Trust · Responsible AI

Responsible use of AI

AI assists. Humans own. That is a written policy inside nVisionIT, with a named owner and a review date.

nVisionIT has a Responsible AI Use Policy that governs every use of AI in a client engagement, from a coding assistant to an agentic tool. It is owned by the directors, approved by the CEO, reviewed every six months, and enforced through tool approval, data classification and a named human reviewer on every deliverable. This page is the summary. The policy itself is client-facing and we will send it to you on request.

Microsoft Responsible AI StandardISO/IEC 42001NIST AI RMFKing VPOPIA & Mauritius DPA
The principles

Eight commitments that apply to every engagement

Our programme is aligned to, and interpreted consistently with, the Microsoft Responsible AI Standard, ISO/IEC 42001 for AI management systems, the NIST AI Risk Management Framework, and the technology and information governance principles of the King V Report on Corporate Governance.

Accountability

We remain fully accountable for any AI system used in your environment. People review, verify and approve every AI-generated output.

Fairness

Structured processes to minimise bias in model selection, prompt design, data handling and output evaluation.

Inclusiveness

AI-assisted design and interface output is checked for accessibility to at least WCAG 2.2 AA before delivery.

Privacy

Data minimisation, purpose specificity, consent, secure processing and no exposure of confidential data to external AI platforms without your written approval, under POPIA and the Mauritius DPA.

Transparency

You get clear visibility into how AI functions in your engagement, how outputs are generated and validated, and where AI was used in a deliverable.

Human oversight

Where AI materially informs a decision with legal or similarly significant effects on a person, a competent human makes or meaningfully reviews that decision first. Affected people can request human review.

Security

AI-enabled processes are resilient, governed, and protected from misuse, manipulation and leakage.

Validity

All AI-generated material is quality-checked, tested and verified for accuracy and business relevance before it reaches a deliverable.

Your data

The Zero Exposure Rule

No confidential, regulated, personal or client-owned data may be submitted to an external AI platform unless a contractual agreement exists, the platform meets your security requirements, and explicit written approval has been obtained. There is no informal path around this.

Classified
Content is classified before it is processed
Sensitivity labels drive where it is allowed to go
On-tenant
The most sensitive content stays on our own tenant
Routed to a local model, never to a public API
Risk-tiered
Controls scale with the risk of the use case
High-risk use attracts documentation and validation, disclosed to you

What our people may not do

  • Put client, citizen, confidential or third-party data into a public AI tool without explicit approval
  • Ship AI-generated code without engineer review, testing and named sign-off, or deploy unvalidated code into your environment
  • Use AI in a way that breaches law, contract, privacy requirements or industry standards
  • Generate deceptive, fraudulent or misleading content
Agentic tools

Agentic tools: AI that acts on its own

Agentic tools plan, generate, test, iterate and execute multi-step work on their own. They carry more risk than a coding assistant, so they carry additional controls.

Only where you have agreed in writing

Agentic tools are deployed in a client environment only where that has been explicitly agreed with you in writing. There is no default.

Never wired to live systems without authorisation

They are never connected to production systems or to data stores holding personal or confidential information without your written authorisation and a security review signed off by our Engineering Lead.

Same review, same gates

Anything an agentic tool produces for a deliverable goes through the same human review, validation and quality gates as any other AI-assisted output.

You can ask what it touched

You may request details of any agentic tool used on your engagement, including the scope of access it was granted and the controls applied to it.

Disclosure

You are told where AI was used

We provide a standard Client AI Disclosure whenever AI generated more than incidental content in a deliverable, such as a business requirements document, solution architecture document, specification or design. It is not held back until you ask.

What the disclosure covers

Which AI tools were used and their approved status in our registry; the controls applied, including human review, quality gates, security scanning and the Zero Exposure Rule; how your data was protected during the work; and the human accountability chain, meaning who reviewed it, who approved it and who is answerable for it.

What else you can ask for

Model-usage detail and the registry entries relevant to your engagement, our data-handling procedures and security-configuration evidence, security and audit assurances including ISAE 3402 documentation, and AI risk assessments for a specific use case. Clients with AI restrictions written into their contracts are accommodated case by case.

Governance

Who enforces it, and how

A policy that no one enforces is a brochure. These are the mechanisms that make ours operate.

Board and executive oversight

Consistent with King V, our governing body is accountable for the governance of AI, information and technology. The CEO approves material changes to the policy once it is in force.

A governed tool registry

Only tools on our approved registry may be used on client work. Each entry records security posture, licensing, data residency, risk tier, whether the vendor trains on your data, approved use cases and the approval date.

Named human ownership

Every AI-generated artefact delivered to you is approved by a named engineer or consultant, version-controlled with provenance tagging, and validated against our Definition of Done.

Continuous monitoring

We review model performance and output quality, emerging security risk from AI tooling, compliance under POPIA and the Mauritius DPA, and the effectiveness of the controls themselves, on a set cadence.

Compliance & incidents

What we commit to, and what happens when something goes wrong

Regulatory commitment

POPIA, the Mauritius Data Protection Act 2017 and other applicable data-protection law. Your own data-protection terms and contractual AI restrictions. The Microsoft Responsible AI Standard, ISO/IEC 42001 and the NIST AI Risk Management Framework. King V as the governance framework for AI, information and technology. Mauritius’s National AI Strategy and FAIR Guidelines where an engagement has a Mauritius nexus, and the EU AI Act’s risk-based obligations where it has a European one.

Incidents

Any suspected or confirmed AI-related incident, including data leakage, incorrect output, harmful content or unauthorised access, is escalated immediately for containment and, where required, client notification. We investigate under our POPIA breach protocol, or the Mauritius DPA protocol where Mauritius-based data subjects are involved, which includes notifying the Data Protection Office within 72 hours where feasible. You may request a written incident report once an investigation concludes.

Review cycle

The policy is reviewed every six months, and sooner if the regulatory environment shifts, your contractual requirements change, a new AI capability such as an agentic tool introduces a risk the current policy does not address, or an incident reveals a gap. Material updates are communicated to clients and folded into our standard engagement documentation.

Ask us for the policy

The full Responsible AI Use Policy is client-facing and we will send it to you, along with the tool-registry entries and security evidence relevant to your engagement.