Skip to main content

Aventora AI Governance Policy

FieldValue
Document NameAI Governance Policy
Version1.1
Effective DateJuly 20, 2026
Document OwnerAventora Security
Review FrequencyAnnual
ClassificationInternal / Customer Shareable
Approval StatusApproved for publication — see Version History

Document Control

This policy establishes Aventora Inc. (“Aventora,” “we,” “us,” or “our”) requirements for the responsible development, deployment, and operation of artificial intelligence capabilities within the Aventora platform and related services.

This document is intended for enterprise customers, security assessors, privacy officers, procurement teams, and Aventora personnel. It supports security, privacy, and AI governance reviews for organizations such as insurance carriers, financial institutions, and regulated enterprises. Aventora does not claim formal certification or attestation under any specific AI governance, privacy, or security framework based on this document alone. Implementation details may vary by deployment model, contractual terms, and enabled product features.

Governance Commitments

Aventora’s AI Governance Policy incorporates principles for responsible AI, including fairness and ethical use; human oversight and accountability; data minimization; privacy and security by design; transparency regarding AI-assisted functionality; customer data protection; third-party AI provider governance; risk management; and compliance with applicable legal and contractual requirements. AI-generated outputs are advisory and remain subject to human review and control.

The table below maps each commitment to the sections of this policy where it is addressed:

CommitmentPolicy sections
Responsible AI, fairness, and ethical useSection 4, Section 9
Human oversight and accountabilitySection 8
Data minimizationSection 4, Section 6
Privacy and security by designSection 4, Section 10
Transparency regarding AI-assisted functionalitySection 4, Section 5
Customer data protectionSection 6, Section 7
Third-party AI provider governanceSection 5, Section 11
Risk managementSection 12
Legal and contractual complianceSection 14
Advisory outputs subject to human review and controlSection 8

RFC 2119 Terminology

The key words “MUST,” “MUST NOT,” “REQUIRED,” “SHALL,” “SHALL NOT,” “SHOULD,” “SHOULD NOT,” “RECOMMENDED,” “MAY,” and “OPTIONAL” in this document are to be interpreted as described in RFC 2119.


Approval

RoleNameSignatureDate
Chief Executive Officer[To be completed upon formal approval]
Document Owner (Aventora Security)[To be completed upon formal approval]
Engineering Leadership[To be completed upon formal approval]

This policy is effective upon signature by the Document Owner and notification to affected personnel. Material revisions require re-approval and updated version history.


Table of Contents

  1. Purpose
  2. Scope
  3. Definitions
  4. AI Governance Principles
  5. Approved AI Providers
  6. Data Handling
  7. Model Training
  8. Human Oversight
  9. Prohibited Uses
  10. Security Controls
  11. Third-Party AI Provider Management
  12. Risk Management
  13. Incident Response
  14. Regulatory Compliance
  15. Roles and Responsibilities
  16. Policy Exceptions
  17. Annual Review Process

1. Purpose

The purpose of this AI Governance Policy is to define Aventora’s organizational commitments and operational requirements for the responsible use of artificial intelligence in connection with the Aventora platform and related services.

Aventora operates an AI-powered customer engagement platform that enables organizations to manage communications and customer interactions across channels such as voice, SMS, email, chat, and related administrative workflows. AI capabilities—including large language model inference for conversational assistance, summarization, and related features—are integrated into platform services to support customer-configured engagement workflows.

This policy:

  • Establishes governance principles for responsible AI—including fairness, ethical use, transparency, and customer data protection—across Aventora products, infrastructure, and operations;
  • Defines requirements for data minimization, privacy and security by design, human oversight, and prohibited uses of AI;
  • Describes third-party AI provider governance, security controls, and risk management practices;
  • Provides a reference for enterprise security, privacy, and AI due diligence assessments; and
  • Communicates Aventora’s commitment that customer data is processed only for contracted service delivery, is protected through logical isolation and platform security controls, and is not used to train general-purpose AI models unless explicitly agreed in writing.

