-case name
- Business purpose
- Process or customer journey affected
- Date created, last reviewed and next review
- Business owner
- Technology or AI owner
- Executive sponsor
2. Autonomy and mandate
- Autonomy classification: Assistive, Recommending, Bounded execution or Material action
- Approved business purpose
- Actions the system is permitted to take
- Actions explicitly prohibited
- Human approval requirements
- Monetary, operational, product, customer or jurisdictional boundaries
3. Accountability and governance
- Accountable business owner
- Relevant executive or senior sponsor
- First-line operating owner
- Technology, Data or AI owner
- Risk and Compliance challenge owner
- Change approver
- Exception or risk-acceptance authority
- Suspension or intervention authority
- Relevant governance forums
4. System and data context
- Model/provider and relevant configuration where available
- Workflow/version reference
- System instructions or prompt reference
- Data and retrieval sources
- Customer or personal data categories
- Tools, APIs and downstream systems
- Third parties and subcontractor dependencies
- User/service identities and permissions
5. Risk and customer impact
- Customer outcome or conduct relevance
- Vulnerable-customer considerations where applicable
- Data-protection and confidentiality considerations
- Financial, operational and compliance impact
- Operational-resilience dependency or important-business-service relevance
- Key failure modes and foreseeable harms
- Inherent and residual risk assessment
6. Controls and assurance
- Pre-deployment evaluation and testing
- Human-review or approval controls
- Access and permission controls
- Policy, threshold and action-boundary controls
- Monitoring and exception controls
- Change-control requirements
- Third-party assurance requirements
- Independent challenge or review requirements
7. Evidence record
- System/agent and human identity
- Mandate and approval state
- Model/provider and workflow version where available
- Prompt or instruction reference
- Relevant source-data or retrieval references
- Tool calls and downstream actions
- Policy/control version applied
- Human review, overrides and exceptions
- Outcome, incident and remediation record
- Evidence owner, access controls and retention period
8. Intervention and recovery
- Escalation triggers
- Who can require additional review
- Who can restrict data, tools, permissions or authority
- Pause or suspension process
- Safe fallback process
- Incident response process
- Customer remediation and communications process where relevant
- Lessons learned and periodic review process
Fictional worked example
Use case: AI complaints-triage and response-drafting workflow.
Business purpose: classify incoming customer complaints, identify urgency and vulnerability indicators, retrieve relevant internal policy material, prepare a draft response and route the case to an appropriate human handler.
Autonomy level: Recommending. The workflow cannot close a complaint, change a customer record or send a final response without human approval.
Permitted: classify, prioritise, recommend queue, retrieve approved internal guidance and draft a response. Prohibited: final complaint determination, settlement/refund approval, final customer communication, amendment of customer records and use of non-approved external sources.
Evidence retained: case ID, human user identity, workflow version, approved prompt/reference, retrieved policy sources, recommended category, vulnerability flag, draft output, reviewer identity, final disposition, overrides, exception reason, outcome and complaint resolution data.