Decision inputs
Facts that change the policy answer
For this request, party identifiers, ownership information and screening results is the input boundary and a possible match assessment is the output boundary. A useful check makes both explicit.
- 1Task and owner
- Compliance analyst wants to screen a party for sanctions risk. The request needs an accountable owner for a possible match assessment, even when the tool prepares most of the first draft.
- 2Information involved
- Party identifiers, ownership information and screening results. Check uploads, history and connected systems before describing the request as low sensitivity.
- 3Tool and account
- An approved company account. Treat a new plug-in or connector as a change to the approved setup.
- 4Intended result
- The expected result is a possible match assessment. The policy needs to know what happens after generation, including publication, communication and automated use.
- 5Consequence if it is wrong
- Name similarity can create false matches while missed ownership links carry serious risk. This is the fact most likely to move the request from routine handling into review.
- 6Human review
- sanctions compliance owner should inspect, change, reject or stop the result. The reviewer needs the source material and must be able to reject the output before it takes effect.
Possible policy routes
The task name alone cannot decide it.
A published workplace policy can return different answers for the same task. These are the practical branches worth encoding.
A routine policy route may be possible
The lower-friction route begins when the exact account is approved, only the minimum personal and company information is used, a possible match assessment remains within the stated purpose, and sanctions compliance owner reviews it before use.
Approval may be required
Specialist approval becomes relevant if the account or data handling is uncertain, name similarity can create false matches while missed ownership links carry serious risk, or a possible match assessment reaches people or systems beyond the requester’s authority.
The request may need to stop or change
The proposed use should pause if restricted information would enter an unapproved service, the output would act before sanctions compliance owner can intervene, or use authoritative data and require trained review of potential matches cannot be maintained. Consider less information, a controlled account or a non-AI process.
Request checklist
Questions to ask before using the tool
- 01
Which approved account will perform screen a party for sanctions risk, and what external connections can it reach?
- 02
What is the most sensitive element in party identifiers, ownership information and screening results, and does the tool need it?
- 03
Could someone treat a possible match assessment as final even though it was generated as assistance?
- 04
Can sanctions compliance owner inspect the complete result and its source before reliance?
- 05
When must the employee stop and run the policy check again?
Worked request
What the employee should submit
This example supplies decision facts without pasting the underlying material into the approval record.
- requester
- compliance analyst
- task
- Use AI to screen a party for sanctions risk.
- information
- party identifiers, ownership information and screening results
- tool
- An approved company account
- frequency
- Recurring work
- region
- Where the work and affected people are located
- purpose
- Analyse
- impact
- Customer or transaction restriction
- review
- Complete human review
- owner
- sanctions compliance owner
Useful safeguards
Controls that fit this request
- ✓
Use authoritative data and require trained review of potential matches
- ✓
Start with a de-identified sample of party identifiers, ownership information and screening results before considering broader access.
- ✓
Set an expiry or review point when recurring work turns into a permanent process.
- ✓
Link the completed check to the applicable policy version and append later reassessments separately.
Questions people ask
About this AI use
Is using AI to screen a party for sanctions risk automatically allowed?
Permission depends on the facts submitted for this request. A different tool, information class, region or use of a possible match assessment can produce another route.
How specific should the workplace AI request be?
Describe a possible match assessment, identify party identifiers, ownership information and screening results, name the exact tool and account, explain who will receive or rely on the output, and state how sanctions compliance owner will review it.
What belongs in the completed policy record?
Link the completed check to the applicable policy version and append later reassessments separately. A classification and controlled reference may be enough when copying party identifiers, ownership information and screening results would create unnecessary risk.