Project Compass | AI use policy
AI use policy timeline for Compass Assist
Draft v0.2 | 29 January 2027 | Change lead, Change Made Simple | Policy owner: Fatima Haddad, Head of compliance
Compass Assist cannot go live for any group until Risk and Compliance approves the policy and its guardrails. This page shows the eight steps, which are done, and where the sign-off gate now sits.
- The guardrails sign-off gate moves from Fri 26 Mar 2027 to Fri 9 Apr 2027, ten days before go-live. The test set cannot be complete before UAT closes (T5, change C-3).
- Training demonstrates Compass Assist with the approved guardrails only (T5).
- Q-05 is answered: Compass Assist may draft written complaint responses, and the complaints officer must edit and send them. Drafts are labelled (T5, change C-5).
- Compass Assist is off for business bankers at go-live and offered in week 3 as opt-in (T4).
Where the policy stands
- The draft policy was written after the Risk and Compliance session on Tue 19 Jan 2027 and issued as v0.1 on Fri 22 Jan. Three desk reviews have since checked it against guidance, the assistant's set-up and Hampton Bank's other policies.
- The formal Risk and Compliance review runs from Mon 1 Feb to Fri 19 Feb 2027, with a second draft back to the reviewers inside that window. The guardrails test set is built alongside and run after UAT closes on Wed 17 Mar.
- Fatima Haddad approves at the sign-off gate on Fri 9 Apr 2027. Training uses the approved guardrails only, Victoria goes live on Mon 19 Apr, and NSW sign-off is confirmed before Mon 7 Jun.
Policy owner: Fatima Haddad Reviewers: Ben Okafor Priya Raman Executive sponsor for the policy: Name to be assigned by compliance
Eight steps
- 1Policy draftFri 22 Jan 2027
- ↻Risk and Compliance reviewMon 1 to Fri 19 Feb
- 3Guardrails test setMon 15 Feb to Thu 8 Apr
- 4Sign-off gateFri 9 Apr 2027was Fri 26 Mar Updated v0.2
- 5Training, approved guardrails onlyTue 30 Mar to Fri 16 Apr
- 6Victoria go-liveMon 19 Apr 2027
- 7Review after hypercareMon 3 to Fri 14 May
- 8NSW sign-off confirmationBefore Mon 7 Jun 2027
Filled dot: done. Hollow dot: planned. Dashed dot: in the feedback loop. Large dot: go-live. The green line runs to the last done step.
1. Policy draft
Fri 22 Jan 2027 | done
- v0.1 written from the T3 decisions of Tue 19 Jan.
- Human review of every drafted text is a written rule.
- No customer personal data in prompts outside Salesforce.
2. Risk and Compliance review
Mon 1 to Fri 19 Feb | in the feedback loop
See the three reviews- Second draft due Fri 19 Feb.
- Loop avoids the school holidays and Easter.
3. Guardrails test set
Mon 15 Feb to Thu 8 Apr | planned
- Ben Okafor drafts the test set outline by Fri 12 Feb.
- The set is run after UAT closes on Wed 17 Mar.
- Easter, Fri 26 to Mon 29 Mar, is excluded.
4. Sign-off gate Updated v0.2
Fri 9 Apr 2027 (was Fri 26 Mar) | planned
- Fatima Haddad confirms the date in writing by Fri 5 Feb (A-27).
- Ten days before go-live on Mon 19 Apr.
- Risk R-14 covers the narrower margin.
5. Training Updated v0.2
Tue 30 Mar to Fri 16 Apr | planned
- Compass Assist is shown with approved guardrails only.
- Compass Assist blocks run from Mon 12 Apr, after the gate. Sam Petrovic to confirm the blocks
- Make-up sessions on Wed 14 and Thu 15 Apr.
- Bankers see Compass Assist in week 3, as opt-in.
