# AI Governance Framework

Implementing robust, efficient AI governance structures is crucial for overseeing the development, deployment, and operation of AI systems. Effective governance ensures that AI systems perform reliably, ethically, and align with organizational goals throughout their lifecycle. This requires establishing and continuously maintaining clear frameworks and control management practices. Identifying and mastering AI risks is a central obligation for Unique. It ensures that AI systems can be implemented with confidence, knowing that there are structures in place to manage any potential risks effectively.

The Unique AI Governance Framework is designed to ensure the reliability, factual accuracy, and integrity of outputs generated by its AI platform. This framework adheres to current good industry standards for responsible AI, including principles outlined in FINMA Guidance 08/2024 and relevant international standards like Singapore Model AI Governance Framework. The Unique AI governance structure encompasses the following key pillars: AI Governance, Inventory and Risk Classification, Data Quality, Testing & Continuous Monitoring, Documentation, Explainability, and Independent Reviews - all supported by the Unique’s ISO 42001 certification.

# Key Pillars of the Unique AI Governance Framework

Unique has created their own AI governance principles, which has been thoroughly operationalized and built in throughout the entire Unique AI platform.

## Trust

**Trust** is foundational for AI adoption, especially for agentic systems that act autonomously. By demonstrating consistent, ethical AI behavior aligned with client values, we enable both end-users and stakeholders to confidently deploy AI agents that make decisions and take actions on their behalf.

- Responsible AI guidelines and policies: [Unique AI Policy](https://docs.unique.ai/security-and-compliance/ai-governance-framework/unique-ai-policy)

- Active stakeholder engagement to collectively promote transparency in AI, such as AI Roundtables (e.g. [AI Governance White Paper (Part III): Industry Leaders' Opinions](/content/en/blog/industry-leaders-opinions-insights-from-industry-leaders/index.html))

- [**Unique AI Academy**](https://uniqueai.efrontlearning.com/start): Role-specific training covering AI fundamentals, agentic AI workflows, governance best practices, and responsible use of autonomous AI tools, ensuring clients interact with AI agents confidently and appropriately.

- Unique AI [Compliance Layer](https://docs.unique.ai/security-and-compliance/compliance/compliance-layer-3-0)

- Responsible AI culture (e.g. mandatory compliance trainings and awareness campaigns)

- Strong community with membership such as:

- [AI Verify Foundation](https://docs.unique.ai/security-and-compliance/ai-governance-framework/ai-verify-foundation)

- IMDA Spark Programme - Singapore ( [https://www.imda.gov.sg/how-we-can-help/imda-spark](https://www.imda.gov.sg/how-we-can-help/imda-spark))

- POC together with LatticeFlow on technical assessment of FINMA guidelines: [Unique AI x LatticeFlow AI: Introducing FINMA-Aligned Technical Blueprint](/content/en/blog/unique-ai-x-latticeflow-ai-introducing-finma-aligned-technical-blueprint/index.html)

## Safety & Security

**Safety & Security** ensures agentic AI operates within legal and regulatory guardrails while protecting against agent-specific risks like unauthorized tool access, unintended actions, and cascading failures. Robust security controls and compliance frameworks enable safe deployment of autonomous AI capabilities.

### **Organisational standards**

- System and Organization Controls 2 (SOC2/ISAE 3000): [SOC 2](https://docs.unique.ai/security-and-compliance/compliance/certifications/soc-2-type-2)

- FINMA Circular Audit: [FINMA Outsourcing Circular 2018/3](https://docs.unique.ai/security-and-compliance/compliance/certifications/finma-outsourcing-circular-2018-3)

- ISO 27001, 9001 and 42001: [ISO Certifications](https://docs.unique.ai/security-and-compliance/compliance/certifications/iso-certifications)

- EU AI Act Conformity Assessment: [EU AI Act: Unique's view](https://docs.unique.ai/security-and-compliance/ai-governance-framework/eu-ai-act-unique-s-view)

