AI is already changing how people get answers, complete tasks, and move work forward.
An employee can get quick guidance on benefits in seconds. A client team can move faster because information is easier to access and understand. Routine questions can be handled seamlessly, giving teams more time to focus on the work that matters most.
That impact is real, and so are the expectations that come with it.
If AI becomes part of the client experience, it must meet the same standard as everything else we deliver. That means reliability, accountability, transparency, and trust can’t be optional additions layered on afterward. They must be designed into the process from the beginning.
To that end, we’re formalizing that approach through ISO/IEC 42001, the international standard for managing AI systems through an Artificial Intelligence Management System (AIMS).
This isn’t a shift in direction. It’s a continuation of how we already approach technology and client service with deliberate design, clear ownership, and accountability for outcomes.
For our clients, that means AI isn’t being introduced as an experiment. It’s being implemented within defined boundaries, supported by governance, and operated with ongoing oversight.
When It’s Done Right, AI Improves the Experience
We’ve been intentional about how AI is introduced into our platform and workflows.
Today, we use AI in a small number of focused ways designed to improve the experience for employees, clients, and internal teams. In the moments that matter, it can help surface information faster, support employees with real-time answers, and streamline operational workflows behind the scenes.
The goal is simple: Make the experience better, faster, and more intuitive.
But as those experiences evolve, the standard itself doesn’t change. Speed only matters if it comes with trust.
Whether an answer comes from a person or a system, our responsibility remains the same. The output still needs to be accurate, understandable, reliable, and something we can stand behind.
AI changes the speed of delivery, not the standard of accountability.
Why AI Requires a Different Governance Approach
Traditional software generally behaves the same way every time it runs. AI systems are different.
Outputs can vary based on context, prompts, retrieved information, or changes to the underlying model. The same question may not always produce the same answer. As systems evolve, behavior can shift over time in ways that aren’t always immediately visible.
That variability is part of what makes AI powerful, but it also introduces new operational and governance challenges.
Without the right structure, organizations can lose consistency, visibility, and accountability over time. Risk can emerge gradually through inaccurate outputs, unclear ownership, unintended data exposure, or decisions that become difficult to explain or validate.
Those aren’t tradeoffs we’re willing to make.
Governance for AI can’t stop at deployment. It has to extend across the full lifecycle: evaluating use cases, defining ownership, validating outputs, monitoring performance, managing change, and continuously reassessing risk as systems evolve.
Designing AI With Accountability Built In
We approach AI the same way we approach any technology that impacts clients or employees, with accountability built into the design process from the start.
In practice, that means establishing clear ownership for AI-enabled workflows, validating outputs before they reach users where appropriate, and monitoring performance over time to maintain consistency and reliability.
It also means defining where human oversight remains essential. AI can improve speed and efficiency, but judgment, escalation, and accountability still belong to people.
If something is delivered through our platform, whether generated by a person or supported by AI, we own the outcome.
That principle guides how these systems are introduced, governed, and continuously improved.
Protecting Data by Design
Trust starts with how data is handled.
When we use AI, we do so within strict operational and security boundaries. Employee data isn’t used to train or enrich AI models. Data remains isolated within controlled platform environments, and we work with enterprise-grade providers under governed agreements and defined usage controls.
We also evaluate how AI-enabled workflows interact with broader security and privacy controls, including access management, logging, data classification, retention practices, and vendor oversight.
AI systems shouldn’t exist outside an organization’s existing control environment. They should operate within it.
These safeguards aren’t treated as optional enhancements. They’re foundational requirements for how AI is deployed responsibly.
No Black Boxes in the Client Experience
AI should make experiences clearer and more efficient, not more opaque.
That’s why we focus on keeping outputs understandable and reviewable, maintaining transparency around where AI is involved, and ensuring oversight exists where it matters most.
Clients should be able to trust the information they receive, and we should be able to explain how that information was produced and what controls support it.
