AI Drafts It. A Human Approves It. Nobody Chases It.

Compliance teams need AI to reduce collection and follow-up without letting it make consequential decisions alone. The system drafts, a person approves, and the workflow tracks the handoff.

Sorena AI TeamProduct and Strategy3 min read

Keep judgment separate from collection

AI can make decisions without adequate oversight, while manual compliance can consume expert time with collection, mapping, and follow-up.

A clear division of labor addresses both risks. Let the system handle collection, mapping, and drafting, and reserve human attention for judgment and approval.

Split the work by who is good at what

Use systems for repeatable work and people for accountable decisions. Collection, mapping, drafting, tracking, and assembly are high-volume tasks. Judgment, prioritization, and risk trade-offs require context and an accountable person.

The system reads the requirement, gathers the evidence, maps it, and drafts the response. A person reviews the draft, applies judgment, and approves or corrects it. The workflow tracks the steps between drafting and approval.

How NIST treats human oversight

Design human oversight into workflows where the risk calls for it. The NIST AI Risk Management Framework has four functions: Govern, Map, Measure, and Manage. NIST describes Govern as a cross-cutting function that informs the other three.

NIST notes that some AI systems may not require human oversight while others may require it. MAP 3.5 says organizations should define, assess, and document human-oversight processes according to policies from the Govern function. For consequential compliance positions, define the reviewer, route the draft to that person, and keep the decision record.

What the approval object should contain

Give the reviewer a precise approval record. A governed assessment answer should include the requirement, AI draft, cited evidence passage, confidence or coverage signal, reviewer, decision, and timestamp. Keep prior versions when the answer changes.

The reviewer approves a claim, its evidence, and the obligation it satisfies. If the reviewer rejects it, route the gap back to an owner instead of leaving the draft in chat history.

Make review part of the workflow

Do not rely on someone remembering to review a draft. Require the review in the workflow.

In Sorena Assessment, the system extracts requirements, gathers evidence, and drafts the mapped response. A person must review and approve it before it is final. Each draft links to evidence and each approval is logged.

Judgment stays where it belongs

Risk decisions need an owner, and that owner is a person. Deciding whether a control is adequate, whether a gap is acceptable, or how to prioritize remediation is a judgment call with consequences. Those calls belong to accountable people, not to a model.

Risk work stays human-led. When Sorena surfaces a gap or a concentration of exposure, it hands the decision to the people who own it in Sorena Risk Management, with the evidence assembled and the context in front of them. The system removes the grunt work of finding and formatting. The human keeps the part that requires accountability. Humans decide, systems execute.

Nobody chases what the system already tracks

Track the handoff from draft to approval. In manual work, a draft can sit after the approval request until a deadline forces follow-up.

Once the system routes a draft for approval, it should track the item, owner, evidence, and due date through completion. The reviewer receives the material needed to make the decision without manually chasing status.

Spend human attention on judgment

Keep people responsible for judgment and approval. Use the system to collect, map, draft, route, and record the work around that decision.

AI drafts it. A person approves it. The system tracks the handoff and keeps the evidence and approval record.

Frequently asked questions

Does governed automation mean AI makes compliance decisions?+

No. The system handles collection, mapping, drafting, and tracking, but a human reviews and approves before anything is final. This fits the NIST AI Risk Management Framework pattern: Govern is cross-cutting, and MAP 3.5 calls for human-oversight processes to be defined, assessed, and documented according to organizational governance policies.

How is this different from just using an AI chatbot for compliance?+

A chatbot gives you an ungoverned answer with no built-in approval, evidence trail, or tracking. Sorena Assessment builds the guardrails into the workflow: every draft is grounded in evidence, requires human approval, is traceable to its source, and is tracked to completion. Oversight is structural, not left to the user to remember.

Who owns risk decisions in this model?+

People do. Judgment, prioritization, and risk trade-offs stay with accountable humans. When Sorena surfaces a gap, it assembles the evidence and hands the decision to the owners in Sorena Risk Management. The system removes the grunt work; the human keeps the accountability.

Sources

Share

See Sorena do the work

Book a demo and watch one real compliance workflow go from question to audit-ready output.