AI governance · 2024 to 2025

Designing AI Assisted Compliance

A human-in-the-loop approach to safer, more consistent decisions.

Role
Senior UX Designer. Sole designer on the feature.
Time
3 weeks, concept to private preview.
Team
Product manager, engineering, ML.
Status
Private preview with 10 customers.

01 · Background

Risks and controls

OneTrust is a B2B platform for privacy, security and AI governance used by over 14,000 organizations, half the Fortune 500 among them. Compliance teams use it to identify risks and apply controls that reduce them. This project was about the second half of that sentence.

A risk is a threat you have written down: our AI model produces biased or harmful outputs. A control is the safeguard that reduces it: bias testing before deployment, human review of outputs, monitoring for drift.

02 · The problem

Control selection had no system-level guidance

A risk team opened the controls library, saw hundreds of options, and had to know what to pick. The system offered nothing. As organizations scale, that produces gaps in coverage and decisions nobody can reconstruct later.

  • Highly manual

    Search, read, guess, repeat. No guidance on what to pick for a given risk.

  • Dependent on expertise

    Senior people had strong instincts. Newer people under-mapped or spent a long time searching.

  • Inconsistent across teams

    Two teams, the same risk, different answers. A serious problem when an auditor asks why.

03 · Research

The reasoning mattered as much as the recommendation

I ran ten user interviews with the PM, alongside usage data on how often people opened the library, how long they spent searching, and where they ended up with gaps. The quantitative signal matched what we were hearing.

3×

More trust with rationale visible

Users trusted recommendations three times more when the rationale was visible.

Compliance officers have to explain decisions to auditors. A tool that can’t help them say why doesn’t get used. That finding set how every explanation in the feature works.

04 · Decision

Banner, or inside the modal

The obvious move was to put recommendations inside the modal people already used. I went the other way.

Option A Selected

Banner plus guided review

For

  • Lightweight entry point
  • Aligns with existing patterns
  • Works for new and existing risks
  • Fast to scan and act

Against

  • Adds one extra click
  • Different from current experience
Option B

Embed in the add-control modal

For

  • Fewer clicks
  • Everything in one place

Against

  • Heavy, cluttered modal
  • Blends manual and AI workflows
  • Harder to scan recommendations
  • Higher engineering complexity

I took the extra click. Keeping the AI path scannable and the manual path untouched was worth more than saving it.

05 · The design

Evaluating AI recommended controls

Everything needed to decide, in one place: the control, the confidence, and why it was surfaced.

  • Rationale

    Explains why a control is recommended, so the user can validate whether it applies to their situation. Inline, one click away, never a tooltip. It has to survive being pasted into an audit response.

  • Confidence

    A four-step scale, not a percentage. The model team wanted a number. Research said a number created false precision and raised anxiety.

  • Selection

    Explicit select or dismiss, nothing auto-applied. The review step is not friction. It is what lets a compliance officer own the outcome.

The review step as it shipped. Twelve recommended controls with a confidence rating each, one row expanded to show its description, implementation guidance, rationale and source, and Cancel and Add selected at the bottom.
The review step as it shipped. Confidence sits in its own column so a list can be scanned on it, and the reasoning stays folded away until someone asks for it.

Try it · the review step, rebuilt in HTML

Review recommended controls

12 recommended controls to help mitigate this risk. Review each recommendation, and add the controls that apply.

Library risk: Failure to maintain data integrity during input, processing, or output.

AICPA & CICA GAPP Recovery Very high
AICPA & CICA GAPP Recovery Very high

Description

Ensure that personal data collected for different purposes can be processed separately.

Implementation guidance

Enable centralized logging, version control, and audit trails.

Rationale

Gaps in reconciliation increase risk despite existing monitoring.

Source

AICPA & CICA GAPP

Dismiss recommendation

AICPA & CICA GAPP Recovery Very high
HIPAA Recovery Very high
AICPA & CICA GAPP Recovery Very high

Recommendations may be inaccurate. Verify info. 5 of 12 shown

3 selected

06 · Measurement

Defined before shipping, not after

Three dimensions, agreed with product and engineering before V1 shipped, so there would be a baseline.

Decision quality

Reduced reliance on individual expertise.

  • Recommendation acceptance rate
  • Coverage completeness across risks
  • Variance in selection across teams

User confidence

Rationale and confidence actually support the decision.

  • Confidence engagement rate
  • Reviewed vs. skipped recommendations
  • Qualitative feedback on trust and clarity

Workflow efficiency

Less time lost in a library of hundreds.

  • Time to map controls per risk
  • Manual searches per session
  • Drop-off in the selection flow

V1 shipped to private preview with 10 customers. I was laid off in a company-wide reduction before post-launch data came in, so there are no outcome numbers here. The framework and the pre-launch research are what I have.

07 · Tradeoffs

Three tradeoffs

Trust vs. automation

Traded: kept humans in the loop. Users review rather than auto-apply, which costs speed.
Next: auto-apply for very high confidence recommendations, with guardrails.

Entry point vs. discoverability

Traded: a banner is easy to ignore. Some users missed it entirely.
Next: smarter triggers. Surface it when someone is mid-task on a risk with gaps.

Signal quality

Traded: shipped V1 with limited validation of the confidence scoring.
Next: align with the model team on what high confidence actually means.

08 · Reflections

A recommendation users don’t understand is a recommendation they won’t follow.

  • 01

    Rationale and confidence are not nice to have. They are how a person calibrates trust in a system.

  • 02

    Lightweight entry points reduce friction, but they need deliberate discoverability or they disappear.

  • 03

    Humans in the loop build confidence and cost speed. The workflow decides which one matters more.

Let’s talk.

I’m open to UX and product design roles, Seattle or remote.