Maybank Advisors · Professional services AI operating series
03 · The control system
From AI policy to engagement-level controls
Professional services AI governance is often discussed as a technology problem. It is usually an operating problem first.
The practical question is not simply: can this tool produce useful work? It is:
Can the responsible professional put their name on the result, explain how it was produced, and demonstrate that the information was handled inside the obligations that apply to the engagement?
That question reaches contracts, confidentiality, professional obligations, processing environments, review, accountability and evidence. A tool policy alone cannot answer it.
Who this is for. Managing partners, COOs, general counsel, risk leaders, technology owners and service-line leaders at firms where employees are already using AI — or soon will be — and client information carries contractual, professional or regulatory obligations.
White paper · 2026
A common sequence is: select tool, pilot, discover constraints, write policy, retrofit controls.
A more durable sequence is: identify work, identify information, read the obligations, define permitted routes, establish review, choose technology that fits.
The governing sequence of this paper. Every layer is decided before the one below it.
Work type
What is being produced, and for whom.
Information involved
Which classes of information the work touches.
Executed client / professional obligations
What the signed agreements and professional rules actually permit.
Permitted processing route
Which approved environment may handle it.
Required human review
Who checks what, before the work moves.
Evidence / logging
What record survives the engagement.
Named responsibility
One role accountable for the decision.
Technology belongs inside the control architecture. It should not determine the architecture.
Maybank framework
A policy says: do not put confidential information into unapproved AI tools.
A control answers the questions that sentence leaves open:
The second set of questions is what makes the first sentence usable under deadline.
What information is involved?
Firms need a usable classification system. Not a fifty-page taxonomy — a working one.
Where may each class of information be processed?
Approval should address the environment, not simply the product name: access controls, data retention, model training, subprocessors, storage, logging, contractual protections, geographic processing and administrative access.
What human review is required?
The review burden should follow consequence.
What evidence must survive?
A firm should decide what it needs to reconstruct later.
Who owns the decision?
“Ask IT” is not governance. Neither is “ask legal” if legal does not own the operating workflow. Each decision needs a named role.
An illustrative control structure, not a legal conclusion.
| Information class | General approved AI environment | Firm-controlled AI environment | External / consumer AI | Required review |
|---|---|---|---|---|
| Public | Firm policy | Firm policy | Firm policy | Normal professional review |
| Internal firm information | Defined by policy | Defined by policy | Usually restricted unless specifically approved | Role appropriate to use |
| Client confidential | Engagement + firm rules determine | Engagement + firm rules determine | Do not assume permission | Qualified review + trace appropriate to policy |
| Privileged / regulated / highly sensitive | Explicit firm decision required | Explicit firm decision required | Escalate / do not assume | Firm-defined specialist review and escalation |
The important word is determine. A universal internet chart cannot tell a professional firm what its executed agreements or regulatory obligations allow. Each firm should establish its actual matrix from its contracts, professional obligations, regulatory environment, technology architecture and risk posture.
The matrix exists so practitioners do not have to re-interpret the policy every time work moves.
Maybank illustrative model
AI governance can fail at the engagement boundary.
The master template may say one thing. The signed engagement, amendment, data-processing addendum or client security schedule may say another. The firm should identify the provisions that can affect AI-assisted work, including where applicable:
Do not assume that contractual silence is either permission or prohibition. Treat it as a question that must be resolved by the appropriate firm authority.
Three outcomes, distinguished by treatment: permitted, refused, and unresolved.
Does the work involve client or protected information?
Follow normal firm AI policy.
Continue to the next question.
Do executed obligations clearly permit the proposed processing route?
Apply required control and review.
Escalate to the designated legal or risk authority.
Use an approved alternative route, or do not process.
Does the output create a high-consequence professional conclusion?
Apply enhanced human review and sign-off.
Standard review.
The decision tree does not interpret the contract. It makes sure the contract gets interpreted before the information moves.
Maybank framework
A parallel AI-review process will eventually be skipped. The safer design is to insert the control into the quality step practitioners already use.
Five steps inserted into the quality process practitioners already use.
| Step | Responsible role | Minimum evidence |
|---|---|---|
| Classify | Preparer | Information class + permitted route |
| Produce | Preparer | System / prompt or workflow identity where required |
| Review | Qualified reviewer | Material verification and changes |
| Escalate | Designated owner | Unresolved issues or exception |
| Sign | Responsible professional | Accountability for final deliverable |
The system should not imply that AI is responsible for the work. A professional remains responsible for deciding whether the result is fit to use.
A parallel AI-review process will eventually be skipped. This one sits inside the existing step.
Maybank framework
Logging should be proportionate to the work.
Information classification
What category entered the process?
Processing route
What approved environment handled it?
Workflow identity
Which prompt, agent or workflow version was used where traceability is required?
Sources
What information supported material factual claims?
Reviewer
Who reviewed the result?
Material changes
What did the reviewer alter, reject or add?
Sign-off
Who accepted responsibility for the deliverable?
Exception
Did anything fall outside the normal standard?
