AI Governance
AI that drafts and explains. It never decides.
Every enterprise buyer now asks what our AI touches. Here is the whole answer, including the part where we tell you what it deliberately cannot do.
The line that matters
The credit decision is not AI.
SCREDIT decides using a weighted scorecard that you configure — your components, your weights, your risk bands. It is deterministic: the same inputs produce the same score today and when someone asks about it six months from now, and any score can be taken apart into the factors that produced it.
That is not a gap we are apologising for. Trade credit decisions get questioned — by an auditor, by a sales director who wanted a higher limit, occasionally by the customer who was declined. A number a model produced and nobody can reconstruct is indefensible in all three conversations.
So AI works around the decision, not inside it.
What it does
Three jobs, all of them advisory.
These are the places where a generated draft saves an analyst real time without taking anything away from their judgement.
Explains a score
Turns the factors behind a risk score into plain-language reasoning an analyst can put in front of an approver, or a customer who asks why.
Reads statements
Maps extracted line items to standard metrics, flags figures that do not sit right, and drafts a narrative from the resulting ratios — for a person to review.
Drafts the follow-up
Credit memos, next-best collection actions, and customer emails at the right tone — every one held for a human to approve before it sends.
How it is governed
What happens before a model is called.
Every AI request runs the same path, in this order. None of it is optional and none of it depends on a person remembering to follow a procedure.
Your policy, first
Before anything runs, the request picks up the model settings, prompt configuration, and safety rules that your organisation has been configured with. AI behaviour is set by policy, not baked into the product.
A safety check
The request is evaluated against your safety rules before it is allowed to proceed.
Masked before the model sees it
Sensitive values are masked in a dedicated step that runs before the request leaves for the model. This is the answer to “does our customer data go into an LLM?” — the model receives a masked payload.
Recorded, every time
Each execution is written down: what ran, for whom, and what came back. AI use is as auditable as any other action in the platform.
A person approves
Generated drafts stay drafts. An email is not sent, and a memo is not filed, until someone with the authority to do it says so.

What it will not do
The list we are asked for most.
Approve or decline a credit application.
Set or change a credit limit.
Send an email, a memo, or a statement to your customer without a human approving it.
Act on a customer record outside a workflow you configured.
Learn from your data to train a model we sell to anyone else.
What security reviews ask.
Does AI make the credit decision?
No — and this is deliberate rather than a limitation we are working around. The decision is produced by a weighted scorecard you configure: the same inputs produce the same score today and in six months, and every score decomposes into the components that drove it. An opaque model that cannot be defended to an auditor, a regulator, or a customer who was declined has no business making a credit decision. AI sits around that decision, explaining and drafting; it does not make it.
Does our customer data get sent to a third-party model?
Requests run through a masking step before they leave for the model, so sensitive values are not transmitted in the clear. The AI features are built on a managed cloud AI service under our own account and guardrail configuration rather than a consumer product, and every execution is recorded. If your security review needs the specifics — which provider, which region, what is masked — ask us and we will answer precisely rather than in generalities.
Can AI send an email to our customer without us seeing it?
No. Drafting and sending are separate steps by design. A generated email or memo is held in a draft state with an explicit approval before anything leaves the system, and the approval is recorded against it. There is no configuration that turns this off.
Can we turn AI features off?
Yes. AI behaviour is configured per organisation — which features are enabled, which model settings apply, and what safety rules run. A credit team that wants none of it can operate the platform with the features disabled, because the decisioning, routing, and receivables workflows do not depend on them.
Does the AI cite its sources?
Not today, and we would rather say so than imply otherwise. The ability to register source documents exists, but grounded citations are not yet wired into the generation path, so a narrative is not currently returned with references to the policy documents behind it. When that ships, it will appear here.
How do we explain this to our auditor?
The short version: the decision is deterministic and reproducible, AI output is advisory and recorded, and nothing customer-facing is sent without a human approving it. Each of those is a property of the system rather than a procedure your team has to follow, which is usually the distinction an auditor is testing for.
For the wider security and compliance picture, see the Trust Center.
Bring your AI governance questionnaire.
We would rather answer it on a call than have you infer the answers from a marketing page. Most of it is above; the rest we will answer directly.