whylearn.ai

Approach

The order the work goes in.

What decides whether an AI deployment holds is almost never in the model. It is whether anybody can say what the tool is allowed to reach. Three principles, then four stages, from a problem you can name to something running on your own systems.

Three principles

Settle the reach

What the AI may touch, on whose authority, on what data, with what record afterwards. Purpose, access, retention and consent get answered as the work is designed, not written up later to justify it. Every AI workflow we build traces back to a stated reason for reaching the data it reaches.

People stay accountable

The software carries the repetition. It does not carry the decision. Every point where it decides something has a review point and a named person against it, and that person stays accountable for what the output is used for.

Controls written for your job

What an AI tool is allowed to do depends on your obligations, your systems and the people doing the work. Generic AI policies fail at the moment they are needed, because nobody recognises their own job in them.

The work

Four stages, from problem to running AI

Stage one

Map the work an AI tool would touch

We trace the process and the data under it. Where it enters, where it gets copied, who it reaches, where it rests, when it goes. This is the same map an AI tool needs in order to be given sensible limits. Two things this map shows that nobody has counted: how many copies of the data exist, and how many people can open something they have no reason to open.

Stage two

Rank what AI can carry, and what blocks it

Which parts of the process an AI tool could take on, and what stands in the way of each, written as specific checkable statements. Not themes. We rank by value and by effort, because a plan that ignores effort never gets started. Each item leaves this stage with an owner.

Stage three

Set the limits it will run inside

What each tool may reach, who signs off on what, what gets logged, and what a person checks before an output is acted on. Written as procedures, in the language of the job. If the person supervising a model cannot follow it on a busy day without asking anyone, then what you have is a note about an intention.

Stage four

Build it, and put it in people’s hands

The AI and the automation get built where the limits are settled, with review points and a record of what the tool did. Then the people who will use it are trained on it, including where to stop and check. Anything still unclear is left out of scope for now, in writing, with what it would take to bring it in.

Definitions

An AI answer is only as good as the definitions under it.

Data protection is knowing what you hold, where it moves and who may see it. Governed reporting is knowing what a figure means, where it came from and who owns it. Point an AI tool at a business question and it asks both at once.

Both fail in the same way. Nobody wrote the definition down. The lineage was never recorded. When the figure got challenged there was no single person accountable for it. So where three teams cannot agree on a figure, we treat that as groundwork for the AI work: one definition, one owner, one query that produces it, and a record of every report it appears in. An assistant asked that question then has one answer to give.

That work belongs inside the audit, not alongside it, and we do not price it as a separate service.

Constraints

What this order costs you

What you get is AI that survives being questioned once it is running, whether the question comes from a regulator, an auditor, a client, or somebody in your own organisation asking where an answer came from. Here is what it costs. It is slower at the start: if you want a tool live this month, you will find we want the first two weeks for establishing what it is allowed to reach. That is a real delay, and we are not going to dress it up as a benefit.

It also produces findings you may not want. Mapping who can open what, ahead of giving a model access to any of it, tends to surface permissions nobody intended to grant, and once that is written down somebody has to deal with it. We will say which of it is quick to fix and which is not. An organisation that would honestly rather not know is taking a reasonable position, and it means we are the wrong firm for them.

The two weeks are what stop the build being unpicked later. That is the whole trade, and we have chosen it deliberately.

And the audit put hours against the processes that cost you most, so there is a number to come back to. Once the AI is live we come back to it, and we say plainly whether those hours moved. A finding that a tool saved less than we expected is worth more to both of us than a case study.

The first step is always the same.

Send us one process. Within five working days we will tell you where AI could take work off it, what would have to be true first, and how far off that looks from here.