SEE A DEMO
Close

Best Practices in Trust and Explainability for AI in Digital Communications Governance

Trust and explainability in AI

Best Practices in Trust and Explainability for AI in Digital Communications Governance

Artificial intelligence is transforming how organizations supervise and govern digital communications. Across highly regulated sectors like financial services, AI-powered Digital Communications Governance and Archiving (DCGA) platforms are helping compliance teams manage growing communication volumes, identify risk faster, and improve operational efficiency.

But as the adoption of AI-powered DCGA solutions accelerates, a critical question continues to emerge from customers, regulators, auditors, and legal teams alike: Can the AI be trusted? The answer depends heavily on explainability and governance. For example FINRA’s Regulatory Notice 24-09, reminds firms using Gen AI tools for “the review of electronic correspondence, for instance” that “policies and procedures should address technology governance, including model risk management, data privacy and integrity, reliability and accuracy of the AI model.” For technology providers delivering AI into regulated environments, trust and explainability are no longer optional features—they are foundational requirements. 

This article sets out the best practices in trust and explainability that organizations should expect when adopting AI-driven DCGA solutions, including validating and understanding AI-based detections.

1. Check for Robust Explainability Reporting

Regulators expect firms to understand and explain how AI-driven decisions are reached. Organizations cannot rely on opaque AI models that generate unexplained alerts; they need AI systems with a robust explainability framework capable of providing a defensible, auditable rationale behind detections.

Explainability reporting is a key mechanism for documenting, communicating, and auditing how AI systems make decisions. In practice, leading DCGA platforms tackle this by integrating native explainability reports and features to provide compliance teams with the defensibility and clarity needed to understand exactly why a model identified specific content as a risk.

Summarized AI Decisions 

Where an AI classifier detects a potential compliance, conduct, data privacy, or security risk, the platform should provide the explicit rationale behind the decision. Rather than simply flagging a communication as risky, it must offer transparency into why a detection occurred, which indicators triggered the alert, and what contextual evidence contributed to the outcome.

A best-practice feature to look for is plain-language explanation directly within the platform.  Within Theta Lake’s platform, the detection annotation feature provides a straightforward rationale for the triggering of a particular AI risk detection, including detections that span multiple channels or modalities like video, voice, chat and AI interactions. If a conversation triggers a collusion detection, the system might point to specific phrases or indicators as evidence of an attempt to obscure information. This audit-ready summary allows human reviewers to easily verify alerts and defend subsequent decision making.

Model Risk Cards

Organizations should expect structured, transparent documentation from vendors describing how individual AI models operate across their lifecycle. A prime example of this best practice are Theta Lake’s Model Risk Cards which provide structured documentation describing how its AI models operate, including model purpose and intended use, data sources, performance metrics, known limitations, bias and risk considerations as well as validation and monitoring procedures.

These reports provide transparency into the AI lifecycle and help organizations assess whether models align with regulatory, operational, and governance expectations.

2. Expect Active Model Governance and Monitoring

Organizations need practical mechanisms to validate AI performance and continuously improve detection quality over time. The most effective DCGA platforms incorporate several best practices to support trustworthy AI oversight.

Built-In Audit Reporting 

Continuous monitoring requires built-in capabilities that track the performance of risk detections over time. Features like Theta Lake’s built-in classifier audit reports generate top-level statistics regarding the frequency of positive or negative examples across the organization. These metrics serve as a continuous feedback loop to track false negatives and false positives, and can be shared with internal and external stakeholders to demonstrate ongoing AI oversight. 

Context Feedback Loops

Firms need the ability to refine AI accuracy using real-world reviewer interaction. Through Theta Lake’s AI Compliance Advisor, human reviewers can actively confirm, reject, or mark a detection as a false positive (FP), training the system through direct operational feedback.

AI Summarization For Auditing Workflows

When reviewing lengthy and complex conversations that span multiple platforms and modalities, having concise summaries of the detection rationale significantly streamlines the process.  In Practice Theta Lake embeds these summaries directly alongside flagged content.  Compliance teams can leverage these automated summaries directly within their review and audit workflows to validate complex interactions at a glance.

Human-in-the-Loop Controls

Firms must retain full operational control by having the ability to enable or disable specific AI risk detections at any time. Compliance teams should also be able to manage the risk sensitivity of AI detections. For example, categorizing a detection as risky, informational or validation  in Theta Lake’s platform enables organizations to adjust aggregated conversation risk scores and effectively control and prioritize which conversations are routed for human review.

3. Require Independent Certification and Assurance

In parallel with integrated features, the provision of robust, auditable protocols by vendors for the oversight and governance of their AI models is paramount. Financial services firms should assess whether third-party service providers align with recognized international frameworks:

  • ISO/IEC 42001 Certification: Launched as the global benchmark for trustworthy AI, ISO/IEC 42001 for Artificial Intelligence Management Systems (AIMS) sets out a certifiable framework to ensure AI is developed and deployed responsibly. Technology providers that achieve independent ISO/IEC 42001 certification—such as Theta Lake—provide verifiable, independently audited assurance to demonstrate compliance with responsible AI standards, enabling regulated institutions to safely leverage AI. This article explains more about the ISO/IEC 42001Certification and the assurance it provides
  • CSA STAR for AI Level 2: This certification builds on the ISO/IEC 42001 framework by integrating the Cloud Security Alliance (CSA) AI Controls Matrix. It delivers macro governance, granular security, and continuous validation to address bias mitigation, model risk management, algorithmic explainability, and training data privacy.
  • Traditional Third-Party Assurance and Audits: Vendors must continue to assess AI vulnerabilities and systemic risks as part of independent third-party reviews such as SOC 2 Type II, ISO 27001, PCI DSS, and TruSight audits. These frameworks provide consistent, repeatable and measurable protocols that demonstrate compliance with articulated controls critical to AI development.

Takeaway: An AI Explainability Checklist

When evaluating the AI governance aspects of a Digital Communications Governance and Archiving platform, financial services firms can use the following best practices as an evaluation checklist:

  1. Explainability and Audit Reporting: Does the platform provide audit-ready, plain-language summaries explaining the specific reasons that triggered an AI risk detection, backed by comprehensive model cards?
  2. ISO/IEC 42001 Compliance: Has the vendor established, implemented, and maintained an Artificial Intelligence Management System (AIMS) certified by an independent third party?
  3. CSA STAR for AI Level 2: Has the vendor achieved this certification to demonstrate specialized cloud AI safety, compliance, and operational transparency?
  4. Third-Party Framework Attestations: Does the vendor maintain broader third-party audits (like SOC 2 Type II and ISO 27001) that explicitly cover model development and administrative access?
  5. Human-in-the-Loop Controls: Can compliance teams review AI decisions, adjust risk sensitivity levels, and enable/disable specific AI classifiers to maintain ultimate operational control?
  6. AI Performance Transparency: Does the platform provide built-in audit reporting to track metrics like false positive rates and model performance over time?

Author

  • Stacey English

    Stacey English is Director of Regulatory Intelligence for Theta Lake. She has over 25 years' experience in financial services regulation and technology as a former regulator at the now FCA and as a risk and compliance practitioner in global banks and insurers. She formerly led Regulatory Intelligence for Thomson Reuters providing regulatory and industry insight to financial services firms. Stacey is also a qualified accountant, a published author on conduct and accountability and an Honorary Fellow of Cambridge Judge Business School providing expert guidance on regulation.