AI-generated outputs are advisory. They assist users and end customers but do not replace human judgment. Outputs remain subject to human review and control as described in Section 8.

This policy supplements, and should be read together with, the Personal Data Privacy & Protection Policy, Subprocessor Annex, Integration Security, and related security documentation.


2. Scope

2.1 In Scope

This policy applies to:

AreaDescription
AI-enabled products and servicesEngagement Hub, Domain Assistant, Aventora CRM, administrative applications, mobile clients, and supporting integrations that incorporate AI inference or AI-assisted workflows
Customer Data processed by AIData submitted to, generated by, or transmitted through AI features in connection with contracted services
Aventora personnelEmployees, contractors, and authorized agents who design, develop, deploy, operate, or support AI-enabled capabilities
Third-party AI providersExternal vendors engaged by Aventora to supply AI inference, speech, or related model services on Aventora’s behalf
Development and operationsSoftware development, feature design, deployment, monitoring, support, and vendor management activities involving AI capabilities

2.2 Out of Scope

Unless explicitly addressed in a written agreement, the following remain outside the scope of this policy:

  • Customer-managed AI systems, models, or data pipelines not operated by or on behalf of Aventora;
  • Third-party AI services configured or operated directly by the customer outside Aventora’s control;
  • General employee use of consumer AI tools for internal productivity, which is governed by separate acceptable-use and confidentiality requirements; and
  • AI research or experimentation not connected to production customer workflows.

2.3 Deployment Models

This policy applies across Aventora-managed cloud deployments, customer self-hosted deployments, and private-cloud or on-premises configurations. Customer-specific AI governance, residency, and provider requirements MAY be incorporated during deployment where agreed in writing. Variations from default controls MUST be documented and approved through Aventora’s exception process (see Section 16).


3. Definitions

For the purposes of this policy, the following definitions apply:

TermDefinition
Generative AIArtificial intelligence systems that generate text, speech, or other content in response to prompts or inputs, including large language models and related inference services used in conversational or summarization workflows.
Large Language Model (LLM)A machine learning model trained on large volumes of text data to understand and generate natural language. Aventora integrates third-party LLMs through enterprise API interfaces; Aventora does not operate proprietary general-purpose LLMs for customer-facing inference.
AI ProviderA third-party vendor that supplies AI inference, speech recognition, speech synthesis, or related model services to Aventora in connection with platform delivery. Current AI providers are listed in the Subprocessor Annex.
Customer DataData submitted to or processed within the Aventora platform on behalf of a Customer, including conversation content, engagement records, configuration data, and related metadata. Customer Data may include Personal Data.
Personal DataInformation about an identified or identifiable natural person, as defined in the Personal Data Privacy & Protection Policy.
Human OversightMeaningful human involvement in the design, deployment, monitoring, and use of AI-enabled features, including human review of AI outputs where appropriate and human accountability for business decisions informed by AI.

4. AI Governance Principles

Aventora governs AI usage according to the following principles. Together, these principles implement Aventora’s commitments to responsible AI, customer data protection, provider governance, risk management, and compliance with applicable legal and contractual requirements.