6. Victoria go-live
Mon 19 Apr 2027 | planned
- Wave 1 groups start with Compass Assist, except business bankers.
- Hypercare runs to Fri 30 Apr.
7. Review after hypercare
Mon 3 to Fri 14 May | planned
- Fatima Haddad's team reads the Compass Assist logs.
- Policy changes found are made before NSW training.
- Prompt-change ownership (Q-02) is settled here.
8. NSW sign-off confirmation
Before Mon 7 Jun 2027 | planned
- Risk and Compliance confirms the policy still holds for Wave 2.
- NSW training runs from Mon 17 May.
- Confirm NSW school calendar once for the plan.
What the policy solves
- One rule for who may use Compass Assist. Each group in Wave 1 and Wave 2 knows whether it has the assistant at go-live.
- A human review rule. An agent reviews all drafted text before saving, and a complaints officer edits and sends any complaint response.
- A clear data boundary. No customer personal data goes into prompts outside Salesforce.
- Logging and a gate. Use is logged, and Risk and Compliance approves before each wave.
End outcome: staff use Compass Assist inside rules they can state in a sentence, and Fatima Haddad can show the board how each rule is checked.
| Question | Policy that answers it |
|---|---|
| Who may use Compass Assist, and when? | The AI use policy, which sets groups and the approval gate. |
| May it draft a complaint response? Updated v0.2 | The AI use policy: yes, labelled, then edited and sent by the complaints officer. |
| Can customer personal data go into a prompt? | The privacy policy, read with the AI use policy: not outside Salesforce. |
| Who owns prompt changes after go-live? | Not covered yet. Q-02 open |
| How long are AI-drafted notes kept? | The records policy, which does not yet name Compass Assist. |
Where policies disagree
Four points are listed once here and settled in the feedback loop.
- Complaint responses. The complaints handling procedure has staff write responses; the AI use policy allows drafts. Settled in T5: drafts are allowed, labelled, and edited and sent by the complaints officer.
- Personal data in prompts. The privacy policy allows approved tools; the AI use policy allows none outside Salesforce. Priya Raman is checking the wording with security (A-12). Open.
- Prompt changes. No policy names an owner. Q-02 is with Fatima Haddad and Anika Rao. Open.
- Record keeping. The records policy names the author of a case note, and a Compass Assist draft has two. Owner: Fatima Haddad. Wording to be agreed
All Hampton Bank policies on this page are fictional. See open questions and solution overview, process 5.
Three desk reviews of draft v0.1 were prepared for the Risk and Compliance review. Each reads documents, not the live system, and each is re-run after UAT. Counts are from the review pages.
Review A: against published AI governance guidance
Inputs
- Draft AI use policy v0.1
- T3 decisions, Tue 19 Jan
- Hampton risk appetite statement
- Guidance set used by compliance Set to be named
- Salesforce public documentation on AI assistant features
- Privacy policy
Outputs
- Human review is covered in full.
- Logging is partly covered and needs a retention period.
- Incident handling is the one missing item.
Review B: against the Compass Assist configuration
Inputs
- Draft AI use policy v0.1
- Northgate Digital configuration notes
- Salesforce public documentation on AI assistant features
- Solution overview, process 5
Outputs
- Draft labelling for complaint responses is a build item for Jorge Alvarez.
- Logging fields are partly planned.
- Group-level switch for bankers is missing and needed at go-live.
Review C: against Hampton Bank's other policies
Inputs
- Draft AI use policy v0.1
- Privacy policy
- Records policy
- Complaints handling procedure
- Information security policy
- Outsourcing policy
- Conduct and ethics policy
- Training and competency policy
Outputs
- Complaints wording is settled after T5.
- Records policy does not yet name AI-drafted notes.
- Training policy needs a line on approved guardrails.
Sources: T3 risk and compliance session, T4 business banking workshop, T5 steering catch-up. Related: plan on a page, go/no-go, phased rollout, risk register, shared facts.