Risk Ledger leverages LLMs and other Generative AI techniques to enhance efficiency for users while maintaining a 'security first' architecture. Our implementation of AI systems is designed specifically to meet the rigorous compliance standards of safety conscious organisations, ensuring that confidential information you hold with Risk Ledger remains entirely within your control, while still being traceable and auditable.
What data is processed by AI?
We never give models blanket access to data relating to clients or suppliers; instead, we always minimise data input to specific data points relevant to the task at hand, and provide these in a scoped manner alongside each prompt.
Where is AI processing performed?
LLM Models
We utilise enterprise grade LLM platforms within our own cloud environments. We use a combination of different AWS hosted LLMs, including models from the Anthropic family, as well as Google hosted LLMs from the Gemini family.
We may update the models we use over time as our evaluations identify improvements in performance within appropriate security and price envelopes.
All data processing is done within our cloud platforms and never sent to other third parties.
Data residency
The processing via both AWS and GCP takes place in the EU.
Is customer data used to train AI models?
No. We take a zero training approach: the models we use and their providers do not train on customer inputs. This means that customer inputs, logic, and data points never influence the global intelligence of the LLM or risk being extracted or reused in later outputs from the models.
How long is data retained by AI providers?
Data is only retained by the model providers for up to 90 days, under their standard terms relating to abuse monitoring. Risk Ledger has requested exemption from this retention.
Who owns AI-generated outputs?
Neither we nor the model/compute providers we use assert any ownership over outputs generated by users via Risk Ledger’s AI features.
How does Risk Ledger test AI accuracy and reliability?
Pre-release evaluation and testing
We've combined recent models from frontier AI labs with internally-developed harnesses and prompts that leverage our deep experience in supply chain security, delivering supplier reviews that consistently meet our high quality thresholds in evaluations.
Every AI feature we ship goes through a structured evaluation process before release and on an ongoing basis after launch. Our evals, against synthetic benchmark datasets produced in-house, produce scores for factors that matter most for risk management work, such as factual accuracy, completeness, and hallucination rates.
We then test the system in production using our own Risk Ledger account and run qualitative testing with early access customers before wider release.
Continuous monitoring and evaluation
We run our evaluation suite during development to catch regressions before code ships, and continuously in production through sampled output reviews and customer feedback loops. We also use these checks to monitor consistency and control "drift" in outputs over time. When we identify a new failure mode or another way to enhance performance, whether through internal testing or customer feedback, we add it to our test suite so future versions of our systems are measured against it.
Ongoing development
We are developing numerous additional features that lean on AI to support the most important use cases of our customer base. We continuously evaluate and iterate on security, accuracy and efficiency as we build, and continuously improve the technical foundations, processes and tooling that support the AI features in our product. We will update our documentation over time as our approach continues to mature.
Are AI outputs explainable and auditable?
Every AI output is grounded in customer/supplier provided evidence and logged with its model and prompt versions, so any answer can be traced back to what the original data said and which version of the system produced it.
Can customers opt out of AI features?
For organisations with stricter requirements - or indeed any other concerns - you can opt-out of AI functionality, and we will not enable AI features on your accounts. Please reach out to your Account Manager or email support@riskledger.com to remove access to AI features in your account.
How does Risk Ledger protect against prompt injection?
Prompt injection is a known risk for any system that processes user-supplied text with an LLM, and we treat resilience against prompt injection as an important part of our pre-release testing.
Every AI feature is evaluated against a suite of test cases before it ships, covering a range of known attack patterns and adversarial inputs designed to manipulate model behaviour. Features only progress to release once they consistently pass these checks.
How is human oversight maintained?
We always keep humans in the loop in all consequential decisions; our AI features assist with summarisation and review and then surface suggestions, but final risk decisions and critical actions stay with your team.