PrincipleDescription
Responsible AIAI capabilities are designed and operated to deliver customer-configured business value while managing risks to privacy, security, reliability, and the rights of individuals.
Fairness and ethical useAI features MUST NOT be used for prohibited or discriminatory purposes (see Section 9). Aventora evaluates intended use, customer impact, and alignment with applicable law before releasing AI-enabled capabilities. Features that could lead to unjustified or disproportionate treatment of individuals are prohibited or restricted.
Human oversight and accountabilityAI outputs are advisory. Humans remain accountable for decisions that affect customers, end users, and business operations. AI-generated outputs SHALL remain subject to human review and control where customer workflows, applicable law, or customer policy require it.
Transparency regarding AI-assisted functionalityAventora discloses when platform features use AI inference to assist conversations, summarization, or related workflows. Third-party AI providers, applicable data flows, and subprocessor relationships are documented in customer-shareable materials such as the Subprocessor Annex and Integration Security. Customers are informed when AI features process Customer Data.
Privacy by designAI features incorporate privacy considerations at design time, including data minimization, purpose limitation, and alignment with the Personal Data Privacy & Protection Policy.
Security by designAI integrations are implemented with authentication, authorization, encrypted transport, credential protection, and secure development practices consistent with Aventora’s security program.
Data minimizationOnly the minimum data necessary for a specific AI-enabled function is collected, transmitted, and retained.
Customer data protectionCustomer Data belongs to the customer. Aventora processes it only to deliver contracted services, enforces logical isolation between customers, does not sell Customer Data, and applies the handling requirements in Section 6 and Section 7.
Third-party AI provider governanceAI Providers are evaluated, contracted, and monitored according to Section 11. Only approved enterprise providers are used for production customer workflows.
Risk managementAI-related risks are assessed before release and monitored in operation according to Section 12.
Compliance with applicable legal and contractual requirementsAI processing activities are conducted in accordance with applicable privacy, data protection, and AI-related legal requirements, as well as customer contractual obligations (see Section 14).
Least privilegeAccess to AI features, provider credentials, and Customer Data used in AI workflows is restricted to authorized personnel and scoped system components.

These principles apply across all in-scope AI-enabled products, services, and operational activities.


5. Approved AI Providers

5.1 Enterprise AI Integration

Aventora MAY integrate enterprise AI providers through programmatic API interfaces to supply inference for customer-configured features. Approved provider categories include:

Provider categoryExamplesUse
Large language model APIsOpenAI API and compatible enterprise LLM providersConversational AI, summarization, and related text generation during active sessions
Alternative inference providersGroq and other enterprise-configured providersInference where selected per deployment configuration

The current list of AI subprocessors, processing activities, and typical processing locations is maintained in the Subprocessor Annex.

5.2 Consumer AI Accounts

Aventora MUST NOT use consumer-grade AI accounts (for example, personal chat subscriptions or free-tier consumer services) for production customer workflows. Production AI integrations MUST use:

  • Enterprise or API-tier provider accounts with contractual terms appropriate to business use;
  • Credentials managed through restricted deployment configuration; and
  • Provider configurations that support data use limitations where available.

5.3 Customer-Configurable Providers

Where supported by deployment model and agreement, customers MAY select among approved AI providers or configure private or on-premises model endpoints. Customer-directed provider choices remain subject to this policy’s data handling, security, and prohibited-use requirements.


6. Data Handling

Customer data protection is a core requirement of Aventora’s AI governance program. Aventora applies the following requirements to Customer Data processed by AI-enabled features:

6.1 Data Minimization and Transmission

  • Only the minimum data required for a specific AI-enabled request SHALL be transmitted to an AI Provider.
  • Prompts and context SHOULD be limited to what is necessary for the customer-configured function (for example, active conversation content required for inference during a session).
  • Data minimization SHOULD be applied in system design and prompt construction wherever feasible.

6.2 Personal Data and Anonymization

  • Personally identifiable information SHOULD be anonymized, pseudonymized, or redacted where practical before transmission to AI Providers, consistent with feature requirements and customer configuration.
  • Where anonymization is not practical for a given function, transmission is limited to the minimum necessary and governed by applicable privacy requirements and customer agreements.

6.3 Customer Isolation

  • Customer Data is logically isolated by account, workspace, or tenant boundaries within Aventora platform services.
  • Customer Data MUST NOT be intentionally shared, combined, or exposed across customer boundaries.
  • Multi-tenant deployments enforce account-level isolation for engagement records, configuration, and credentials.

6.4 Secrets and Credentials

  • Secrets, API keys, passwords, private keys, and other credentials MUST NOT be intentionally submitted to AI systems in prompts, training data, or inference requests.
  • Personnel MUST NOT paste production credentials, environment files, or live secrets into AI tools.
  • System designs SHOULD prevent inadvertent inclusion of credentials in AI request payloads through input validation and operational procedures.

