The Vendor AI System No One Classified
An AI policy is not enough if live systems cannot be traced to classification rationale, obligations, ownership, evidence and review.
Synthetic scenario. Illustrative only — does not describe any real organisation, supplier, patient, programme or event.
Scenario at a glance
- Industry context
- UK/EU financial services; AI governance; EU AI Act readiness
- Primary persona
- AI Governance Lead
- Trigger event
- Internal audit asks for evidence of the organisation’s position on a live vendor AI recruitment screening system.
- Assurance failure type
- AI inventory gap; unresolved classification; operator-role ambiguity; obligation ownership failure; evidence sprawl; human oversight not evidenced.
- Scenario shape
- Weak signal → missed ownership → unclosed action → missing evidence → assurance failure → business impact
What happened
Meridian Financial Services Group is a fictional UK/EU financial-services organisation with retail banking, insurance and corporate services divisions. It has an AI policy, a model-risk committee, a privacy office, a technology-risk team, procurement controls and a risk committee that receives quarterly AI governance updates.
AI use cases are tracked inconsistently across spreadsheets, architecture review notes, procurement records, business-unit trackers, privacy assessments, vendor due-diligence records and committee slides.
Meridian’s HR function adopted a vendor platform with AI-enabled candidate screening, ranking and shortlisting features. The capability was activated during a wider recruitment-process modernisation project.
The vendor described the feature as decision support. Procurement recorded it as an HR technology renewal. HR operations believed final decisions remained human-led because recruiters could override recommendations. Legal was asked whether the system might be in scope of the EU AI Act, but the classification review remained open because the organisation had not agreed whether Meridian was only a deployer, whether configuration created additional responsibilities, or whether the tool should be treated as a high-risk candidate.
A partial AI inventory entry was created. It recorded the vendor name, business owner, intended use and live status. But classification was still under review. Operator role was still to be confirmed. DPIA status was requested. Vendor evidence had been received but not reviewed. Human oversight evidence had not been reviewed. The review due date was blank.
Six months later, internal audit asked the AI Governance Lead to evidence the organisation’s position on recruitment AI. The team could not produce a complete assurance trail.
Records were split across a vendor due-diligence questionnaire, procurement contract file, privacy DPIA draft, model-risk email thread, risk committee slide, spreadsheet inventory, HR procedures, vendor bias-testing statements and recruiter training material.
The issue was not that Meridian had no AI policy. The issue was that policy had not translated into a connected, reviewable assurance chain.
What it cost
Regulatory and compliance impact
Internal audit escalated the finding. The organisation had to revisit its EU AI Act classification, privacy review and fundamental-rights assessment position.
Operational impact
HR, procurement, legal, privacy, technology risk and AI governance teams were pulled into an urgent remediation sprint. Expansion of the feature to other business units was paused while records were reconstructed.
Commercial impact
The recruitment automation rollout was delayed. Supplier-management conversations had to be reopened, and remediation cost was higher than it would have been before deployment.
Governance impact
The risk committee challenged whether AI readiness reporting could be relied on. Internal audit required evidence-backed status reporting rather than narrative summaries.
Reputational and workforce impact
The organisation faced concern over whether recruitment decisions were sufficiently explainable, reviewed and evidenced.
Where the assurance chain broke
| Broken link | What was missing | Why it mattered |
|---|---|---|
| AI system discovery | The AI-enabled feature was treated as part of a SaaS renewal, not as a distinct AI system. | The AI inventory did not fully reflect actual business use. |
| Intended purpose | The intended use was described too generally as screening support. | Classification and obligation analysis depends on intended purpose and operating context. |
| Classification | The system stayed under review with no completed rationale or sign-off. | Leadership could not tell whether the system was prohibited, high-risk, transparency-only, minimal risk or out of scope. |
| Operator role | Provider/deployer responsibilities were not documented clearly. | Internal owners assumed the vendor owned most obligations, but the vendor pack did not show what Meridian still had to do. |
| Obligation ownership | Known requirements were not translated into owned actions. | DPIA/FRIA review, human oversight, training, logging, monitoring and vendor follow-up had no clear owners or due dates. |
| Evidence | Evidence lived in multiple systems and was not linked to the AI system, obligations or review decisions. | The organisation had artefacts, but not a reconstructable dossier. |
| Human oversight | Human review was asserted but not operationally evidenced. | The firm could not show how recruiters reviewed, challenged, overrode or escalated AI recommendations. |
| Review forum | The risk committee saw a high-level readiness statement, not unresolved evidence gaps. | Leadership assurance was based on incomplete records. |
What should have been visible earlier
Known signals
- The vendor product included AI-enabled screening and ranking.
- HR used the capability in a people-related workflow.
- Legal had not completed classification review.
- Privacy had requested a DPIA update.
- Vendor documentation existed but had not been reviewed against internal obligations.
- Human oversight was assumed but not evidenced.
Unowned actions
- Complete EU AI Act classification rationale.
- Confirm operator-role decision.
- Complete DPIA/FRIA assessment.
- Review vendor bias-testing evidence.
- Define and evidence human oversight procedure.
- Confirm recruiter training.
- Define monitoring and exception review cadence.
- Prepare a risk committee assurance position.
Stale or missing evidence
- Classification rationale and sign-off.
- Operator-role decision record.
- DPIA/FRIA status and review notes.
- Vendor evidence pack review record.
- Human oversight control evidence.
- Recruiter training evidence.
- Bias and fairness review evidence.
- Exception handling and override review evidence.
- Risk committee sign-off record.
Missing review points
- No pre-launch AI governance gate.
- No classification completion gate before wider rollout.
- No evidence-quality review before risk committee reporting.
- No recurring review date for in-life assurance.
How STREAM® Cloud could help
Capture the AI system as a distinct record
STREAM® Cloud could help create a clearer AI system register so vendor AI features are not buried inside procurement renewals or business-unit project trackers.
Record human-reviewed classification rationale
STREAM® Cloud could help record classification status, rationale, reviewer, assumptions, guidance references and sign-off state.
Clarify operator-role decisions
STREAM® Cloud could help document provider, deployer and related role assumptions, linking the decision to vendor evidence, legal review and internal ownership.
Translate obligations into trackable work
STREAM® Cloud could help turn obligations into linked actions with owners, due dates, evidence requirements, status and review cadence.
Create a reconstructable evidence chain
STREAM® Cloud could help link or reference vendor documentation, DPIA/FRIA records, training records, human oversight procedures, review notes, monitoring evidence and audit findings.
Support review forums
STREAM® Cloud could help dashboards and drill-down views show live systems missing classification, high-risk candidates missing evidence, overdue obligations and vendor documentation gaps.
Make assurance more defensible
STREAM® Cloud could help show what was recorded, who owned it, what changed, what evidence existed, what remained open and what leadership was asked to rely on.
Related use case
AI Governance & EU AI Act Readiness
Want to see how STREAM® Cloud supports evidence-backed assurance?
STREAM® Cloud helps teams connect records, actions, evidence, review status and assurance outputs in a configurable workspace.