Daily AI briefing
Traceable AI: What to Record in Customer-Facing Workflows
Short answer: To keep AI decisions traceable, record the purpose, data used, model version, human oversight, and any corrections. Follow ICO guidance on accountability and individual rights, and consider the Algorithmic Transparency Recording Standard.
Why traceability matters in customer-facing AI
When your team uses AI in customer-facing workflows, every decision can have a direct impact on individuals. Whether it's a credit scoring tool, a chatbot that handles complaints, or a system that triages service requests, you need to know why a particular outcome occurred. The Information Commissioner's Office (ICO) makes clear that accountability is a core principle of data protection law. You must be able to demonstrate compliance, not just claim it.
Traceability is the practical side of accountability. It means keeping records that allow you to reconstruct what the AI did, why it did it, and how you responded. This is essential for handling customer queries, correcting errors, and defending your decisions if challenged.
- AI decisions can affect customers' rights and expectations.
- Traceability means being able to explain and justify decisions.
- Recording is not just good practice; it is a legal requirement under UK GDPR.
The accountability principle: what the ICO expects
The ICO's guidance on AI and data protection emphasises that accountability is not a tick-box exercise. It requires you to take responsibility for your AI systems and to be able to show how you comply. This includes having clear roles and responsibilities, training staff, and maintaining documentation.
The ICO also notes that you must use a risk-based approach. You need to assess the risks to individuals' rights and freedoms, and decide what measures are appropriate. Recording these assessments is key. If you cannot show what you considered and why, you cannot demonstrate accountability.
The ICO's guidance is currently under review due to the Data (Use and Access) Act, so you should stay updated and seek professional advice where needed.
- The ICO expects senior management to understand and oversee AI risks.
- You must embed data protection by design and default.
- A risk-based approach means recording the risks you identify and how you mitigate them.
Recording at each stage of the AI lifecycle
The ICO explains that individual rights apply at every point where personal data is used in the AI lifecycle. This includes training data, deployment data, and the model itself. To support these rights, you need to keep records at each stage.
During design, document the purpose of the AI system and the lawful basis for processing. If you conduct a DPIA, keep it as a living document. The ICO says a DPIA is a roadmap for identifying and controlling risks, so update it as the system evolves.
During training, record what data you collected, how it was pre-processed, and the model version. The ICO notes that pre-processing is still processing under data protection law, so you must treat it accordingly. Keep logs of any transformations that might affect identifiability.
During deployment, record the input data for each decision, the output, and whether a human reviewed it. This is crucial for answering 'why did this happen?' questions. Also record any corrections made after the AI's output, as these are part of the decision history.
- Design stage: record the intended purpose, the lawful basis, and the DPIA.
- Training stage: record the data sources, pre-processing steps, and model version.
- Deployment stage: record the input data, the model's output, and any human review.
- Monitoring stage: record performance metrics, incidents, and corrections.
Individual rights and what to record for requests
The ICO's guidance on individual rights in AI systems highlights that training data can be personal data, even if it has been pre-processed or stripped of obvious identifiers. If a customer can be 'singled out' from the data, you must be able to respond to their rights requests.
To do this, you need to know what data you hold and where it came from. Record the sources of training data and any transformations applied. If you cannot identify an individual in the training data, you must be able to demonstrate that. The ICO says you should not dismiss requests as manifestly unfounded just because they are difficult to fulfil.
For rectification, the ICO notes that individual inaccuracies in training data may be less important for the model's overall performance, but you still must consider each request. For erasure, you are unlikely to have a justification to refuse if the data is not needed for the model's purpose. Keep records of these requests and your responses.
If you outsource AI services, your contract must require the processor to assist you with rights requests. Record the contractual terms and any joint controller arrangements.
- You must be able to respond to access, rectification, and erasure requests.
- Training data may be personal data even if it lacks identifiers.
- Record how you handle requests and any difficulties you encounter.
Using the Algorithmic Transparency Recording Standard
The UK Department for Science, Innovation and Technology (DSIT) has published the Algorithmic Transparency Recording Standard. It is designed for public sector organisations, but the principles apply to any organisation using AI. The standard asks you to record information about the algorithmic tool, including its purpose, the data it uses, and the decisions it supports.
Adopting this standard can help you create consistent records that are easy to audit. It also aligns with the ICO's expectation that you document your AI systems. You can adapt the standard to your professional services context, focusing on customer-facing workflows.
The DSIT toolkit also includes other resources, such as the AI Assurance Toolkit, which can help you evaluate the reliability and fairness of your AI systems. Recording the results of these evaluations is part of traceability.
- The Algorithmic Transparency Recording Standard is a UK government framework.
- It helps you document the purpose, data, and oversight of algorithmic tools.
- Even if not mandatory for your sector, it provides a useful template.
Practical checklist for your operations team
To put traceability into practice, follow this mini-runbook when deploying or using AI in customer-facing workflows:
1. Assign a named owner for AI governance. The ICO says senior management must understand and be accountable for AI risks.
2. Conduct a DPIA before launch, and revisit it whenever the system changes. Record the risks you identify and the measures you take.
3. For each customer interaction, log the input data, the model's output, and any human intervention. Store these logs securely and retain them according to your data retention policy (which you should also document).
- Define roles: who is responsible for AI oversight and record-keeping?
- Create a DPIA and update it regularly.
- Log every AI decision with input data, output, and human review.
- Maintain a version history for models and training data.
- Document all rights requests and your responses.
- Use a standard template, such as the Algorithmic Transparency Recording Standard.
Frequently asked questions
What key records should we keep for AI traceability?
You should record the purpose of the AI system, the data used for training and deployment, the model version and any changes, the human oversight process, and any decisions or corrections made. This supports accountability and individual rights requests.
Do we always need a Data Protection Impact Assessment (DPIA)?
The ICO requires a DPIA for AI that involves systematic and extensive evaluation of personal aspects, or other high-risk processing. Even if not mandatory, a DPIA helps document risks and decisions, which is essential for traceability.
How do individual rights apply to training data?
Training data may still be personal data even if pre-processed or lacking identifiers. You must be able to respond to rights requests if individuals can be identified, directly or indirectly. Record how you handle such requests and any difficulties.
What is the Algorithmic Transparency Recording Standard?
The Algorithmic Transparency Recording Standard, from the UK government, provides a framework for documenting algorithmic tools. While designed for the public sector, it offers a useful template for professional services to record purpose, data, and oversight.
Sources
- Accountability and governance implications of AI — Information Commissioner's Office
- Ensuring individual rights in AI systems — Information Commissioner's Office
- Responsible AI Toolkit — UK Department for Science, Innovation and Technology