6.5 Session-Bound Processing

When AI features are enabled, conversation content is sent to configured AI Providers only during active sessions and only as necessary for the customer-configured function. See Integration Security — AI Provider Handling and Engagement Hub Features — AI and Customer Data.


7. Model Training

7.1 Aventora Model Training

Aventora does not use Customer Data to train its own general-purpose AI models. Aventora does not operate proprietary LLMs trained on customer conversation content for cross-customer model improvement.

7.2 Cross-Customer Use

Customer Data MUST NOT be intentionally used to improve models, features, or algorithms for other customers. Processing is limited to delivering the contracted service for the applicable customer.

7.3 Third-Party Provider Training

Enterprise AI APIs SHOULD be configured in accordance with provider policies that exclude API data from public model training where such options are supported by the provider and applicable to the deployment. Provider-specific data handling, retention, and training practices depend on:

  • The selected AI Provider and account tier;
  • Provider contractual terms; and
  • Customer deployment and configuration choices.

Customers SHOULD review enabled AI features and provider terms as part of their privacy and AI governance assessments. Customer data is not used to train general-purpose AI models unless explicitly agreed in writing.


8. Human Oversight

Human oversight and accountability are fundamental to Aventora’s approach to AI. AI systems assist users; they do not replace human judgment or accountability for business outcomes.

8.1 Advisory Nature of AI Outputs

AI-generated content, recommendations, summaries, and conversational responses are advisory. They are intended to assist users and end customers; they do not constitute authoritative business, legal, medical, financial, or compliance determinations.

AI-generated outputs remain subject to human review and control. Customers and their authorized users retain responsibility for reviewing, validating, escalating, or overriding AI outputs as appropriate to their workflows, regulatory obligations, and internal policies.

8.2 Human Responsibility and Review

  • Users, customer administrators, and Aventora personnel remain responsible for business decisions informed by AI outputs.
  • Customers SHOULD define internal review procedures for high-impact use cases, including escalations to human agents where appropriate.
  • AI features SHOULD be configured with human handoff, escalation, or review paths where customer workflows require them.
  • Where a customer workflow involves decisions with legal or similarly significant effects on individuals, human review SHOULD be applied in accordance with applicable law and customer policy.

8.3 Autonomous Decision Restrictions

AI systems MUST NOT autonomously:

  • Approve financial transactions or binding contractual commitments on behalf of a customer without explicit human authorization defined in the workflow;
  • Make legally binding decisions affecting individuals without appropriate human review where required by law or customer policy; or
  • Operate as fully autonomous agents outside customer-configured guardrails.

Engagement workflows may automate outreach, routing, and response generation within customer-defined parameters, but accountability for outcomes remains with the customer and its authorized users.


9. Prohibited Uses

Aventora MUST NOT develop, deploy, or operate AI features for the following purposes:

Prohibited useDescription
Social scoringEvaluating or scoring individuals based on social behavior or personal characteristics in a manner that leads to unjustified or disproportionate treatment
Biometric identificationReal-time remote biometric identification in publicly accessible spaces for law enforcement or surveillance purposes, except where explicitly permitted by applicable law and customer agreement
Emotion recognitionInferring emotions in workplace or education contexts where prohibited or inappropriate under applicable law or customer requirements
Discriminatory profilingProcessing that results in unjustified discrimination based on protected characteristics
Illegal surveillanceCovert or unlawful monitoring of individuals
High-risk autonomous decision makingFully automated decisions with legal or similarly significant effects on individuals without required human oversight, safeguards, or lawful basis
EU AI Act Article 5 use casesAny practice prohibited under Article 5 of Regulation (EU) 2024/1689 (EU AI Act), where applicable

This section does not limit Aventora’s obligation to comply with additional prohibited or restricted uses defined by applicable law, customer contract, or deployment-specific requirements.


