Human-in-the-loop
AI drafts; accountable people decide.
How this site implements it
Every AI output is labelled, timestamped and marked 'human review required'. The Knowledge Dojo blocks saving until a reviewer ticks the review box.
How it would work in an enterprise
Named approvers per use case, review recorded in the ticketing or knowledge tool, and no autonomous changes to production without a change record.
Evaluation
Prove quality before widening rollout.
How this site implements it
Outputs use fixed structures and ask the AI to state its confidence and missing information, so weak answers are visible.
How it would work in an enterprise
A golden test set of real (sanitised) cases, accuracy and hallucination checks against it before each wider rollout, and re-testing after model or instruction changes.
Data privacy
No personal or confidential data in AI conversations.
How this site implements it
All data is synthetic, and input screens warn visitors not to paste confidential or personal information.
How it would work in an enterprise
Data classification rules, redaction before sending, approved tools only, and Canadian privacy law considerations reviewed with privacy counsel.
Model risk
Treat AI models as models, with inventory, validation and monitoring.
How this site implements it
OSFI Guideline E-23 Model Risk Management, final September 11, 2025, effective May 1, 2027, brings AI/ML models into scope — illustrative.
How it would work in an enterprise
Each AI use case registered in the model inventory with a risk rating, owner, validation evidence and ongoing performance monitoring.
Audit trail
Every AI call is traceable.
How this site implements it
Each AI call is logged with session, feature and timestamp. Live count for this session is shown below.
AI calls logged this session: 0
How it would work in an enterprise
Centralised logs of who asked what, which model answered, and what was accepted, retained to the records policy.
Cost guard
Spend is bounded and predictable.
How this site implements it
Each visitor session is limited to 10 AI calls per 24 hours; buttons disable when the limit is reached.
How it would work in an enterprise
Per-team budgets, usage dashboards, rate limits and alerts on unusual consumption.