AI policy: data governance & safety

This AI policy defines how Innowise governs data and AI use across client engagements. It sets requirements for data handling, AI development, third-party AI tools, security controls, human oversight, and accountability. The policy provides a consistent basis for protecting client data and addressing applicable legal and contractual requirements.

The AI company policy applies throughout the AI lifecycle to Innowise employees, contractors, and other authorized parties involved in AI-related work. It covers data accessed, processed, stored, transferred, or otherwise used in connection with AI systems, subject to any stricter project-specific requirements.

For the purposes of this policy, the client acts as the data controller and AI deployer, while Innowise acts as the data processor and AI system provider. Where applicable law or a project agreement assigns additional or different responsibilities, those requirements take precedence.

Core principles of responsible AI

These principles apply to every AI engagement Innowise delivers. They define the baseline for responsible data use and the controls our teams follow throughout the AI lifecycle.

Data minimization

Innowise limits data collection and processing to what the approved AI use case requires. Any data used in an engagement must have a defined purpose, with access and retention limited to that purpose. Data that is no longer required should not remain in active use.

Transparency and explainability

AI systems must be documented according to their purpose and risk. Relevant stakeholders must be able to understand the system’s use of data and the basis of its outputs. Known limitations that may affect how those outputs are interpreted must also be documented.

Human oversight

Human review is required where AI output may materially affect people or business operations. The level of oversight must reflect the risk and regulatory context of the use case. AI output does not replace human approval where such approval is required.

Fairness and non-discrimination

AI systems must be assessed for unfair or discriminatory outcomes relevant to their intended use. Identified risks must be documented and addressed before deployment, with controls matched to their likely impact.

Accountability

Responsibility for AI governance decisions must be assigned across the lifecycle. Records must identify who approved material decisions and what controls were applied. Significant changes to the system or its data must also be reviewable.

Data covered by this policy

The AI policy covers the main categories of data Innowise may handle during AI engagements. Protection measures depend on data sensitivity and its role in the project.

Personal and sensitive data

Personal and sensitive data includes names, contact details, financial records, health information, and other information that may identify an individual. Innowise restricts access to authorized project roles and uses approved environments for handling such data.

Proprietary business data

Client records, pricing information, operational data, and internal processes fall under proprietary business data. We treat them as confidential, restrict access to authorized project roles, and limit their use to the agreed engagement.

AI training and evaluation data

Training and evaluation datasets may be used to train, fine-tune, validate, or benchmark AI models. Innowise documents their source and approved purpose while restricting access according to project requirements.

Synthetic and anonymized data

This category covers synthetic datasets and copies of real data with direct identifiers removed. Where the data can still be linked to an individual, as is commonly the case with pseudonymized rather than fully anonymized records, Innowise applies the same access restrictions as the source data. For datasets used to train or fine-tune models, Innowise also assesses the risk that a model may retain and reproduce fragments of its training data and adds controls where that risk is material to the use case.

Credentials and system secrets

Authentication credentials, encryption keys, API tokens, and other system secrets must never be submitted to or processed by AI tools. This restriction applies across all engagements, regardless of data tier or project context.

Safe data handling

Data security applies at every stage of an AI engagement. Before client data enters an AI workflow, Innowise defines the rules for its collection and use. The same requirements remain in force during development and production.

Data collection and scoping

Before client data is introduced into an AI workflow, the team determines what information the system actually needs and where it comes from. Any restrictions on its use are documented at this stage. Innowise keeps collection within the agreed project scope, and data without a defined project purpose must not enter the workflow.

Data storage and access

Client data is kept in approved project environments with access limited to people whose responsibilities require it. Innowise assigns permissions according to project roles and reviews them when responsibilities change. Project requirements also determine whether access activity needs to be logged or reviewed. Data at rest and in transit is protected using encryption appropriate to the sensitivity of the information and the requirements of the project.

Data used in training and evaluation

When client data is used to train, fine-tune, validate, or evaluate a model, the team records what data is involved and how it may be used. Access remains limited to the approved project context. Where the technical task allows it, synthetic or anonymized datasets can reduce unnecessary exposure of identifiable information during testing.

Production data handling

Before deployment, Innowise reviews how production data will move through the system and where processing will take place. The team also defines who may access that data. The production setup follows the security requirements agreed for the project, including controls required for sensitive or regulated information.

Data retention and removal

Client data is kept only for the period defined for the project or required by an applicable obligation. When that period ends, Innowise follows the agreed process for returning or deleting the data. The project team also records any approved exceptions that require data to remain available longer.

Source code and model artifacts

Client source code, proprietary datasets, and model weights developed or fine-tuned during an engagement are treated as client-owned assets for the purposes of this policy, subject to the applicable project agreement. They are not reused on other projects, retained beyond the agreed engagement scope, or submitted to third-party AI tools without explicit client approval.

AI governance in the development process

AI governance starts before technical work begins and remains part of development, release, and later updates. Innowise defines how AI can be used within each project and applies controls according to the system’s purpose, risk, and operating context.

Governance scoping

Before development begins, the team defines how AI will be used in the solution and what level of oversight the use case requires. Innowise records the intended purpose and relevant risk factors. Responsibility for governance decisions is also assigned before technical work moves forward.

Development controls

During development, AI components follow the architecture and engineering rules agreed upon for the project. Changes to models, prompts, datasets, or AI logic must remain traceable through the development workflow. Access to AI development environments follows the roles defined for the engagement.

Model review and evaluation

Before an AI model or feature is cleared for release, the team evaluates its behavior against the agreed use case and acceptance criteria. Testing focuses on risks identified for the project. Where relevant, that includes unreliable outputs, discriminatory behavior, or other issues that could affect how the system is used. Where a system accepts external inputs, testing also covers prompt injection, unintended data leakage through model outputs, and other adversarial misuse patterns relevant to the deployment context. Material findings are addressed before release.