Explainability and accountability become increasingly important as AI becomes more embedded into operational workflows and client experiences.
Trust depends not only on whether systems work, but whether organizations can govern them responsibly over time.
Governance Has to Be Operational
AI governance only works if it becomes part of day-to-day operations.
Policies and principles are important, but governance can’t exist only on paper. Organizations need repeatable processes for evaluating AI use cases, reviewing changes, validating outputs, managing vendors, monitoring performance, and responding when something behaves unexpectedly.
That operational discipline becomes increasingly important as AI expands across platforms, workflows, and client-facing experiences. Without consistency, organizations risk fragmented oversight and unclear accountability.
Our focus is building governance that scales alongside adoption, so innovation can move forward without compromising trust, reliability, or security.
In practice, that means quality over scope. We remain deliberate about where AI adds meaningful value, where human judgment remains essential, and how these systems should evolve responsibly over time.
Why We’re Implementing ISO 42001
As AI becomes more embedded in how work gets done, governance must scale with the same level of care. That’s why we’re implementing ISO 42001 to manage our AI systems through an Artificial Intelligence Management System (AIMS).
In practical terms, an AIMS defines how an organization governs AI across its lifecycle: identifying risk, assigning ownership, implementing controls, validating outcomes, and continuously improving oversight as systems evolve.
AI adoption is accelerating faster than many traditional governance models were designed to support. Organizations across industries are introducing AI into customer experiences, operational workflows, and decision-support systems while regulatory expectations and industry standards continue to mature in parallel.
ISO 42001 provides a structured framework for introducing consistency and accountability early, before AI adoption becomes difficult to govern retroactively.
As we build our AIMS, we begin with scope and visibility by understanding which AI-enabled capabilities are in use, what data they interact with, where decisions are made, and where human oversight remains in place.
From there, governance becomes operationalized through defined ownership, documented processes, risk and impact assessments, validation requirements, monitoring activities, and escalation paths when something doesn’t behave as expected.
We also evaluate AI-specific risks, including accuracy, transparency, privacy boundaries, unintended bias, and how system behavior could evolve over time. Those findings are translated into practical controls that support reliability and accountability in day-to-day operations.
This work fits naturally into our broader security and compliance journey. Over time, we have invested in certifications, independent validation, and mature operational controls to help safeguard client and employee data while continuously improving how we manage risk.
ISO 42001 extends that same discipline into how we design, deploy, and operate AI systems.
The Standard We Intend to Keep
AI will continue to evolve quickly, and expectations around how it should be governed will continue evolving alongside it.
We believe organizations shouldn’t have to choose between innovation and accountability. The systems that create better experiences should also be designed with clear ownership, measurable controls, transparent responsibility, and thoughtful oversight from the beginning.
That’s the standard we intend to keep as AI becomes more integrated into how we support clients and employees.
Our investment in ISO 42001 reflects a broader belief that trust isn’t something added after innovation happens. It has to be built into the process itself.
Because technology moves quickly, but accountability should remain constant.
Extending Our Standard of Care
AI will continue to evolve. The expectations around it will, too.
What won’t change is how we approach the work.
When a client relies on us, whether that interaction is powered by a person, a system, or AI, they are trusting us to get it right. To be clear. To be consistent. To stand behind the outcome.
AI becomes part of that same loop of delivery and accountability.
Put simply: We set expectations upfront, maintain visibility as systems run, and stay accountable for outcomes.
Formalizing our approach through ISO 42001 is how we ensure that standard holds as we scale.
For our clients and partners, this provides confidence that AI is being deployed intentionally, governed consistently, and held to the same standard as every other part of our platform. And as we learn, iterate, and expand what AI can do, the management system behind it ensures we do so without compromising trust.
Because in the end, this isn’t about adopting new technology. It’s about making sure that everything we build reflects the same level of care, accountability, and trust our clients expect from us every day.