### **Individual standards**

- End-User Terms and Conditions (T&Cs)​ - available upon request

- Legal contracts - available upon request

### **Product standards**

- Adherence to Open Worldwide Application Security Project (OWASP) Frameworks such as

- [OWASP Top 10 for LLM Applications 2025](https://docs.unique.ai/security-and-compliance/it-security/owasp-top-10-for-llm-applications-2025)
- Alignment according to the Monetary Authority of Singapore: [Generative AI Guardrails in Banking](https://docs.unique.ai/security-and-compliance/it-security/owasp-top-10-for-llm-applications-2025/generative-ai-guardrails-in-banking)

- [MCP Governance Framework](https://docs.unique.ai/security-and-compliance/ai-governance-framework/mcp-governance-framework-v1-0)

- Use-case-specific threat modeling analyzing agent capabilities, data access, tool permissions, and potential failure modes before deployment.

- Unique’s Secure Software Development Lifecycle (SSDLC)

## Accountability

**Accountability** establishes clear responsibility chains for both human operators and AI agents. Every action, whether by user or agent, is traceable, auditable, and attributed to specific identities. This includes role definitions, access rights, agent permission boundaries, and escalation protocols for autonomous decisions.

- Workspace concept (easy configurable way to limit access to files)​ [Folder (Scope) Access Permissions](https://docs.unique.ai/administrators/knowledge-base-for-admins/folder-scope-access-permissions)

- [Responsible AI in Practice](https://docs.unique.ai/users/general-ai-practices/responsible-ai-in-practice)

- BYO model to control for weights, training data, etc. ​

- Role concept and Privilege Access Management (PAM)​: [Access Role Concept](https://docs.unique.ai/it-operators/identity-and-access-management-iam/access-role-concept)

- [Audit logs](https://docs.unique.ai/it-operators/operations/security-and-data-privacy/audit-logs) ​

- [Data Leakage Prevention](https://docs.unique.ai/it-operators/operations/security-and-data-privacy/data-leakage-prevention-dlp) (DLP)​

- Threat Modelling workshops with relevant stakeholders

## Reliability & Robustness

Reliability & Robustness encompasses continuous validation of agent performance across tools, tasks, and workflows. We systematically monitor agent success rates, error patterns, and decision quality, enabling proactive corrections before issues impact operations or cascade across multi-agent systems.

- FSI Benchmarking by use case to avoid model drift and data drift​: [Benchmarking](https://docs.unique.ai/administrators/models-llm-management/benchmarking)

- LLM as a judge: [Hallucination Evaluation](https://docs.unique.ai/administrators/space-management/helper-resources/hallucination-evaluation)

- Prompt Engineering guide: [Prompting Guide Unique AI](https://docs.unique.ai/users/general-ai-practices/introduction-to-prompting/prompting-guide-unique-ai)

- PCO together with LatticeFlow on technical assessment of FINMA guidelines: [https://www.unique.ai/en/blog/unique-ai-x-latticeflow-ai-introducing-finma-aligned-technical-blueprint](/content/en/blog/unique-ai-x-latticeflow-ai-introducing-finma-aligned-technical-blueprint/index.html)

- Meta data filtering

## Explainability & Transparency

**Explainability & Transparency** means users understand not just what AI outputs, but what agents do and why. Full visibility into agent reasoning, tool selection, and action chains ensures human oversight remains meaningful and agents remain aligned with intended goals throughout autonomous workflows.

- Retrieval augmented generation (RAG) with link to source document (doc highlighting) for traceability: [RAG Assessment and Improvement](https://docs.unique.ai/administrators/research/rag-evaluations/rag-assessment-and-improvement)

- Hallucination score​: [Hallucination Evaluation](https://docs.unique.ai/administrators/space-management/helper-resources/hallucination-evaluation)

- Data quality in source documents​: [Knowledge Base for End Users](https://docs.unique.ai/users/knowledge-base-for-end-users)

- Agent execution steps visible to end users

- Watermarking AI Generated content

- Human-in-the loop concept

- Elicitation

- User [feedback](https://docs.unique.ai/administrators/insights-measurement/feedback) loop