10. Security Controls

AI-enabled features are subject to Aventora’s platform security controls. The following controls support the secure operation of AI integrations:

10.1 Authentication

  • Production APIs and administrative interfaces require authentication unless explicitly designated as public with compensating controls.
  • API credential authentication, token-based sessions, and delegated access tokens are used according to the Authentication and Access Control documentation.
  • Service-to-service communication between platform components uses scoped credentials.

10.2 Role-Based Access Control

  • Role-based access control (RBAC) with least privilege is applied across platform APIs, administrative portals, and workspace access.
  • AI provider credentials and configuration are accessible only to authorized deployment and engineering personnel.
  • Authorization is enforced on the server before business logic executes.

10.3 Encryption in Transit

  • TLS (1.2 or higher) protects production API traffic, administrative access, and communications with third-party AI Providers.
  • Reverse proxies terminate TLS for customer-facing and administrative endpoints in managed deployments.

10.4 Encryption at Rest

  • Production data stores use provider-supported encryption at rest where available in the deployment environment.
  • Passwords and API credentials are stored using industry-standard one-way cryptographic protection.
  • OAuth tokens and integration secrets are stored with restricted database access and encryption mechanisms where supported.

10.5 Audit Logging

  • Security-relevant events—including authentication, authorization denials, administrative actions, and webhook validation—are logged for operational review and incident investigation.
  • Logs are protected against unauthorized access and retained according to documented retention practices. See Logging and Audit.

10.6 Secure Software Development Lifecycle

  • Changes affecting authentication, authorization, data handling, and AI integrations are developed in version-controlled repositories with peer review.
  • Pre-production security scan utilities perform dependency audit, secret detection, and configuration checks.
  • Security-relevant functionality is tested before production release. See API Security Policy and Vulnerability Management.

10.7 Vulnerability Management

  • Dependencies are tracked and updated through controlled release processes.
  • Known high-severity vulnerabilities are addressed prior to production release or mitigated with documented compensating controls.
  • Reported vulnerabilities are investigated through security@aventora.ai.

10.8 Change Management

  • Application and infrastructure changes follow the Application Change Management Policy.
  • New third-party AI integrations and material AI architecture changes require Engineering Leadership approval before production use.
  • Emergency changes follow documented emergency change procedures with post-implementation review.

Note: Control implementation may vary by deployment model. This section describes operational practices; it does not assert uniform maturity across all environments or formal certification under SOC 2, ISO 27001, or other frameworks unless explicitly stated in a valid attestation report delivered under contract.


11. Third-Party AI Provider Management

Aventora maintains governance over third-party AI providers used in production customer workflows. Provider selection, evaluation, and ongoing management are subject to the requirements below and the Subprocessor Annex.

11.1 Provider Evaluation

Before engaging or materially changing an AI Provider, Aventora SHOULD evaluate:

Evaluation areaDescription
Security practicesAccess controls, encryption, incident response, and security documentation
Privacy practicesData use limitations, retention, subprocessors, and data subject rights support
Processing locationsGeographic regions where data may be processed
Contractual termsConfidentiality, security, deletion, and breach notification obligations
Training and retention policiesWhether API data may be used for model training and applicable opt-out or enterprise terms
Business continuityAvailability and recovery capabilities for critical services

11.2 Enterprise Contractual Terms

Aventora MUST require AI Providers that process Personal Data to accept the Standard Vendor and Subprocessor Contractual Requirements in the Vendor Management Policy, including (without limitation):

  • Confidentiality and security obligations;
  • Restrictions on use of Customer Data beyond providing the contracted inference service;
  • Prohibition on unauthorized re-identification of de-identified, anonymized, aggregated, or pseudonymized data;
  • Prior written authorization (or general authorization via notice and opportunity to object) before engaging new Further Subprocessors;
  • Prompt assistance with data subject rights requests;
  • No transfer of Personal Data outside agreed processing locations without Aventora’s prior written approval, with legally required safeguards for approved international transfers;
  • Data deletion and return obligations upon termination; and
  • Incident notification commitments appropriate to the processing activity.

