Review
How we review
live systems.
This page is the review policy. The web address stays /governance/ai-ethics so old links still work. The title is about review, not about a slogan.
Patrick Enwerem Limited builds and runs systems that can send a message, score a lead, draft a script, or speak a walkthrough. Those systems can help a team. They can also bother a person who did not ask. This page says who signs off, who can stop the work, and what we will not do.
It is not a research paper. It is not a certificate. It is not a promise that every model is fair in every setting.
Why a review page exists
A message sent at scale is not a private note. A score that ranks people is not a toy. A voice file that sounds like advice is not a joke. If we cannot say who approved the live run, we should not run it.
Review exists so that a ministry, a bank, or a founder can see the rule before they hand us a list. Review exists so that a person inside PEL can point to a page when someone asks them to skip the human step.
Scope
This policy covers:
Outbound systems we operate. Scoring and ranking we operate. Written reports and scripts we produce as part of an assessment. Voice walkthroughs we produce as part of an assessment. Any other automated system named in a SOW that can affect a person.
It does not cover a client's own tools that we never touch. It does not cover a public social post by someone who does not work for us. It does not cover a spreadsheet a client built alone.
If a job is only a document, the review is lighter. If a job can send, score, or speak without a person in the middle, the review is heavier.
Five operating rules
Rule one. A named person is accountable for each live system. Today that person is reached at info@penwerem.com. When extra committee members are seated, this page will say so. Until then the director signs.
Rule two. Sensitive decisions keep a human in the loop. The system may draft. It may not close a legal, credit, hiring, or medical decision on its own. It may not issue a government benefit decision on its own. It may not send a threat. It may not impersonate a public official.
Rule three. Client data and briefs are not used to train a third-party model. We may use tools to draft. We do not pour your file into a public training pot.
Rule four. Before a high-risk use, we test for unfair outcomes on the groups the client names. If the client will not name the groups, we still ask. If the use is low risk, we still keep rules one, two, three, and five.
Rule five. Every live system has a stop. Cadence can be paused. A mailbox can be disconnected. A broken connection is a stop, not a reason to guess and keep sending.
These five rules are the whole spine. The rest of this page is how they show up in work.
What counts as high risk
High risk, for us, includes:
Public-sector work that touches citizens. Regulated finance work that scores a person. Any work that uses a protected or sensitive attribute to rank people. Any work that sends a message that looks like legal, medical, or credit advice. Any work that could get a person fired, denied a service, or publicly shamed.
Low risk, for us, includes:
A draft email that a human must send. A research note that a human must read. A scorecard that does not auto-send.
Low risk is not no risk. A draft can still be cruel. A human still reads it before it goes.
If we argue about the line, we treat the job as high risk until the SOW says otherwise.
The path of a job
Brief. Someone tells us the problem and the constraint. Scope. We write what we will do and what we will not do. Build. We connect only what the scope named. Review. A human looks at sample outputs and at the stop. Run. The system goes live under the locks. Pause. If something breaks, we stop.
Skipping review to save a week is how you buy a month of cleanup. We will not skip it on high-risk work to win a date on a slide.
The Ethics Committee
The Trust hub names an Ethics Committee. That is the review function.
Appointment of extra members may still be in progress. That sentence is here so you do not invent a panel. Until extra members sit, the director signs the review and keeps the record.
The committee, or the director in its place, can:
Approve a high-risk go-live. Require a change. Refuse a go-live. Order a pause on a live system.
It cannot:
Invent a licence. Invent a certificate. Approve a bribe. Approve a 100 percent close claim. Approve retired internal names in prospect copy.
Records stay with the company. They are not a blog.
Humans in the loop
A human in the loop means a person who can read the output and stop it. It does not mean a person who clicks approve on a hundred items without looking. If the volume makes looking impossible, the volume is wrong. We cut the volume or we add people. We do not pretend a blur of clicks is oversight.
For outbound, the locked model already limits what the machine may do after a reply. A hot lead can be booked once, then the cadence stops. An objection can take one audit path. Out of office gets one warm path, then stop. Not interested is lost. Neutral alerts a human and does not pretend to be a close. An audit path never books and never turns outbound on.
