Responsible AI Principles

A risk-based approach to AI projects

Last updated:

These principles describe the approach Meru Software aims to apply when designing or integrating AI systems. They are not a certification or a guarantee that every project has identical requirements. Project-specific commitments are defined by the agreed scope, applicable law, deployment context and written client agreement.

1. Purpose and Transparency

We aim to document the intended use of an AI feature, its material limitations, relevant third-party model providers and the role of human review at a level appropriate to the project.

2. Human Oversight

For use cases that may materially affect people, we recommend meaningful human review and work with the client to define which decisions require review, escalation or an alternative non-automated route.

3. Quality, Fairness and Limitations

Where included in scope, we evaluate outputs against agreed criteria, examine relevant bias and quality risks, and document known limitations. Evaluation methods depend on the use case, available data and potential impact.

4. Data Privacy

Privacy requirements are assessed for the specific use case, data, model provider, deployment and contractual roles. Personal-data processing must be addressed in the applicable privacy notice, client agreement and data-processing terms rather than assumed to be covered by a general compliance claim.

5. Security and Reliability

Security testing, access controls, monitoring, fallback behaviour and incident handling are selected according to the system's risks and agreed project scope. AI output should be treated according to its intended use and verified before high-impact action.

6. Accountability

Project documentation should identify responsibilities for development, deployment, operation, review and use. Concerns or incidents should have a defined reporting and escalation path appropriate to the engagement.

7. Ongoing Review

AI systems and providers change over time. Where ongoing operation is included in scope, review activities may include monitoring agreed quality measures, reassessing risks after material changes and updating controls or documentation.

Questions about these principles can be sent to info@merusoftware.com.