Aventora SHOULD prefer enterprise or API-tier contractual terms that incorporate these requirements.

11.3 Security and Privacy Requirements

AI Providers MUST satisfy Aventora’s security and privacy requirements for the relevant processing activity before production use, including completion of the due-diligence and contract-review checklists in the Vendor Management Policy. Material subprocessor changes are managed according to the Subprocessor Annex and Section 24 of the Personal Data Privacy & Protection Policy.


12. Risk Management

Aventora manages AI-related risk as part of its broader security and privacy program. Structured review before release and ongoing monitoring in operation reduce the likelihood and impact of AI-related privacy, security, and customer-impact events.

12.1 Pre-Release Review

Before releasing new or materially changed AI-enabled features to production, Aventora SHOULD conduct:

Review typeFocus
AI feature reviewIntended use, data flows, customer impact, and alignment with this policy
Security reviewAuthentication, authorization, credential handling, input validation, and integration security
Privacy reviewData minimization, Personal Data handling, subprocessor disclosure, and lawful basis alignment
Customer impact assessmentEffects on end users, escalation paths, error handling, and transparency

Review depth SHOULD be proportionate to the sensitivity of data processed and the criticality of the feature.

12.2 Ongoing Monitoring

Aventora SHOULD monitor AI-enabled features for:

  • Provider availability and error rates;
  • Security-relevant log events and anomalous access patterns;
  • Changes to provider terms, subprocessors, or processing locations; and
  • Customer-reported issues affecting AI output quality, privacy, or security.

Identified risks SHOULD be tracked and remediated according to severity and customer impact.

AI-related risks MUST also be recorded and managed under Aventora’s enterprise Information Security Risk Management Program, including the risk register review cadence and treatment requirements. See the Information Security Risk Management Policy and Risk Assessment and Treatment Procedure.


13. Incident Response

AI-related security and privacy incidents are handled under Aventora’s incident response procedures. See Incident Response and the Personal Data Privacy & Protection Policy — Incident Response.

13.1 Reporting

  • Personnel MUST report suspected AI-related incidents—including unauthorized disclosure of Customer Data to an AI Provider, credential exposure in AI prompts, or provider security notifications—to Aventora Security through established reporting channels.
  • External reports SHOULD be submitted to security@aventora.ai.

13.2 Investigation

Incidents involving AI features SHOULD be investigated to determine:

  • Affected customers, data categories, and time period;
  • Whether Customer Data was transmitted to or retained by an AI Provider outside intended scope;
  • Root cause, including configuration, code defect, or procedural failure; and
  • Whether provider-side incidents contributed to the event.

13.3 Containment

Containment measures MAY include:

  • Disabling affected AI features or provider integrations;
  • Rotating provider API credentials;
  • Revoking compromised user or service credentials;
  • Isolating affected deployment components; and
  • Blocking further data transmission to the affected provider until risk is mitigated.

13.4 Customer Notification

Where an incident involves unauthorized access, disclosure, or loss of Personal Data processed in connection with AI features, Aventora SHOULD:

  • Notify affected customers without undue delay where required by agreement or applicable law;
  • Cooperate with customers in fulfilling data subject and regulator notifications where Aventora acts as Processor; and
  • Document findings, remediation actions, and lessons learned.

Notification timelines align with applicable legal requirements and contractual obligations.


14. Regulatory Compliance

Aventora MUST govern AI processing activities in compliance with applicable laws and customer contractual requirements. Relevant frameworks include:

FrameworkRelevance to AI governance
GDPR / UK GDPRLawful processing, data minimization, processor obligations, data subject rights, subprocessor transparency, and restrictions on automated decision-making where applicable
PIPEDA (Canada)Accountability, limiting collection, safeguards, and transparency for personal information processed through AI-enabled features
EU AI ActProhibited practices (Article 5), transparency obligations, and requirements for high-risk AI systems where applicable to Aventora’s role and deployed features. Aventora does not make general claims of EU AI Act conformity assessment or CE marking based on this policy alone
Customer contractual requirementsData processing addenda, AI addenda, sector-specific terms, and deployment-specific security schedules agreed with customers

This policy SHOULD be interpreted alongside customer agreements, the Data Processing Addendum Appendix, and applicable law. Where conflicts arise, the stricter requirement applicable to the processing activity SHOULD prevail unless prohibited by law.

