AI-assisted risk review
Documentation status: tutorial — see Maturity and evidence.
Purpose
The assistant helps a reviewer understand the case; it does not become the source of truth for identity, authorization, validation or transaction boundaries.
Bounded context
Build the assistant context from structured runtime information:
current RiskRequest
+ Customer projection allowed for this user
+ related RiskIndicators
+ RiskReviewProcess state
+ existing RiskDecision draft
+ authorized published actions
+ relevant constraints and explanations
This is preferable to sending an unrestricted database dump.
Allowed tasks
The assistant may summarize indicators, explain why a rule or threshold was reached, identify missing information, draft a decision explanation or suggest the next authorized action. Any execution request still goes through a published action and normal runtime validation.
Human control
If policy requires human approval, encode that requirement in the process. AI output is then a proposal or explanation attached to the case; it is not a final decision until the model-defined validation step succeeds.
Traceability
Store provenance for AI-assisted output when it affects review: model/provider version where relevant, request/process identity, input context version, timestamp and whether a human accepted, edited or rejected the proposal.