For assessments, a person can open the row and read the script before anyone records a video. The sheet is the queue. It is not an auto-publish button.
Data the review must see
A review that cannot see the data the system will use is not a review. We need to know:
Where the list came from. Whether the client had a right to use it. Whether it includes people who asked not to be contacted. Whether it includes children. Whether it includes public officials in a way that creates a separate rule.
If the client cannot answer, we do not connect the list.
We do not need to see passwords. We do not need to see a full card number. Paystack holds cards.
Testing for unfair outcomes
We are not a university lab. We will not publish a fake fairness score with three decimal places. We will do something simpler and harder to dodge.
Ask who could be harmed. Ask which groups the client cares about. Look at sample outputs for those groups. Look for slurs, stereotypes, and junk rankings. Write down what we saw. Change the system or refuse the go-live.
If the client wants a formal study, that is a line in the SOW with a fee. It is not a free poster.
Models and tools
We may use third-party models to draft. Those tools change names and prices. This page does not pin a brand so that a rebrand makes the policy false.
Before F1, internal automation canvases are being moved to Claude 4.6 or below. That is an internal operations note. It is not a client feature. It does not mean a prospect should hear a model name in an outreach line.
Whatever the tool, rules three and five still hold. Your brief is not training data for a public pot. The system still has a stop.
We do not put Kimi on a live canvas because a free quota looked nice. We do not put a random new model on a live canvas because a demo was clever.
Voice and likeness
If we produce a voice walkthrough, it is a delivered file for the person who bought the work. It is not a clone of a stranger. It is not a political deepfake. We will not build a voice that pretends to be a named official.
If a page plays audio, the page should say what it is. We do not hide a generated voice as a secret CEO cameo.
What operators may not say
Outreach from this firm does not sell a model name to a prospect. Outreach does not say retired internal names. Outreach does not say 100 percent close. Outreach does not say unhackable. Outreach does not say we read your private mail without a lawful basis.
If a template drifts into those words, we cut the template. If a person types them anyway, we correct it and we treat it as a review miss.
Children and vulnerable people
We do not target children. If a list might include them, we stop and ask. If a job targets people in distress, the human loop gets tighter, not looser. A scared person does not need a faster cadence.
Public-sector extra care
Public work can affect people who did not choose us. We assume a journalist will read the output. We assume an opposition letter will quote it. We write the SOW that way.
We do not scrape a ministry mailbox because we can. We do not train on citizen files. We do not put a citizen file in a demo.
If a public body needs an extra review board of their own, we work with that board. We do not replace it.
Incidents
If a live system sends the wrong thing, we pause. We tell the client. We keep the record. We fix the cause or we leave it off.
If a person says they were harmed, we do not argue about feelings first. We pause, we read, we answer. Legal threats go to info@penwerem.com and to counsel as needed.
We do not pay silence money to hide a real failure. We also do not publish a client as a villain to save our pride.
Complaints
Write info@penwerem.com. Name the system. Name the date. Name the harm. We pause when pause is safe.
Data-rights complaints also go there, and to the Nigeria Data Protection Commission if you choose.
Records
Reviews, pauses, and complaints are kept as business records. They are not tweets. They last as long as the law and the SOW need. They are not used as marketing.
Training our own people
People who operate a live system should know the five rules. They should know how to pause. They should know that a clever bypass is still a bypass. We do not need a poster. We need a person who will pull the stop.
Relationship to Privacy and to compliance
Privacy is the notice for personal data. Compliance is how the company is set up. This page is how live systems are watched. Read all three if your job will send or score.
ISO/IEC 27001 remains a target on the security page. It is not a substitute for a human stop.
What this page refuses to become
It will not become a slogan wall. It will not become a fake academic journal. It will not become a place to rename old products. It will not become a place to claim a close rate. It will not become a place to claim the system cannot be abused.
Any system that can send can be abused. That is why the stop exists.
