OIA · Guard Rail - governance and risk framework · Worked example Hartwell M&E Group · £45m turnover · 180 staff · Maturity 2.4 / 5 · 4-week diagnostic · Bleed Rate £1.87m (4.2% of turnover)
ILLUSTRATIVE · Operational Intelligence Audit™ · Deliverable 05 of 07

Guard RailGOVERNANCE & RISK FRAMEWORK

Defining data handling, approval gates, audit trails and safe operating boundaries for AI workflow deployment across the business.

Prepared for
Hartwell M&E Group
Prepared by
Built AI Ltd
Date
May 2026
Guard Rail™ — Governance & Risk Framework
← Audit PackDeliverable 05 of 07BAI-HME-AUD-005
Section 01

Framework Purpose

This framework defines the governance controls, data handling rules and approval processes that should be in place before, during and after AI workflow deployment at Hartwell M&E Group.

Governance principles

Human authorityAI workflows produce structured drafts. Competent human reviewers approve, modify or reject every output before it is used, issued or relied upon. AI does not make decisions.
Data minimisationOnly the minimum data required for each workflow is processed. No data is stored beyond the processing cycle unless explicitly required for audit trail purposes and agreed in writing.
TraceabilityEvery AI-assisted output carries a source reference, version identifier and reviewer record. Any output can be traced from final version back to its input data and processing steps.
ProportionalityControls are scaled to risk. Higher-risk outputs (safety documentation, client-facing submissions, commercial claims) require stronger approval gates than lower-risk outputs (internal summaries, draft agendas).
Continuous reviewThe framework is reviewed quarterly during Phase 1 and annually thereafter. Controls are adjusted based on operational experience, incident review and regulatory changes.
This is not a compliance checklist. It is a practical operating framework designed for the way Hartwell works. The aim is to make AI adoption defensible, auditable and commercially useful — not to create bureaucracy.
Section 02

Data Classification Model

A three-tier classification system determining which data types can be processed through AI workflows, under what conditions, and with what controls.

Red — Restricted

Data that must not be processed through AI workflows without explicit senior approval and additional safeguards.

Do not process by default
Includes: personal employee data (payroll, HR records, medical information), client financial data (contract values where NDA-restricted, fee proposals, margin calculations shared under NDA), commercially sensitive client information covered by explicit confidentiality clauses, security-sensitive site information (access codes, alarm systems, critical infrastructure details), individual subcontractor pricing and rates, personal data relating to building occupants or patients.
Required controls: Written approval from Commercial Director or MD before processing. Data anonymisation or pseudonymisation where feasible. Processing log reviewed by data owner within 48 hours. Data deleted within 24 hours of processing completion.

Amber — Controlled

Data that can be processed through AI workflows with standard controls, human review and audit trail requirements.

Standard controls apply
Includes: tender documents (specifications, schedules, drawings, PQQs), RAMS and method statements, variation narratives and commercial correspondence, contract reports and QBR data, CAFM ticket data and SLA reporting, financial data exported from Sage 200 for reporting purposes (contract-level, not individual), standard company information used for PQQ and compliance responses, site survey information and job-specific technical data.
Required controls: Human review of all outputs before use. Source traceability on every extracted item. Output labelling (draft/reviewed/approved). Processing log maintained. Data retained only for the duration of the workflow cycle.

Green — Open

Data that can be processed through AI workflows with minimal additional controls beyond standard operating procedures.

Minimal controls
Includes: publicly available information (regulatory guidance, British Standards references, CIBSE/BSRIA guidance), internal templates and standard text libraries, company capability statements and accreditation details, generic assumptions libraries, standardised report formats and structure templates, published product specifications and technical data sheets.
Required controls: Standard output review. No additional approval gates or processing logs required beyond normal workflow records.
Section 03

Approval Gates

The approval process for AI-assisted outputs, scaled by output type and risk level. Every output passes through at least one human review gate before use.

1
AI produces
structured draft
Automated
2
Competent reviewer
checks & modifies
Mandatory
3
Senior approver
signs off
Risk-dependent
4
Output issued
or submitted
Final
Output typeRisk levelGate 2: ReviewerGate 3: ApproverBefore issue
RAMS & safety documentationHighHSQE Manager or competent H&S personOperations DirectorBoth gates mandatory. Signed record.
Client-facing commercial submissionsHighQS or Commercial ManagerCommercial DirectorBoth gates mandatory. Submission log.
Tender responses & bid documentsMedium-HighEstimating LeadCommercial Director (bids >£500k)Gate 3 for high-value bids only.
Monthly contract reportsMediumContract ManagerNot requiredGate 2 only. Standard review.
Variation narratives & notice draftsMediumQS or Contract ManagerCommercial Director (values >£50k)Gate 3 for high-value claims.
Internal summaries & action logsLowWorkflow user (self-review)Not requiredGate 2 only. Self-review acceptable.
QBR packs & board reportsMediumFinance Director or Commercial DirectorMDBoth gates for board-level outputs.
Non-negotiable rule. No AI-assisted output is issued to a client, submitted as part of a tender, included in safety documentation, or used as the basis for a commercial claim without at least one competent human review. The human reviewer is accountable for the content — not the AI.
Section 04

Audit Trail Requirements

What records must be maintained for every AI-assisted output, and how those records should be stored and accessed.

