HLD Group
AI governance & responsible use
Risk management for AI systems in products and operations.
Last updated: 24 July 2026
Version 1.0 · Review cycle: 365 days · View all frameworks
1. Purpose
This policy establishes how HLD Group governs the responsible development, procurement, deployment, and use of artificial intelligence systems. It ensures our AI is lawful, safe, fair, transparent, and accountable, and that AI-specific risks are identified and managed throughout the system lifecycle.
2. Scope
This policy applies to all AI and machine-learning systems developed, procured, deployed, or operated by HLD Group, including systems built for customers, and to the personnel who build and operate them. It applies in addition to our security, privacy, and data governance policies, which continue to apply to AI systems.
3. Definitions
- AI system — a machine-based system that infers, from input, how to generate outputs such as predictions, recommendations, or decisions
- Foundation and general-purpose model — a broadly capable model adaptable to many tasks
- High-risk AI — an AI use that poses significant risk to health, safety, or fundamental rights, as characterised by applicable law
- Automated decision-making — a decision made without meaningful human involvement
- Model card and system documentation — records describing an AI system’s purpose, data, performance, and limitations
4. Governing principles
- Lawfulness — AI complies with applicable law, including privacy, anti-discrimination, consumer, and sector regulation
- Human oversight — meaningful human control is maintained over consequential decisions
- Fairness — AI is assessed and managed for unfair bias and discriminatory impact
- Transparency — the use of AI is disclosed appropriately, and its behaviour is explainable to the degree needed
- Safety and robustness — AI is tested for reliability, security, and resistance to misuse
- Accountability — a named owner is responsible for each AI system and its risks
- Privacy and data governance — training and operational data are handled under our data policies
5. Legal and framework alignment
- ISO/IEC 42001:2023 (AI management systems)
- NIST AI Risk Management Framework (AI RMF 1.0)
- Regulation (EU) 2024/1689 (EU AI Act), including its risk-tiered obligations and transparency duties
- ISO/IEC 23894 (AI risk management) and ISO/IEC 42005 (AI system impact assessment)
- Privacy Act 1988 (Cth) and GDPR, including GDPR Article 22 on automated individual decision-making
- Applicable anti-discrimination and consumer protection law in each market
6. Risk classification and impact assessment
Each AI use case is classified by risk. Higher-risk uses require a documented AI impact assessment covering purpose, affected people, data, foreseeable harms, bias, mitigations, human oversight, and monitoring, before deployment. Uses prohibited or restricted under applicable law are not deployed.
7. Data governance for AI
- Training and evaluation data are lawfully sourced, with rights and consents documented
- Personal data used in AI is handled under the Data Processing and Data Classification Policies, with data minimisation applied
- Data quality, representativeness, and provenance are assessed to reduce bias and error
- Customer and confidential data are not used to train shared models without explicit authorisation
8. Development, testing, and validation
- AI systems are developed under the Secure Development Policy with AI-specific testing added
- Performance, robustness, and bias are evaluated against defined criteria before release
- Security testing addresses AI-specific threats such as prompt injection, data poisoning, and model extraction
- System documentation, including model cards and known limitations, is produced and maintained
9. Transparency and human oversight
- Users are informed when they are interacting with an AI system or AI-generated content where required
- Consequential decisions retain meaningful human review, with the ability to contest or seek human intervention
- Explanations of AI-influenced decisions are available to the extent needed and required by law
10. Monitoring and incident handling
Deployed AI systems are monitored for performance drift, emerging bias, misuse, and safety issues. AI incidents are handled under the Incident Response Policy, and material harms are escalated and, where required, reported. Systems that cannot be operated safely are withdrawn.
11. Roles, exceptions, and review
Each AI system has a named owner; an AI governance function under the CISO oversees this policy. Exceptions require documented approval; legal prohibitions cannot be waived. This policy is reviewed at least annually and as AI regulation and standards evolve.
Related frameworks
For contractual attestations or audit packs, contact [email protected].