Defining data handling, approval gates, audit trails and safe operating boundaries for AI workflow deployment across the business.
This framework defines the governance controls, data handling rules and approval processes that should be in place before, during and after AI workflow deployment at Hartwell M&E Group.
| Human authority | AI workflows produce structured drafts. Competent human reviewers approve, modify or reject every output before it is used, issued or relied upon. AI does not make decisions. |
| Data minimisation | Only the minimum data required for each workflow is processed. No data is stored beyond the processing cycle unless explicitly required for audit trail purposes and agreed in writing. |
| Traceability | Every AI-assisted output carries a source reference, version identifier and reviewer record. Any output can be traced from final version back to its input data and processing steps. |
| Proportionality | Controls are scaled to risk. Higher-risk outputs (safety documentation, client-facing submissions, commercial claims) require stronger approval gates than lower-risk outputs (internal summaries, draft agendas). |
| Continuous review | The framework is reviewed quarterly during Phase 1 and annually thereafter. Controls are adjusted based on operational experience, incident review and regulatory changes. |
A three-tier classification system determining which data types can be processed through AI workflows, under what conditions, and with what controls.
Data that must not be processed through AI workflows without explicit senior approval and additional safeguards.
Data that can be processed through AI workflows with standard controls, human review and audit trail requirements.
Data that can be processed through AI workflows with minimal additional controls beyond standard operating procedures.
The approval process for AI-assisted outputs, scaled by output type and risk level. Every output passes through at least one human review gate before use.
| Output type | Risk level | Gate 2: Reviewer | Gate 3: Approver | Before issue |
|---|---|---|---|---|
| RAMS & safety documentation | High | HSQE Manager or competent H&S person | Operations Director | Both gates mandatory. Signed record. |
| Client-facing commercial submissions | High | QS or Commercial Manager | Commercial Director | Both gates mandatory. Submission log. |
| Tender responses & bid documents | Medium-High | Estimating Lead | Commercial Director (bids >£500k) | Gate 3 for high-value bids only. |
| Monthly contract reports | Medium | Contract Manager | Not required | Gate 2 only. Standard review. |
| Variation narratives & notice drafts | Medium | QS or Contract Manager | Commercial Director (values >£50k) | Gate 3 for high-value claims. |
| Internal summaries & action logs | Low | Workflow user (self-review) | Not required | Gate 2 only. Self-review acceptable. |
| QBR packs & board reports | Medium | Finance Director or Commercial Director | MD | Both gates for board-level outputs. |
What records must be maintained for every AI-assisted output, and how those records should be stored and accessed.
| Record | What it contains | Retention | Owner |
|---|---|---|---|
| Processing log | Date, time, workflow type, input documents (filenames, page counts, classification), processing steps completed, any errors or exceptions flagged. | 12 months minimum | Built AI |
| Output version record | Draft version (as produced by AI), reviewed version (after human modifications), final version (as approved). Track changes or diff record showing modifications. | Contract + 6 years | Hartwell |
| Review and approval record | Reviewer name, date, time, modifications made (summary), approval status (approved / approved with changes / rejected), approver name and date where Gate 3 applies. | Contract + 6 years | Hartwell |
| Data handling record | Classification of input data (Red/Amber/Green), any anonymisation applied, confirmation of data deletion post-processing (where required), any exceptions or escalations. | 12 months minimum | Shared |
| Incident log | Any errors, inaccuracies, near-misses or concerns identified during review. Root cause, corrective action, whether the issue was systemic or isolated. | Duration of engagement | Shared |
Clear boundaries defining what AI workflows can and cannot be used for, and the escalation process for edge cases.
| Trigger | Action | Escalation to |
|---|---|---|
| Unclear data classification | Processing should not begin until classification is confirmed by the data owner. | Commercial Director |
| Output accuracy concern | Concern is logged in the incident log. Output is corrected before approval. | Workflow Lead + Built AI |
| Client enquiry about AI | Response follows the procurement disclosure posture (Section 06). No disclosure without prior agreement on wording. | Commercial Director |
| Regulatory or contractual change | Framework is reviewed and updated before continuing with affected workflows. | MD + Built AI |
| Near-miss or incident | Incident is formally logged and a root cause review is conducted within 5 working days. | MD + Built AI |
Hartwell's recommended position on disclosing AI usage to clients, procurement teams and contracting authorities.
| Core statement | “Hartwell M&E Group uses AI-assisted tools to support document structuring, scope extraction, reporting and quality assurance. All AI-assisted outputs are reviewed and approved by competent personnel before issue. AI does not make decisions, sign certifications or replace competent person roles.” |
| When asked in PQQ | Disclose the use of AI tools as part of the quality management response. Reference the governance framework, human review gates, data classification model and audit trail. Position as a strength. |
| When asked informally | Consistent with the core statement. Emphasise human review, data controls and output quality. Offer to provide the governance framework summary if helpful. |
| When not asked | No obligation to volunteer disclosure unless contractually required. However, proactive disclosure in quality management sections of tenders can differentiate Hartwell positively. |
How the framework is adopted, maintained and updated over time.
| Activity | Detail | Frequency | Owner |
|---|---|---|---|
| Framework onboarding | All workflow users complete a 30-minute onboarding session covering data classification, approval gates, output labelling and escalation procedures. | At Phase 1 start | Built AI + Hartwell |
| Quarterly governance review | Review incident log, escalation records and any framework exceptions. Assess whether controls are proportionate and effective. | Quarterly (Phase 1) | Commercial Director + Built AI |
| Annual framework review | Full review of data classification model, approval gates, disclosure posture and safe operating boundaries. | Annually (Phase 2+) | MD + Built AI |
| Incident root cause review | Formal review within 5 working days of any near-miss or incident. Document root cause and corrective action. | As triggered | Workflow Lead + Built AI |
| New workflow assessment | Before any new workflow type is deployed, a governance assessment confirms data classification, approval gates and output types. | Per new workflow | Built AI |