Leadership · 5 minute read
How to Run an AI Ethics Review
An AI ethics review works when it is triggered by defined criteria, attended by people with authority, asks five specific questions, reaches a recorded decision with reasoning, and has the power to require changes or stop a deployment. Reviews without decision authority become documentation exercises.
AI ethics reviews fail in two directions. Some rubber-stamp: a meeting happens, notes are filed, and no deployment has ever been changed by one. Others stall: every deployment goes to a committee that meets monthly and asks for more information. Both outcomes teach the organization that the review is an obstacle to route around. This guide covers a review process that reaches decisions.
What triggers a review?
Defined criteria, not everything. Reviewing every agent means reviewing none properly and turning the committee into a bottleneck. Sensible triggers:
- Decisions affecting individuals' rights, access, or livelihood: employment, credit, insurance, benefits, education, housing.
- Use of sensitive personal data, including health, biometric, or protected characteristics.
- Customer-facing autonomous action with consequence.
- Novel applications with no precedent in the company.
- Anything the risk tiering classifies as high tier.
- Any deployment where the delivery team requests a review.
Everything else proceeds under standard controls enforced by the platform. The executive guide to AI agent governance covers the tiering that makes this proportionate.
Who attends?
People with authority to require changes: a senior business representative who can accept the cost of a change, legal, risk or compliance, and the technical owner who can explain what the system actually does. Add at least one person independent of the delivery team, and where the deployment affects a specific population, someone with relevant domain knowledge.
What does not work: a committee of advisers with no standing to object, or a meeting where only the delivery team can answer questions and everyone else nods. The AI ethics committee guide covers the standing structure.
What questions are asked?
Five, applied consistently:
| Question | What it surfaces | Evidence required |
|---|---|---|
| Who is affected, and how? | Scope and severity of consequence | Impact assessment; affected populations |
| Is it fair across groups? | Disparate outcomes | Fairness test results on real cases |
| Is it transparent to those affected? | Whether people know and understand | Disclosure design; explanation samples |
| Can they seek recourse? | Ability to challenge and correct | Escalation and correction paths |
| Would we defend it publicly? | Reputational and values alignment | The honest answer from the room |
The AI ethics for executives piece covers how these questions become enforced controls rather than discussion topics.
How are decisions made and recorded?
The review reaches one of four outcomes: approve; approve with conditions (specific changes, with a verification step); defer pending specified evidence; or decline. Each is recorded with the reasoning, the evidence considered, the conditions, and a review date.
The record matters for two reasons. Consistency across cases is what makes the process credible internally: teams need to see that similar cases get similar treatment. And if a decision is later questioned by a regulator, a claimant, or a journalist, the record is the demonstration that the company considered the question seriously. The who is accountable when an AI agent fails guide covers why the documentation matters after the fact.
How fast should it be?
Days, not months. A review that takes a quarter guarantees that teams stop bringing things to it. Practical approach: a standing weekly or fortnightly slot, a short submission template completed by the delivery team, and a decision at the meeting unless specified evidence is genuinely missing. Deferrals should name exactly what is needed.
What if the review has never declined anything?
Then it is not a review, and everyone knows it. A functioning process will, over a year, decline at least one proposal and attach conditions to several. If nothing has ever changed as a result, the triggers are set too narrowly, the attendance lacks authority, or the process is decorative. Executives should check this explicitly, because a decorative ethics review is worse than none: it creates a record suggesting scrutiny that did not occur.
How does the review relate to other governance?
It sits alongside, not instead of. Security review covers whether the agent can be attacked or misused; legal review covers obligations and contractual exposure; the ethics review covers whether the company should do this at all and on what terms. Overlap is normal and useful, but the three should not be merged into a single approval gate, because merged gates default to the concerns of whoever chairs them and the ethical question is the one most easily dropped. Where the same people attend all three, run them as distinct agenda items with distinct records so the reasoning is separable afterward.
What should executives ask?
- What triggers a review, and when did one last happen?
- Who in the room can require a change or stop a launch?
- How many reviews resulted in conditions or a decline this year?
- Can we produce the reasoning for any decision made?
- How long does a review take from submission to decision?
How can FISTA Solutions help?
FISTA Solutions builds AI agents with the impact assessments, fairness testing, disclosure design, and recourse paths that an ethics review examines, and works with executive teams through its AI enablement practice to set triggers, questions, and records that produce decisions rather than documentation. Since 2017, FISTA has delivered 150+ projects for 50+ companies across 12+ countries.
To design a review process teams will use rather than avoid, talk to FISTA on WhatsApp, or read AI ethics for executives.
Share-ready article cover
Download the generated social format.
Clear answers
Questions raised by this field note.
Straightforward guidance for evaluating scope, fit, and the next step.
01What triggers an AI ethics review?
Defined criteria rather than every deployment: decisions affecting individuals' rights, access, or livelihood; use of sensitive personal data; customer-facing autonomous action; novel applications without precedent in the company; and anything the risk tiering classifies as high. Everything else proceeds under standard controls.
02Who should attend an AI ethics review?
People with authority to require changes: a senior business representative, legal, risk or compliance, the technical owner, and at least one person independent of the delivery team. Domain expertise relevant to the affected population is valuable where the deployment touches a specific group.
03What questions should an AI ethics review ask?
Who is affected and how; whether outcomes are fair across groups; whether affected people know AI is involved and understand what it does; whether they can challenge or correct it; and whether the company would defend the use publicly if described accurately.
04How should review decisions be recorded?
With the decision, the reasoning, the conditions attached, the evidence considered, and the review date. The record matters because consistency across cases is what makes the process credible, and because a regulator or claimant may later ask how the decision was reached.
05What makes AI ethics reviews fail?
No decision authority, so reviews produce advice nobody must follow; reviewing everything, so nothing gets real attention; attendance by people without standing to object; no record, so decisions are inconsistent; and never declining anything, which tells the organization the review is theater.
Continue exploring
Related capabilities
Start with the hard problem
Need the outcome owned, not merely analyzed?
Tell us where delivery is constrained. We’ll map the fastest credible path from intent to verified production.