Project Controls in the AI EraAI in project controls: use cases and governance · Lesson 21 of 22

Governing AI: human review, audit trails and data quality

Article · 15 min · 8 min lecture

Video lecture

Governing AI: human review, audit trails and data quality

9 chapters · about 8 min · full transcript

Coming soon

Chapter 1 of 9

'The AI said so' is not an answer

  • Seven governance principles
  • Risk-tiered human review
  • Audit trails, model validation and data leakage

The narrated lecture is in production

Every chapter is scripted and ready. Browse the chapters and read the full transcript now — the video will appear here when it’s published.

Chapters

Why governance is non-negotiable

Project controls outputs influence funding decisions, contractual positions, claims and public accountability. If an AI-assisted forecast is wrong, someone must be able to explain what happened, who reviewed it and on what basis it was accepted. Governance makes AI use safe, explainable and auditable.

Principles

  1. Human accountability. A named person owns every forecast, report and decision. AI assists; it does not sign.
  2. Human review proportional to risk. The higher the impact, the more rigorous the review.
  3. Traceability. Inputs, prompts or model versions, outputs and human edits are recorded.
  4. Data quality and fitness. Models use governed, validated data.
  5. Confidentiality and privacy. Only approved tools; sensitive data protected; personal data handled lawfully.
  6. Transparency. Readers know when content was AI-assisted, per company policy.
  7. Monitoring. Model performance is tracked over time and models are retired or retrained when they drift.

A risk-tiered review model

TierExampleReview requirement
LowFormatting, summarising meeting notesSpot check
MediumDraft variance narrative, schedule quality suggestionsFull review by controls lead; facts checked against source
HighEAC or forecast date used for funding, contractual notices, claimsIndependent review, documented rationale, approval by accountable manager
ProhibitedFully automated contractual or financial decisions without human approvalNot allowed

The audit trail

For each AI-assisted output, record:

Output ID: RPT-2026-09-P14-narrative
Purpose: Monthly executive narrative
Tool / model and version: [approved enterprise assistant, version]
Input data: EVM table v3 (data date 31-Aug), risk register export 01-Sep, change log 01-Sep
Prompt / template reference: NARR-TPL-02
AI draft stored: yes (link)
Human reviewer: [name]   Date: ______
Changes made: corrected cause for CA 1.3; removed unsupported claim on recovery
Approval: [accountable manager]

This record allows anyone to reconstruct how an output was produced and reviewed, which is increasingly expected by auditors and, in some sectors and jurisdictions, by regulation.

Data quality for AI

AI-specific checks on top of normal controls data quality:

  • Representativeness: is training history similar to the current project (type, size, region, contract model)?
  • Leakage: does the model accidentally use information that would not have been known at the time (e.g., final costs) when trained on history?
  • Bias: are some project types or contractors under-represented, leading to systematically wrong predictions?
  • Freshness: are prices, productivity and conditions in the data still relevant?

Validating models

  • Back-testing: run the model on completed projects as they were at earlier data dates and compare its forecasts with actual outcomes, alongside traditional methods.
  • Benchmark: a model should beat simple methods (e.g., CPI-based EAC) to justify its complexity.
  • Explainability: prefer outputs that show drivers ("this forecast is higher because CPI has declined for four periods and similar packages overran").
  • Drift monitoring: track error over time; investigate if it grows.

Regulatory and policy landscape (high level)

Rules on AI vary by jurisdiction and continue to evolve. The EU AI Act introduces risk-based obligations; the UK has taken a principles-based, regulator-led approach; the US has a mix of federal guidance and state laws; the UAE and Saudi Arabia have published national AI strategies, principles and guidance, and Pakistan has developed national AI policy work. Management-system standards such as ISO/IEC 42001 provide a framework for AI governance. Always follow your organisation's legal and compliance guidance; this course does not provide legal advice.

Worked example: a governance failure

Illustrative. A fictional developer used an AI model to forecast EAC for a portfolio. The model had been trained on projects that had mostly finished, but the training data inadvertently included final-cost fields, so historical back-tests looked excellent. In live use, forecasts were far too optimistic. Because no audit trail recorded which model version produced which forecast, it took weeks to identify the problem. Fixes: leakage checks, versioned models, back-testing at historical data dates, and a rule that portfolio forecasts are always compared with CPI-based methods.

Common mistakes

  • "The AI said so" as a justification.
  • No record of model versions or prompts.
  • Using public tools with confidential commercial data.
  • Training on data that is not representative of current projects.
  • No ongoing monitoring after deployment.

Hands-on: back-testing a forecast method against the CPI benchmark

import pandas as pd

# one row per completed project per historical snapshot, using ONLY data known at that date
snap = pd.read_csv("historical_snapshots.csv")  # project, pct_complete, BAC, EV, AC, model_eac, final_cost
snap["cpi_eac"] = snap.BAC / (snap.EV / snap.AC)
for m in ["model_eac", "cpi_eac"]:
    snap[f"err_{m}"] = (snap[m] - snap.final_cost).abs() / snap.final_cost

summary = snap.groupby("pct_complete")[["err_model_eac", "err_cpi_eac"]].median().round(3)
print(summary)            # median absolute % error by stage
wins = (snap.err_model_eac < snap.err_cpi_eac).mean()
print(f"Model beats CPI benchmark in {wins:.0%} of snapshots")

Leakage check before training: list every feature and ask "would this have been known at the snapshot date?" Remove anything that encodes the outcome (final cost, final duration, close-out flags).

Template: AI use policy for a controls team (one page)

1 Purpose and scope: which controls outputs may be AI-assisted.
2 Approved tools: names, versions, data classifications each may process.
3 Tiers: Low (spot check) | Medium (full review vs source) | High (independent review + approval) | Prohibited.
4 Required audit fields: output ID, purpose, tool/model version, inputs + data dates, prompt/template ref,
  draft stored, reviewer, changes made, approver.
5 Data rules: no confidential commercial or personal data in unapproved tools; leakage and bias checks for models.
6 Validation and monitoring: back-test vs simple benchmarks; quarterly error review; retire on drift.
7 Transparency: how AI assistance is disclosed in reports (per company policy).
8 Ownership: policy owner, review date.

How to measure success

  • 100% of medium and high-tier outputs have a complete audit record.
  • Models in use beat simple benchmarks in back-tests and are re-checked at least quarterly.
  • No incidents of unapproved tools processing confidential data.

Key takeaways

  • A named human is accountable for every AI-assisted forecast, report and decision.
  • Scale review rigour to impact; prohibit fully automated high-stakes decisions.
  • Record inputs, model/version, outputs, human edits and approvals in an audit trail.
  • Validate models with back-testing, benchmarks, leakage and bias checks, and monitor drift.

Check your understanding

Quick questions to lock in the lesson. They don’t count towards your certificate.

  1. An AI-generated EAC will be used to request additional funding from the board. What review is appropriate?
  2. A model's back-tests look excellent, but live forecasts are poor. Which issue is a likely cause?
  3. Which item belongs in an AI audit trail record?
  4. Why benchmark an AI forecasting model against simple CPI-based EAC?

Put it into practice

Draft a one-page AI use policy for your controls team: tiers, review requirements, approved tools, audit trail fields and prohibited uses.

Enrol for free to save your progress

Reading is always free. Enrol to keep your place, take the final assessment and earn a verifiable certificate.