RecordWhat it containsRetentionOwner
Processing logDate, time, workflow type, input documents (filenames, page counts, classification), processing steps completed, any errors or exceptions flagged.12 months minimumBuilt AI
Output version recordDraft version (as produced by AI), reviewed version (after human modifications), final version (as approved). Track changes or diff record showing modifications.Contract + 6 yearsHartwell
Review and approval recordReviewer name, date, time, modifications made (summary), approval status (approved / approved with changes / rejected), approver name and date where Gate 3 applies.Contract + 6 yearsHartwell
Data handling recordClassification of input data (Red/Amber/Green), any anonymisation applied, confirmation of data deletion post-processing (where required), any exceptions or escalations.12 months minimumShared
Incident logAny errors, inaccuracies, near-misses or concerns identified during review. Root cause, corrective action, whether the issue was systemic or isolated.Duration of engagementShared
Practical implementation. Built AI will provide a lightweight audit trail template that integrates with each workflow. Reviewers complete a simple approval form (name, date, status, notes) at the point of review, taking less than 2 minutes per output.
Section 05

Safe Operating Boundaries

Clear boundaries defining what AI workflows can and cannot be used for, and the escalation process for edge cases.

AI workflows can be used for

Extracting and structuring scope items from tender documents
Drafting assumptions, exclusions and clarification queries
Generating structured variation narratives and notice drafts
Producing monthly margin snapshots and WIP summaries
Assembling evidence packs and indexing supporting documents
Drafting RAMS content from task and hazard data (with H&S review)
Pre-populating compliance responses from standard libraries
Generating report narratives, action logs and meeting summaries

AI workflows must not be used for

Making final pricing or commercial decisions
Signing or certifying safety documentation
Providing engineering design calculations or certifications
Making employment, HR or disciplinary decisions
Issuing contractual notices without human review and approval
Replacing competent person roles (CDM, RAMS approval, fire risk)
Processing personal data without explicit classification and controls
Communicating with clients on behalf of Hartwell without approval

Escalation process

TriggerActionEscalation to
Unclear data classificationProcessing should not begin until classification is confirmed by the data owner.Commercial Director
Output accuracy concernConcern is logged in the incident log. Output is corrected before approval.Workflow Lead + Built AI
Client enquiry about AIResponse follows the procurement disclosure posture (Section 06). No disclosure without prior agreement on wording.Commercial Director
Regulatory or contractual changeFramework is reviewed and updated before continuing with affected workflows.MD + Built AI
Near-miss or incidentIncident is formally logged and a root cause review is conducted within 5 working days.MD + Built AI
Section 06

Procurement Disclosure Posture

Hartwell's recommended position on disclosing AI usage to clients, procurement teams and contracting authorities.

Recommended disclosure position

Proactive, factual and confident. Hartwell should be prepared to disclose that AI tools are used to support document production, analysis and workflow efficiency — and should frame this as a quality and governance strength rather than a risk.
Core statement“Hartwell M&E Group uses AI-assisted tools to support document structuring, scope extraction, reporting and quality assurance. All AI-assisted outputs are reviewed and approved by competent personnel before issue. AI does not make decisions, sign certifications or replace competent person roles.”
When asked in PQQDisclose the use of AI tools as part of the quality management response. Reference the governance framework, human review gates, data classification model and audit trail. Position as a strength.
When asked informallyConsistent with the core statement. Emphasise human review, data controls and output quality. Offer to provide the governance framework summary if helpful.
When not askedNo obligation to volunteer disclosure unless contractually required. However, proactive disclosure in quality management sections of tenders can differentiate Hartwell positively.
Competitive advantage. Most M&E contractors using AI informally have no governance framework, no data classification and no disclosure position. Hartwell's ability to demonstrate controlled, governed AI usage creates a genuine procurement advantage over competitors who cannot answer these questions.
Section 07

Implementation & Review

How the framework is adopted, maintained and updated over time.

ActivityDetailFrequencyOwner
Framework onboardingAll workflow users complete a 30-minute onboarding session covering data classification, approval gates, output labelling and escalation procedures.At Phase 1 startBuilt AI + Hartwell
Quarterly governance reviewReview incident log, escalation records and any framework exceptions. Assess whether controls are proportionate and effective.Quarterly (Phase 1)Commercial Director + Built AI
Annual framework reviewFull review of data classification model, approval gates, disclosure posture and safe operating boundaries.Annually (Phase 2+)MD + Built AI
Incident root cause reviewFormal review within 5 working days of any near-miss or incident. Document root cause and corrective action.As triggeredWorkflow Lead + Built AI
New workflow assessmentBefore any new workflow type is deployed, a governance assessment confirms data classification, approval gates and output types.Per new workflowBuilt AI
Up next
FP · Flight Plan
← Or back to the Operational Intelligence Audit page