GOVERNANCE

AI Governance

The principles governing the use of artificial intelligence at Mr Suricate, how we assess the risks involved, and the controls we implement.

SMSI Compliant with ISO/IEC 27001·Hosting in the European Union·GDPR-compliant
Informational document; not legally binding

1Purpose

This AI Governance Statement describes the principles, commitments, and governance mechanisms implemented by MR SURICATE the use of artificial intelligence (AI) technologies within its SaaS platform. 

This document is for informational purposes only and does not constitute a standalone contractual commitment. Applicable commitments are defined in the Contract, the DPA, and the SLA. 

 

Scope of AI Features

The AI technologies integrated into the MR SURICATE platform MR SURICATE be used in: 

  • Assistance in Test Scenario Creation 
  • Script Optimization Suggestions 
  • Technical Anomaly Detection 
  • Automated Results Analysis 
  • Technical Documentation Assistance 
  • Agent Orchestration 

AI functionalities are designed as assistive tools. They do not supersede human intervention or user validation. 

 

Guiding Principles

MR SURICATE to design AI mechanisms that are robust and resilient in order to minimize operational errors or unexpected behavior. MR SURICATE the following principles:

Human Oversight

Operational decisions remain under user control. 

AI-generated suggestions require human validation.

Proportionality

The utilization of AI mechanisms is proportionate to the technical objective of the service.

Transparency

MR SURICATE to document: 

  • The use cases of AI functionalities 
  • Their known limitations 
  • Best practices for use

Security

AI components comply with the security standards applicable to the platform: 

  • Hosting in a secure environment 
  • Strict access controls 
  • Logging of administrative actions
  • Logical segmentation of environments 

Data Protection

The use of AI mechanisms complies with GDPR requirements. 

MR SURICATE to limit the exposure of personal data whenever possible, in particular by prioritizing: 

  • Technical data 
  • Pseudonymized data 
  • Adapted test environments

2Risk Management

Risks associated with AI technologies are integrated into the ISMS risk analysis. These risks may include: 

  • Reliability of suggestions 
  • Interpretation errors 
  • Potential biases 
  • Dependencies on third-party providers 

Identified risks are monitored as part of continuous improvement. 

When appropriate, MR SURICATE analyze the results of AI systems to identify any technical biases or unexpected behavior.

3. AI Risk Classification(AI Act Alignment)

MR SURICATE its AI use cases in light of the European Artificial Intelligence Act (AI Act). 

Nature of Systems

The AI features are intended to provide technical support in the field of automated testing. 
They do not make legal or automated decisions that directly affect individuals.

Risk Category

Given their current purpose, the AI systems deployed by MR SURICATE considered to fall under: 
AI systems with limited risk 
or 
Technical assistance tools that do not constitute high-risk systems as defined by the AI Act.

Absence of High-Risk Use Cases

AI functionalities are not used for: 

  • Evaluation of natural persons 
  • Behavioral scoring 
  • Automated decision-making with legal effect 
  • Biometrics 
  • Large-scale surveillance 

Consequently, they do not fall under the categories of high-risk AI.

Regulatory Monitoring

MR SURICATE continuously MR SURICATE regulatory developments in order to adapt its governance mechanisms in the event of functional or regulatory changes.

 

Model & Data Lifecycle Governance

MR SURICATE governance principles that cover the entire lifecycle of AI components and associated data. 

Model Selection and Integration

AI models can be: 

  • Developed internally 
  • Provided by third-party technology partners 

Prior to integration, an evaluation is conducted focusing on: 

  • Security guarantees 
  • Contractual commitments 
  • Data Protection Mechanisms 
  • Applicable Regulatory Compliance 

Execution Environments

AI components are executed within secure environments that adhere to: 

  • Platform Security Standards 
  • Strict Access Controls 
  • Logging Mechanisms 
  • Logical Isolation Requirements

Data Governance

MR SURICATE that: 

  • Limiting the use of personal data 
  • Prioritizing technical or anonymized data 
  • Applying the same security rules as for the entire system 
  • Data is not used for external training without an appropriate legal basis. 

Customer data utilized within the platform is not used to train public or third-party artificial intelligence models without explicit contractual agreement. 

Logging and Traceability

Administrative actions related to AI functionalities are logged in accordance with the platform's logging policy. 

Traceability aims to: 

  • Identify accesses 
  • Identify the changes 
  • Enable analysis in case of an incident

Version and Change Management

Evolutions of AI mechanisms are: 

  • Tested prior to deployment 
  • Documented 
  • Integrated into the change management process 
  • Updates are implemented as part of continuous improvement.

Performance Monitoring

MR SURICATE monitor: 

  • The relevance of suggestions 
  • Technical anomalies 
  • User feedback 

This monitoring aims for continuous improvement and does not constitute a guarantee of absolute accuracy.

Third-Party Dependency Management

When third-party services are utilized: 

  • Providers are evaluated 
  • Contractual commitments are structured 
  • Data transfers comply with regulatory requirements 

4Regulatory Compliance

MR SURICATE changes in the applicable regulatory frameworks, including: 

  • Regulation (EU) 2016/679 (GDPR) 
  • European Regulation on Artificial Intelligence (AI Act) 
  • Best practices for responsible AI 

Current AI mechanisms are designed as technical assistance tools and do not constitute high-risk AI systems. 

 

Responsibility

AI features are provided on a best-efforts basis. 
MR SURICATE guarantee either the absolute accuracy or the absence of errors in the generated suggestions. The user remains responsible for validating the actions taken.

5. Continuous Improvement

The governance of AI mechanisms is monitored as part of MR SURICATE WSIS framework MR SURICATE may be subject to periodic security and compliance reviews. 

The described measures are subject to evolution as part of: 

  • Continuous improvement 
  • Technological evolution 
  • Regulatory Adaptation 

Subject to the maintenance of an equivalent level of security and compliance.

 

Contact

For any questions regarding AI governance: suricate@mrsuricate.com 

A question about our safety?

The security team responds to inquiries from clients and prospects, including security questionnaires and due diligence requests.