Deployment approval

AI functionality moves into production after the required project reviews are complete. Innowise checks that the deployed version matches the approved configuration and that required human review points remain in place. Changes that materially affect model behavior or data use go through review before release.

Monitoring and change control

Governance continues after deployment. The project setup defines which aspects of system behavior require monitoring and how issues are escalated. Model updates and other material changes are reviewed against the governance requirements already established for the project.

Third-party AI tools governance

Any third-party AI platform, foundation model, or automated component must be reviewed and formally approved before it is used in a client project or connected to an operational environment. Innowise evaluates vendors against the intended use, the data involved, and the risks the integration may introduce.

Data handling

We review what data the provider receives, where it is processed, how long it may be retained, and whether submitted information can be used to train or improve the provider’s models.

Security and compliance

Innowise assesses the vendor’s security controls and available compliance documentation against the requirements of the client environment and the type of data involved.

Contractual terms

We check the terms governing confidentiality, data access, and permitted use. Any restrictions relevant to the project are recorded before the tool is approved.

Integration fit

The team reviews how the tool will connect to the client architecture and what systems or data it will be able to access. Formal approval and applicable procurement requirements must be completed before the integration moves into operational use.

Employee responsibilities & disciplinary actions

Everyone involved in AI work at Innowise is accountable for how they use AI tools and handle project data within their assigned role. Team members must follow applicable data classifications, use approved tools, respect access restrictions, and review AI-generated output before it is used in project work. Project leads are responsible for making sure these requirements are understood and followed within their teams.

Violations of this AI acceptable use policy are reviewed based on their nature and severity. Confirmed breaches may result in disciplinary action under applicable company policies.

Compliance frameworks

The frameworks below give clients and auditors a concrete way to check whether AI controls address the security, privacy, quality, and sector-specific requirements relevant to the project.

  • ISO 9001. Innowise holds ISO 9001:2015 certification for quality management, covering documented processes and consistent project controls across software delivery.
  • ISO 27001. Innowise holds ISO 27001:2022 certification for information security management, with controls relevant to access management and risk-based handling of sensitive data in AI engagements.
  • ISO 27017. Innowise holds ISO 27017:2015 certification for cloud-specific information security controls relevant to AI workloads running on cloud infrastructure.
  • ISO 27018. Innowise holds ISO 27018:2019 certification for the protection of personally identifiable information processed in public cloud environments.
  • ISO 13485. Innowise holds ISO 13485:2016 certification for medical device quality management systems, relevant where AI is used in medical software or devices.
  • OWASP. Where AI functionality is exposed through applications, APIs, or connected software interfaces, we align with relevant OWASP guidance, including the OWASP Top 10 for LLM Applications where generative AI components are involved.
  • FDA. For AI-enabled healthcare products targeting the US market, our engineering approach is built to support applicable FDA requirements based on the product scope.
  • EU MDR. For AI used in medical devices intended for the EU market, we align with relevant EU MDR requirements.
  • HIPAA. Where protected health information is involved, our AI engineering approach is built to support applicable HIPAA requirements for data handling and security.
  • GDPR. For AI systems processing personal data, our approach is built to support applicable GDPR requirements around data protection and accountable processing.

Enforcing accountability & clients’ rights

Clients have the right to understand how their data and AI systems are governed throughout an engagement. Innowise provides access to relevant project evidence and uses agreed response procedures when security exceptions or material drift are identified.

Operational evidence and audit support

Clients can request information on data use, model documentation, evaluation results, known limitations, and governance controls applied during the project. Innowise also provides available project records within the agreed scope to support internal or external audits.

Data removal and correction

Clients can request removal or correction of project data under the terms agreed for the engagement. Requests are documented and handled through the project’s established data management process.

Security exceptions and drift

The project agreement or SLA defines notification and response windows for confirmed security exceptions or material drift in data processing or model behavior. Clients receive an initial notice within the agreed timeframe and further updates as the investigation progresses.

Accountability enforcement

Innowise assigns governance ownership and review checkpoints for each AI engagement. Material incidents, significant model changes, and approved exceptions are documented for follow-up and audit review. These records provide a traceable basis for checking whether agreed controls were applied and whether corrective action was completed.

Changes to the policy

Innowise reserves the right to update this AI corporate policy as governance practices, regulatory requirements, or internal controls evolve. Any changes will be published on this page or elsewhere on the company’s websites.

This version was last updated on 18 August 2026, and historic versions can be obtained by contacting Innowise.

Contact details

If you have any questions about this AI corporate data governance & safety policy, its application to an AI engagement, or Innowise data governance practices, please contact:

Innowise | privacy@innowise.com

Table of contents

    Contact us

    Book a call or fill out the form below and we’ll get back to you once we’ve processed your request.

    Send us a voice message
    Attach documents
    Upload file

    You can attach 1 file up to 2MB. Valid file formats: pdf, jpg, jpeg, png.

    By clicking Send, you consent to Innowise processing your personal data per our Privacy Policy to provide you with relevant information. By submitting your phone number, you agree that we may contact you via voice calls, SMS, and messaging apps. Calling, message, and data rates may apply.

    You can also send us your request
    to contact@innowise.com
    What happens next?
    1

    Once we’ve received and processed your request, we’ll get back to you to detail your project needs and sign an NDA to ensure confidentiality.

    2

    After examining your wants, needs, and expectations, our team will devise a project proposal with the scope of work, team size, time, and cost estimates.

    3

    We’ll arrange a meeting with you to discuss the offer and nail down the details.

    4

    Finally, we’ll sign a contract and start working on your project right away.

    arrow