Worked cases, without fake clients
A client wants outbound to a purchased list of unknown origin. We ask for the origin. If they cannot show a right to use it, we do not connect it.
A client wants the system to auto-book anyone who replies with a single word. We do not. Hot is a class with a lock. We do not invent a hotter class that books everyone.
A client wants a voice that sounds like a minister. We say no.
A client wants us to hide the stop because the team will "be careful". We keep the stop.
A client wants the $250 audit to start outbound. We do not. The audit is a result. Outbound waits for setup or retainer.
A client wants a retired internal name on a landing page. We do not.
How this page will change
When extra committee members sit, we will name the function more precisely. We will not invent them early.
When a rule proves too weak, we tighten it. When a sentence is theatre, we cut it.
There is no stamp under the title. The live page is the current page. A dated pack is available on request.
A longer note for a risk committee
If you sit on a bank or ministry risk committee, you will ask whether we understand model risk. Here is the plain answer.
We understand that a drafting tool can sound sure when it is guessing. That is why a human reads high-risk output. We understand that a ranker can copy yesterday's bias. That is why we ask who could be harmed and we look at samples. We understand that a connected mailbox can send after the operator has gone home. That is why a broken account is a stop. We understand that a vendor model can change under us. That is why we do not pin our ethics to a brand name on a homepage.
We do not understand your unpublished internal model inventory. That remains yours. We will not sign that we audited a system we never saw.
A longer note for operators
If you run the queue, you are part of the review. You do not wait for a committee meeting to pause a bad send. You pause, then you write what you saw.
If a metric looks good because the system is pestering people, the metric is wrong. The accepted metric is one of three: a positive reply, an invite accepted, or a new connection. It is not a raw send count. Admin and client see the same three choices. Do not invent a fourth to make a chart climb.
A longer note for writers of prompts and templates
Write like a person. Do not write like a brochure. Do not lean on brochure adjectives. Do not use an em dash as a crutch. Do not mention retired internal names. Do not mention a close rate. Do not mention unhackable.
If a template needs a fact, use a fact the client gave. If the fact is missing, leave a hole for a human. Do not fill the hole with a guess that sounds like research.
Closing
This is how Patrick Enwerem Limited reviews live systems. It is long because the short version gets ignored. It is plain because a fancy version hides the stop.
A human signs off. A human can stop it. Your brief is not public training data. We will not send a lie to win a week.
Write info@penwerem.com if a line is wrong or if a system we run caused harm.
Back to the Trust hub when you are done.
Queue hygiene
A queue that cannot be paused is not a queue. It is a hose. Assessments sit in a sheet so a person can open a row. Leads sit in a sheet so a person can see status. If a pill wraps into two letters, that is a design defect, not a review pass.
Source belongs in its own column when the same company name arrives from more than one door. SalesLever is one door. The firm site is another. Mixing those badges into the name cell is how a sheet starts to look like a pile.
Metrics that lie
Send count lies when the send is junk. Open count lies when a preview loads. Time-on-page lies when a tab is left open. Only the three accepted metrics are allowed to mean success in the engine: positive reply, invite accepted, new connection. Pick one. Do not average them into a vanity number.
Night and weekend sends
A lock that only works in office hours is not a lock. Pause must work at night. A broken Unipile state must stop the send at night. Telegram may wake a person. It must not auto-invent a new path.
Language in outputs
Outputs should read like a person who did the work. They should not read like a brochure. They should not invent a meeting that did not happen. They should not invent a metric. They should not invent a regulator letter.
If a script needs a hole, leave the hole. A human can fill a hole. A human cannot easily unsend a lie.
Languages other than English
If the audience reads another language, the SOW says so. We do not auto-switch into slang we cannot defend. We do not mock a dialect to sound local.
Accessibility of outputs
A report should be readable. A voice file should have a written twin when the buyer needs one. We do not hide a result in a format the buyer cannot open.
Second reviewers
On high-risk work, a second person may read the sample. If we do not have a second person yet, the director is the second person. We do not invent a reviewer.
