What we prove

What our framework proves — and what it does not.

Every compliance supplier tells you what you get. Almost none will tell you where their product stops. This page does both, because the second half is the part that decides whether the first half is worth anything.

Nothing here is a marketing position. It is how the product is built, and you can hold us to every line of it.

What it proves

Every promise has one named record.

An AI policy that says "we use AI responsibly" is a poster. It cannot answer the only question a regulator actually asks, which is show me. So every commitment your policy makes comes with one thing your business does and one record that either exists or does not. There is no third state.

These are the nine commitments, and the record that proves each one.

What the policy commits to The record that proves it Re-confirmed
Scope — which people, tools and activities the policy governs The approved tools and people list, dated at its last review. every three months
Approved tools, and the process for requesting a new one The tool request log — one line per request, showing who asked, what was decided and when. once a year
What may never be entered into an AI tool: personal data of customers or staff, confidential client material, credentials, anything under NDA Signed acknowledgement forms, one per employee, held for as long as they are employed. every three months
Verification of output before it is used or sent externally, and who carries responsibility when it is wrong The check recorded on the file, matter or job — who verified it and when. once a year
Where a human decision is mandatory rather than advisory The list of mandatory human decision points, and for each decision taken, a record of who took it. once a year
Disclosure — when the business tells a customer that AI was used The disclosure wording, and a note of every place it appears. once a year
Record keeping and retention for AI-assisted work The retention schedule, showing each record type and its period. once a year
Breach of the policy: reporting route and disciplinary position The breach log — including the entries that came to nothing, because an empty log and a log nobody keeps look identical. once a year
Review cycle, named policy owner, and the signature block The signed and dated policy itself, plus the date the next review falls due. once a year
What we leave blank

One column arrives empty, on purpose.

Your schedule has a column headed “Where it is held”, and we deliver it empty every time.

We know what record each promise requires. We do not know whether your business holds it, and we are never going to guess — because a pre-filled schedule is a false statement about a business that has not been told it has work to do. A half-completed schedule is a true statement about a business that has.

You fill it in once. After that it ages: each record carries how often it must be confirmed again, and we tell you which ones have gone out of date and who owns them. That is what the annual fee is for — not a document you already have.

How it is written

Six of your documents are never written by a model.

Most of your pack is written against your own answers and the law as it stands today, and a person at Ops Intel is accountable for all of it. But where the content is dictated by statute rather than by your business, generating it is the wrong tool entirely: asked for a data processing agreement, a model reliably produces something that reads perfectly and has quietly dropped a term the Regulation requires.

So these are built from fixed sources we maintain, and no model is asked for them at all:

  • AI Test Cases — What to Check Before You Trust It
  • Controls and Evidence Schedule
  • Data Access Register
  • Data Access Request and Justification
  • GDPR Data Processing Addendum — Per AI Tool
  • Where a Person Must Look
What it does not prove

Where our product stops.

It is not a certificate, and it does not say you are compliant.

Nobody can sell you compliance as an object. What you get is the documentation, the controls and the records a regulator asks for, written against how your business actually uses AI. Whether you then follow them is the part only you can do.

It is not legal advice — take the finished pack to your solicitor.

We write the compliance documents and we read the instruments they are built on. Where your own liability sits is a different question, and it is one for a solicitor. So once you have worked through the pack and filled in the parts only you can, we would recommend taking it to yours for final sign-off. That is the right last step, and it is a much shorter conversation when you arrive with the documents already written.

We have not audited your business.

Everything in your pack is written from the answers you gave us. We have not been through your systems, spoken to your staff or checked that what you told us is what happens. A supplier who has not visited you cannot certify you, whatever their documents look like.

A document is true on the day it is delivered.

Your business changes, your tools change and the law changes. That is the whole reason the framework renews annually with legal updates included, and the reason every record in your schedule carries a date by which it needs confirming again.

Your file

We delete it when you leave.

While you are covered we hold what you told us, because the “what this means for your business” half of a legal update is written from it. When your cover ends and is not renewed, everything you told us and everything we wrote for you is destroyed — 30 days after the term ends, so a late payment or a card retry never costs anybody their file.

What survives is the ordinary commercial record: who bought what, when, and for how much, the way any business keeps its invoices.

Questions

The ones worth asking any supplier.

Does buying a framework make my business compliant?

No, and no supplier can honestly say otherwise. A framework gives you the documentation, the controls and the records a regulator asks for, written against how your business actually uses AI. Following them is the part only you can do.

Have you audited my business?

No. Everything in your pack is written from the answers you give us. We have not been through your systems, spoken to your staff, or checked that what you told us is what happens day to day. A supplier who has never visited you cannot certify you, whatever their documents look like.

Is any of this legal advice?

No. We write the compliance documents and we read the instruments they are built on; where your own liability sits is a question for a solicitor. Once you have worked through the pack and filled in the parts only you can, we would recommend taking it to yours for final sign-off.

Why is a column of my schedule empty?

Because we do not know where your records are held, and filling it in with a guess would turn your schedule into a false statement you had signed. You complete it once, and from then on we track which records have gone out of date and who owns them.

What happens to my data if I do not renew?

Everything you told us and everything we wrote for you is deleted a short grace period after your cover ends. Only the commercial record of the purchase survives, the way any business keeps its invoices.

Ask us the awkward version of any of this.

If a supplier cannot tell you where their product stops, that is the answer to your question. Bring us the version you were not sure you were allowed to ask.

Book a free compliance call
Call Now Claim Your Free Audit