Aventora does not claim formal certification under SOC 2, ISO 42001, ISO 27001, or other frameworks in this document unless explicitly stated in a valid attestation report delivered under contract. See Compliance Alignment.


15. Roles and Responsibilities

RoleResponsibilities
Executive ManagementApproves this policy; allocates resources for AI governance, security, and privacy; ensures accountability for compliance with legal and contractual obligations; approves material exceptions
EngineeringDesigns and implements AI features in accordance with this policy; applies secure development, data minimization, and testing practices; evaluates technical risk before release; responds to incidents affecting AI integrations
SecurityOwns and maintains this policy; conducts or coordinates security reviews of AI features; manages incident response for AI-related security events; evaluates AI Providers; maintains customer-shareable security documentation
Product ManagementDefines customer-facing AI capabilities and transparency; ensures features align with governance principles and prohibited-use restrictions; coordinates customer impact assessment and documentation
Employees and ContractorsFollow this policy and related standards; use approved AI providers and accounts for customer workflows; protect Customer Data and credentials; report incidents and policy violations promptly

Specific named roles (for example, dedicated AI ethics officer or Data Protection Officer) may be designated as the organization matures. Until formally designated, responsibilities above are fulfilled by the listed functions.


16. Policy Exceptions

Exceptions to this policy MAY be granted only where:

  • A legitimate business or technical requirement exists;
  • Compensating controls are documented;
  • The exception is approved in writing by Aventora Security or designated authority;
  • The exception is time-bound and reviewed at least annually; and
  • Material customer-facing exceptions are disclosed or agreed with affected Customers where required by contract.

Exception records SHOULD include the control waived, justification, approver, effective dates, and remediation plan if applicable.


17. Annual Review Process

Aventora Security MUST review this policy at least annually and upon material changes to:

  • AI providers, models, or inference architecture;
  • Product features that introduce or materially change AI processing of Customer Data;
  • Applicable AI, privacy, or security laws and regulatory guidance (including EU AI Act developments);
  • Significant AI-related security or privacy incidents; or
  • Customer contractual obligations affecting AI governance.

17.1 Review Activities

The annual review SHOULD include:

  1. Confirmation that the Subprocessor Annex reflects current AI providers;
  2. Assessment of open risks, incidents, and remediation items related to AI features;
  3. Evaluation of whether prohibited-use and human-oversight requirements remain adequate;
  4. Updates to align with changes in platform architecture and operational practices; and
  5. Communication of revisions to affected personnel.

17.2 Documentation

Review outcomes SHOULD be documented, including approved revisions, open remediation items, assigned owners, and next review date. Version history SHOULD be updated for material changes.


Version History

VersionDateAuthor / OwnerSummary of Changes
1.1.1July 27, 2026Aventora SecuritySection 12: linked enterprise Information Security Risk Management Policy and Risk Assessment and Treatment Procedure
1.1July 20, 2026Aventora SecuritySection 11.2–11.3: require Standard Vendor and Subprocessor Contractual Requirements from Vendor Management Policy for AI Providers (re-identification, Further Subprocessors, DSRs, international transfers)
1.0.1July 6, 2026Aventora SecurityAdded Governance Commitments summary; expanded principles for fairness, ethical use, transparency, customer data protection, and human review and control
1.0July 6, 2026Aventora SecurityInitial release of AI Governance Policy


Contact

For questions regarding this policy, AI governance assessments, or supplemental materials:


This document is provided for informational and contractual support purposes. It does not constitute legal advice. Customers should consult qualified legal counsel regarding their obligations under applicable AI and privacy laws.