When a client brings their own model
If they insist, the SOW names it. Our five rules still apply. Their model does not get to skip the stop. Their model does not get to train on another client's brief.
When a client wants speed more than review
We keep the review. We cut scope. We do not cut the human. If that loses the deal, the deal was the wrong deal.
Closing addendum
A live system is a tool with a stop. This page is the stop written down. Use it.
How a review meeting should run
A review is not a slide. It is a short sitting with the sample outputs, the list origin, the stop, and a yes or a no.
Someone names the job in one sentence. Someone names who could be harmed. Someone shows five real samples, not a polished one. Someone shows the stop. Someone says go, change, or no. Someone writes the decision.
If the sitting cannot produce those six beats, it is not a review. It is a chat.
How a review record should look
Date. Job name. Who sat. What was sampled. What harm was named. The decision. The follow-up date if the decision was change.
That record is a business file. It is not a tweet. It is not a case study. It does not name a private person on this public page.
How we treat a no
No means the live path does not start. It does not mean we rewrite the no into a soft yes after lunch. If the client can change the job so the harm drops, we can sit again. The second sitting is a new record.
A no can protect the client as much as it protects us. A ministry that would have been embarrassed by a send should prefer the no.
How we treat a change
Change means a named fix. Cut the list. Cut the volume. Add a human. Remove a sentence. Remove a voice. Then sit again. A change without a second look is a yes in disguise.
How we treat a yes
Yes means the path may go live under the locks that were shown. It does not mean every future change is pre-approved. A new send path needs a new look. A new list needs a new look. A new regulator on the job needs a new look.
Samples we insist on seeing
A sample that would go to a senior official. A sample that would go to a person who already said no. A sample that would go to a person whose name looks like it may be a child. A sample that failed. A sample that the system thinks is its best work.
The best-work sample is often where the lie hides. A system that sounds sure is more dangerous than a system that sounds unsure.
Lists we refuse
A list with no origin. A list bought from a stranger who will not name the source. A list that mixes children with executives. A list that is clearly a dump from a hack. A list the client will not put their name on.
We can help clean a list the client owns. We cannot launder a list the client will not own.
Messages we refuse
A threat. A bribe. A fake court letter. A fake regulator letter. A medical claim we cannot stand behind. A credit claim we cannot stand behind. A promise of a 100 percent close. A claim that we are unhackable. A mention of a retired internal name. A mention of a product as if it were a separate company.
Voices we refuse
A minister. A judge. A living private person who did not hire us to sound like them. A dead person used as a trick. A child.
A delivered walkthrough for a buyer who paid for their own result is not those things. Keep the line.
How volume becomes an ethics issue
A hundred careful notes are not the same as ten thousand notes nobody reads. If the volume makes the human loop fake, the volume is the problem. We cut volume. We do not hire a person only to click yes.
How speed becomes an ethics issue
A deadline is not a reason to skip the sitting. If the date cannot move, the scope can. A smaller live path with a review beats a large live path without one.
How money becomes an ethics issue
A fee does not buy a yes. A larger fee does not buy a weaker stop. A $250 audit does not buy outbound. A retainer does not buy a lie.
If a client offers more money to skip the sitting, that offer is itself a reason to slow down.
How pride becomes an ethics issue
We will be wrong. A sample will be cruel. A rank will copy an old bias. The ethical move is to pause and fix, not to defend the cleverness of the draft.
A person who cannot stand being wrong should not operate the queue.
How we treat humour
A joke in a private room can still be a send. If it would look ugly on the front of a newspaper, it does not go. We do not need a humour policy. We need that test.
How we treat religion, ethnicity, and politics in lists
We do not build a ranker whose job is to punish a faith, an ethnicity, or a party. If a client asks for that, we say no. If a public list happens to include those facts because a person put them on a public profile, we still do not use them as a weapon.
How we treat health data
If a job needs health data, the SOW must say so before a source is connected. Health data is not a fun extra column. We do not infer a condition from a joke in a profile. We do not send medical advice.
