A human-review process should define who reviews, what they see, what they can change and when the system must stop. Match the review to the consequences of the decision. Record disagreements and overrides so the organisation can evaluate whether human involvement is substantive or merely procedural.
The business situation
A screening tool ranks applications. The reviewer sees only a score and must approve hundreds of results before the day ends. The workflow records human approval, yet the reviewer cannot inspect the reasons, test an error or change the threshold.
AI governance starts with a use case and a responsible legal entity. A model is not itself a Data Fiduciary. The organisation determining the purpose and means of personal-data processing may be one. Contract, intellectual-property, consumer, employment and sector rules can apply alongside data-protection law; the relevant obligations depend on the deployment.
What needs examining
01. Design the review around the affected decision
Identify whether the system drafts, recommends, ranks or executes. Distinguish an internal writing aid from a system affecting employment, lending, insurance or another consequential outcome. Applicable sector and employment requirements need a specific assessment. Do not present a universal statutory right to human review as if it arose automatically under the DPDP Act.
02. Give the reviewer usable authority
Define training, access to underlying evidence, escalation and the power to suspend or reverse a result. Explain uncertainty and known limitations in a form the reviewer can understand. A control fails if business targets make disagreement impractical or if overriding the model requires inaccessible technical intervention.
03. Use the record to improve the process
Track reasons for overrides, repeated errors and cases where reviewers lack enough information. Review a sample of accepted outcomes as well as rejected ones; agreement alone is not proof of quality. NIST AI RMF can help organise the programme as a voluntary framework, while the legal assessment identifies the actual mandatory duties.
Law, contract and recommended practice
Applicable Indian statutes and sector directions are mandatory where their scope is met. NIST AI RMF is a voluntary governance framework, unless particular commitments become binding through a contract or another applicable requirement. Its GOVERN, MAP, MEASURE and MANAGE functions can organise evidence without creating a new Indian legal obligation.
Connect the control to the evidence
Use this table to scope the review. The legal basis and the practical control are identified separately.
| Obligation or objective | Practical control | Evidence to retain |
|---|---|---|
| Law, where applicable Meet sector and decision-specific duties | Map the use case and affected rights | Applicability assessment |
| Recommended practice Enable meaningful intervention | Evidence access, override and stop authority | Reviewer decision and escalation record |
| Recommended practice Detect ineffective oversight | Sample accepted and overridden outcomes | Quality review and corrective action |
Records to prepare
Bring the complete, current record to the review. Preserve earlier versions where a change or disputed event makes them relevant.
Common questions
Is a human approval checkbox enough?
No. It records an action but not necessarily informed review. Assess whether the reviewer had relevant evidence, sufficient time and the authority to change the outcome.
Must every AI-assisted task have the same review level?
No. The design should follow the consequences, applicable obligations and demonstrated system limitations. A low-impact drafting aid and a consequential decision process may need different controls.
Observe one reviewer handling a difficult case. If they cannot explain, change or stop the result, revise the process before relying on the approval record.
Legislation & official resources
These references identify the governing frameworks. Confirm the current text, relevant amendments and applicable judicial position for the matter.
- NIST AI Risk Management FrameworkNational Institute of Standards and Technology · Voluntary governance framework. It does not, by itself, create an Indian statutory duty.
- Indian Contract Act, 1872Government of Uttar Pradesh · Commercial Tax Department · Government-hosted statutory reference. Read with applicable amendments, special law and judicial interpretation.
- Digital Personal Data Protection frameworkMinistry of Electronics and Information Technology · Official framework resource. Apply the relevant Act, Rules and commencement notifications together.
This note is general information. The scenario is hypothetical and does not describe a client matter. The legal result depends on the facts, documents, jurisdiction and operative law. No individual lawyer review is represented by the preparation date.
Explore the AMLEGALS ai governance practice