Trust Centre
AI governance policy
How HMR designs, deploys and oversees AI systems, including the agents we build for clients.
Version 1.0 · Last reviewed 27 September 2026 · Owner: Chief Technology Officer
Principles
We build AI to take work off people, not to take decisions away from them. Four principles apply to every AI system HMR designs, deploys or runs, including the agents we build for clients:
- People stay accountable. Every AI system has a named business owner who answers for what it does.
- Risk decides the level of control. The more an action could cost, harm or expose, the more human review it gets.
- Everything is recorded. If we cannot show what an AI system did and why, it does not go live.
- Data stays within its boundary. An AI system reads and writes only the data its task needs.
Human oversight
- Before an agent goes live, the client and HMR classify each action it can take as low or higher risk. Examples of higher risk are payments, changes to customer records, messages to customers and anything that cannot be undone.
- Low-risk actions may run automatically. Every higher-risk action waits for a named person to approve it, and the agent cannot approve its own work.
- Any authorised person can pause or stop an agent at any time. Stopped runs can be rolled back where the underlying system allows it.
- Agents act under their own scoped identities, never under a person's account, and hold no standing administrator rights.
Data use
- Client data is used only for the task the client has approved. It is never used to train or fine-tune models, ours or a provider's, unless the client asks for that in writing.
- Personal data is kept out of prompts where the task does not need it, and masked where it does.
- Prompts, outputs and logs are stored in the client's environment, or in the region the contract names, and kept only for the period the contract sets.
Model providers
- We use only model providers and models the client has approved, in the regions it has approved, on terms that exclude training on the client's data.
- We record which model and version each system uses. A change of model is treated like any other change: tested, reviewed and approved before it goes live.
- We prefer designs that let a client change provider without rebuilding the system.
Monitoring and incidents
- Every agent decision, tool call and approval is logged with a timestamp and the identity behind it.
- We monitor live systems for errors, unexpected costs and outputs outside agreed limits, and alert the business owner when a limit is crossed.
- If an AI system acts in a way that could cause harm, we stop it first and investigate second. The client is told without undue delay, and the incident is handled under our security incident process.
Review cycle
- This policy is owned by HMR's Chief Technology Officer and reviewed at least once a year, and sooner when the law or our services change.
- Each live AI system we run for a client is reviewed with its business owner at least every six months, including a sample of logged actions and approvals.
- Changes to this policy are recorded with a new version number and date on this page.