How we treat location data
A city on a public profile is not a home address. We do not pretend we know where a person sleeps. We do not threaten to visit. We do not publish a map of private homes.
How we treat images
A public photo on a profile is not ours to put in an ad. A generated image that looks like a real private person is a no. A chart in a report is fine if the numbers are real.
How we treat recordings of meetings
No recording unless the SOW or the room agrees. A hidden recording is a review fail even if the content is dull.
How we treat translation
A translation can change a meaning. A human who knows the language should see a high-risk send. We do not treat a machine translation as a legal opinion.
How we treat internal jokes about clients
We do not put them in a ticket that the client can one day read. We do not put them in a prompt. We do not put them in a sample. Respect is cheaper than a cleanup.
How we treat a person who wants to be forgotten
If they write, we stop the send to them. We delete what the law and the SOW allow us to delete. We keep what the law says keep. We do not keep them on a revenge list.
How we treat a person who was contacted by mistake
Pause. Apologise. Remove. Write the record. Do not argue that a public profile made it fair if the SOW did not cover them.
How we treat a person who replies with distress
Stop the cadence. A human reads. We do not auto-send a cheerful second note. We do not treat distress as an objection that needs a pitch.
How we treat a person who threatens us
Pause the path that touches them. Write the record. Counsel if needed. We do not escalate a fight in the same channel the system uses for work.
How operators escalate
They pause first. They write what they saw. They send it to info@penwerem.com or the named internal channel. They do not wait for a weekly meeting if the send is live.
How the director uses the review function
The director signs until extra members sit. That is a concentration of power. It is also honest. When extra members sit, they can refuse the director. That is the point of extra members. We will write that day when it comes. We will not pretend it has come.
How a public-sector board can sit with us
They can send their questions. They can ask for samples. They can ask for the stop to be shown. They can require their own second look. They cannot require us to hide the stop. They cannot require us to train a public model on citizen files.
How a bank model-risk team can sit with us
They can treat this page as the model-risk note for our systems. They can ask which tools draft. They can ask who can change a prompt. They can ask how we pin a version. They should not expect a university paper. They should expect a sitting and a record.
How we pin a version without theatre
We keep the prompt and the template that went live. We keep the date. We keep who said yes. If a tool vendor changes under us, we note that we do not control their weights. That note is part of the honesty. It is not a shrug. It is a reason to keep the human loop.
How we treat evaluation sets
If we build a small set of sample people to test a ranker, those people should be fake or fully consented. We do not test on a live ministry list for fun.
How we treat red teaming
A person may try to make the system say a forbidden thing. That is useful. It is not a licence to attack the live site. Internal tests stay internal. External researchers write first.
How this page treats the word model
A model drafts. A model ranks. A model does not become the company. We do not sell a model name to a prospect. We sell work and access. The review is about the work.
Last pass
If you only remember five lines, remember these.
A human signs off. A human can stop it. Your brief is not public training data. A $250 audit does not start outbound. Write info@penwerem.com if we caused harm.
The URL can keep the old path. The title stays about review.
A last note for the person who will sit in the review
Bring the samples. Bring the origin of the list. Bring the stop. Leave the slogan at the door. If you cannot show those three, you are not ready to say yes. If you can show them and the harm is still too large, say no. The company will live. A bad send is harder to live with.
Write the decision the same day. Do not trust memory. Do not trust a chat that will scroll away. The record is how the next person knows what you actually approved.
If extra members join you later, hand them this page and the last three records. That is onboarding. That is enough.
If you cannot write the decision the same day, the sitting did not finish. Finish it or keep the path off. A delayed yes is a silent yes. We do not want those.
One page you can hand to a risk committee tonight
High-risk work needs a sitting. The sitting needs samples, list origin, and a stop. The director signs until extra members sit. Client briefs are not public training data. Outbound from a $250 audit is off. The accepted success metrics are a positive reply, an invite accepted, or a new connection. Distress stops the cadence. A threat, a bribe, a fake letter, and a cloned official voice are refusals. Write info@penwerem.com if a live path we run caused harm.