Verification
Consequence-Based Review Gate
Scale evidence, independence, expertise, approval, monitoring, and rollback to the realistic harm caused by an incorrect AI-assisted result.
- Format
- Decision Path
- Level
- Intermediate
- Audience
- Practitioner, Developer, Operator, Leader
- Owner
- Project42 Editorial
- Review cadence
- Every 90 days
- Prerequisites
- A proposed AI-assisted output or action and its intended use
Classify consequence before reviewing
Estimate credible harm across people, safety, rights, privacy, money, operations, security, compliance, reputation, and reversibility. Include scale, affected groups, detectability, time to recovery, and whether an error can trigger an external action. Do not lower the level because the output sounds confident or the model is usually accurate.
Low consequence work may need a reasonableness check. Moderate consequence work needs source comparison, tests, edge cases, and a named reviewer. High consequence work needs current authoritative evidence, independent review, relevant domain expertise, explicit approval, a safe execution boundary, monitoring, and a tested rollback or recovery plan.
Complete the review gate
Use safe labels for protected data and link to authorized evidence. A model-provided risk rating is input to the gate, not the final authorization decision.
Output or action: [WHAT WILL BE USED OR DONE]
Affected people and systems: [SCOPE]
Credible harms: [SAFETY, RIGHTS, PRIVACY, MONEY, OPERATIONS, SECURITY]
Reversibility and recovery time: [ASSESSMENT]
Consequence level: [LOW | MODERATE | HIGH]
Required evidence: [SOURCES, TESTS, REPRODUCTION]
Required reviewer: [PEER | DOMAIN EXPERT | SECURITY | LEGAL | OWNER]
Approval before action: [ROLE OR NONE]
Execution boundary: [READ-ONLY | REVERSIBLE | PRIVILEGED | EXTERNAL]
Monitoring and stop signal: [OBSERVABLE CONDITION]
Rollback or recovery: [TESTED PROCEDURE]
Decision: [APPROVE | REVISE | REJECT | ESCALATE]Expected evidence and verification
The expected evidence is a review record linking the consequence level to required evidence, qualified reviewers, approval, execution controls, monitoring, and recovery. The final decision names an accountable person or role.
Challenge the classification with a plausible worst case and an affected-user perspective. Verify every required check actually ran, reviewers are independent enough for the consequence, approval is fresh, and rollback works in the real boundary. Reclassify when scope, data, audience, automation, or external impact changes.