Retention should follow the firm’s actual engagement-file, contractual, regulatory and records requirements. Do not invent a new retention schedule simply because AI is involved.
Every row has an owner. That is the point, not the letters.
| Decision | Executive leadership | Legal / risk | Technology / security | Service-line leader | Practitioner |
|---|---|---|---|---|---|
| Firm AI policy | A | C | C | C | I |
| Contract interpretation | I | A | C | C | I |
| Approved technical environments | I | C | A | C | I |
| Delivery method | I | C | C | A | C |
| Engagement-level classification | I | C/Esc | C | A | R |
| Output review | I | C where required | I | A | R |
| Exception response | A | A/C | C | C | R to escalate |
R = Responsible — does the work
A = Accountable — owns the decision
C = Consulted
I = Informed
Illustrative Maybank operating model. Actual accountability should reflect the firm’s structure and professional obligations.
Maybank illustrative model
The point is not the letters. The point is that every row must have an owner.
Good governance assumes an exception will eventually happen. The firm should know what happens next before it does.
Seven steps, decided before an exception happens rather than during one.
Stop
Pause further use or distribution.
Preserve
Keep the relevant record, workflow, output and known facts.
Classify
What information, client, system and obligation are involved?
Escalate
Notify the designated legal, risk, security or engagement owner.
Decide
Determine required client, regulatory, contractual or internal action.
Remediate
Correct the immediate issue and the control that allowed it.
Learn
Update the policy, route, prompt, workflow or training where appropriate.
Do not let the incident process itself become an admission or legal conclusion. Its job is to get the right facts to the right decision-maker.
Maybank framework
Generic disclosure language creates risk when the operating reality cannot support it.
Before counsel drafts or approves client-facing language, the firm should be able to answer: what tools and environments are actually used; what information can enter them; whether providers can use information for model training; what retention settings apply; what subprocessors are involved; what human review occurs; what records are kept; whether client consent is required; and what the firm can truthfully promise.
Seven components counsel needs resolved before client-facing language is finalized.
Use
What AI-assisted activities may occur?
Data
What information may be processed?
Environment
Where may it be processed?
Review
Who remains accountable?
Training / retention
What can the firm verify about provider handling?
Consent / notice
What do the applicable obligations require?
Evidence
What record can the firm produce?
Write the disclosure from the control environment. Do not design the control environment around a disclosure somebody already wrote.
Maybank framework
NIST’s AI Risk Management Framework organizes AI risk work around four functions: Govern, Map, Measure and Manage.
That is useful because governance is not a one-time policy exercise. It is continuous across the life of the system. Maybank’s professional-practice control model can be read against the same structure.
An original Maybank representation of the four NIST functions applied to professional services delivery.
Govern
Ownership, policy, accountability, approved environments
Map
Work type, information class, contracts, consequences
Measure
Testing, review performance, exceptions, traceability
Manage
Approval, escalation, remediation, versioning, retirement
Framework alignment — not NIST endorsement
NIST AI Risk Management Framework 1.0 and Generative AI Profile. NIST’s framework is voluntary and cross-sector; this paper applies operating concepts to professional services delivery.
Maybank framework
Professional services governance cannot be reduced to one universal rule.
For example, in the legal profession, ABA Formal Opinion 512 identifies duties including competence, confidentiality, client communication, supervision, candor and reasonable fees when lawyers use generative AI. That is a legal-sector example — not a rule for accounting, consulting, engineering or creative firms. Each profession needs its own overlay.
The common Maybank question remains:
What has to be true for a responsible professional to use this output and defend how it was produced?
A firm does not need a hundred-page AI manual before it can operate responsibly. It does need enough control to answer the important questions.
Eight components. Enough to operate responsibly without a hundred-page manual.
01
Permitted-use standard
Named approved environments and prohibited uses.
02
Information classification
A small number of classes practitioners can actually apply.
03
Contract / obligation route
A process for resolving engagement-specific restrictions.
04
Human review standard
Who must check what before work moves.
Operable AI governance
05
Traceability
The evidence required for each risk class.
06
Escalation
A named person or role with authority to decide.
07
Change control
A process for tool, workflow and policy changes.
08
Training
Practitioners understand the rules at the point of work.
That is enough to begin responsibly. Then the controls should improve with actual usage, exceptions and evidence.
Maybank framework
A governed firm should be able to answer, without reconstructing the story after the fact:
What work was performed?
What information was involved?
Where did it go?
What instruction or workflow was used?
Who reviewed it?
Who accepted responsibility?
What happened when something fell outside the rule?
If those answers exist only in policy language and not in operating practice, governance has not reached the work yet.
Governance should not be a reason to postpone useful AI indefinitely. It should make useful deployment possible. Start with one real service line, real client obligations and the review step already used by the people doing the work.
Next steps
Continue the series →
01 · The economics
The Window Is Closing
Why this matters economically, and why act now.
02 · The delivery system
The Prompt Library Playbook
How recurring work becomes a governed AI operating asset.
Maybank Advisors · Nashville · Charleston
See how permission, review and accountability fit into the broader economic argument →