Skip to content

AI Governance

AI that drafts and explains. It never decides.

Every enterprise buyer now asks what our AI touches. Here is the whole answer, including the part where we tell you what it deliberately cannot do.

The line that matters

The credit decision is not AI.

SCREDIT decides using a weighted scorecard that you configure — your components, your weights, your risk bands. It is deterministic: the same inputs produce the same score today and when someone asks about it six months from now, and any score can be taken apart into the factors that produced it.

That is not a gap we are apologising for. Trade credit decisions get questioned — by an auditor, by a sales director who wanted a higher limit, occasionally by the customer who was declined. A number a model produced and nobody can reconstruct is indefensible in all three conversations.

So AI works around the decision, not inside it.

What it does

Three jobs, all of them advisory.

These are the places where a generated draft saves an analyst real time without taking anything away from their judgement.

Explains a score

Turns the factors behind a risk score into plain-language reasoning an analyst can put in front of an approver, or a customer who asks why.

Reads statements

Maps extracted line items to standard metrics, flags figures that do not sit right, and drafts a narrative from the resulting ratios — for a person to review.

Drafts the follow-up

Credit memos, next-best collection actions, and customer emails at the right tone — every one held for a human to approve before it sends.

How it is governed

What happens before a model is called.

Every AI request runs the same path, in this order. None of it is optional and none of it depends on a person remembering to follow a procedure.

Your policy, first

Before anything runs, the request picks up the model settings, prompt configuration, and safety rules that your organisation has been configured with. AI behaviour is set by policy, not baked into the product.

A safety check

The request is evaluated against your safety rules before it is allowed to proceed.

Masked before the model sees it

Sensitive values are masked in a dedicated step that runs before the request leaves for the model. This is the answer to “does our customer data go into an LLM?” — the model receives a masked payload.

Recorded, every time

Each execution is written down: what ran, for whom, and what came back. AI use is as auditable as any other action in the platform.

A person approves

Generated drafts stay drafts. An email is not sent, and a memo is not filed, until someone with the authority to do it says so.

The AI credit memo view on a SCREDIT credit application, labelled AI-generated, review before use. A completed pipeline shows five stages in order — governance, safety check, prompt build, PII masking and model dispatch — followed by the model used, the time taken and the token count, and a note that the request was processed locally. Below is the drafted memo itself, covering company profile, financial position, bureau results, references, what the file lacks, and what the reviewer should confirm. It ends by stating that the memo summarises the file and does not decide it. Approve and attach, or reject, are the only ways forward.
AI credit memo — the guardrails it passed through, and a draft that waits for a humanSCREDIT demo environment · illustrative data, not a customer

What it will not do

The list we are asked for most.

Approve or decline a credit application.

Set or change a credit limit.

Send an email, a memo, or a statement to your customer without a human approving it.

Act on a customer record outside a workflow you configured.

Learn from your data to train a model we sell to anyone else.

What security reviews ask.

Does AI make the credit decision?

No — and this is deliberate rather than a limitation we are working around. The decision is produced by a weighted scorecard you configure: the same inputs produce the same score today and in six months, and every score decomposes into the components that drove it. An opaque model that cannot be defended to an auditor, a regulator, or a customer who was declined has no business making a credit decision. AI sits around that decision, explaining and drafting; it does not make it.

Does our customer data get sent to a third-party model?

Requests run through a masking step before they leave for the model, so sensitive values are not transmitted in the clear. The AI features are built on a managed cloud AI service under our own account and guardrail configuration rather than a consumer product, and every execution is recorded. If your security review needs the specifics — which provider, which region, what is masked — ask us and we will answer precisely rather than in generalities.

Can AI send an email to our customer without us seeing it?

No. Drafting and sending are separate steps by design. A generated email or memo is held in a draft state with an explicit approval before anything leaves the system, and the approval is recorded against it. There is no configuration that turns this off.

Can we turn AI features off?

Yes. AI behaviour is configured per organisation — which features are enabled, which model settings apply, and what safety rules run. A credit team that wants none of it can operate the platform with the features disabled, because the decisioning, routing, and receivables workflows do not depend on them.

Does the AI cite its sources?

Not today, and we would rather say so than imply otherwise. The ability to register source documents exists, but grounded citations are not yet wired into the generation path, so a narrative is not currently returned with references to the policy documents behind it. When that ships, it will appear here.

How do we explain this to our auditor?

The short version: the decision is deterministic and reproducible, AI output is advisory and recorded, and nothing customer-facing is sent without a human approving it. Each of those is a property of the system rather than a procedure your team has to follow, which is usually the distinction an auditor is testing for.

For the wider security and compliance picture, see the Trust Center.

Bring your AI governance questionnaire.

We would rather answer it on a call than have you infer the answers from a marketing page. Most of it is above; the rest we will answer directly.