• Nederlands

Challenge

We have to meet new requirements

New frameworks around data and AI keep arriving, and they touch systems that have been running for years. The question is rarely whether you comply, but whether you can show it.

See the solution →
Tall stack of checklist sheets next to a laptop

The situation

The requirement is not the problem, demonstrating it is

Most organisations already do a lot right. Thought has gone into access, into retention periods, into who may see which data. What is missing is the record: the moment someone asks how a decision came about, which data went into it and who signed off, the searching begins.

This sharpens as more becomes automated. A person, too, cannot always recount afterwards which information they used, but with a system it is reconstructable, provided the system was designed for it. Without recorded data and model versions only approximation remains, and that rarely holds up in an audit.

Why it reaches the agenda late

Because it looks like a legal topic for a long time. It gets assigned to the lawyer or the compliance officer, while the answers sit in the systems and therefore with the people who build them. Those two groups usually only meet when a deadline or an audit comes into view.

The second reason is that it produces nothing you can show. There is no new functionality, only the assurance that something will not go wrong later, and that loses against almost any other project, until the moment it does go wrong.

What we do and do not do

Twentynext does not give legal advice and does not determine which frameworks apply to your organisation. That belongs with your legal or compliance function. What we do is the technical side: making sure the questions they ask can actually be answered from your systems.

How this plays out in government and non-profit is on the sector page.

What helps

Four questions you can ask yourself

Which requirements apply exactly differs per sector, per type of data and per role a system plays: your legal function determines that, not us. The four questions below are not a summary of the rules but a first technical inventory. If the answer to all four is “we don’t know”, you know where to start.

Do you know which data sits where?

Not broadly, but specifically: which personal data sits in which system, how did it get there and how long does it stay. Without that overview no further question can be answered.

Can you reconstruct a decision?

If a system produced an outcome last quarter, can you show which data and which version of the model it rested on?

Is someone accountable?

Per system, by name. Shared responsibility between IT and the business often means in practice that nobody has the overview at the moment it is needed.

Where does a human intervene?

For which automated outcomes does a person review, and does that person have the knowledge and the authority to overrule it? Reviewing without a mandate does not count. It is also rarely written down anywhere.

Further reading

Where this is set out in more detail

Challenge

Our data is not trusted

Origin and ownership are the same foundation here. Anyone who has that in order can answer most of the questions above.

Read the challenge

Solution

Data architecture

Where definitions, lineage and ownership are recorded: the layer every question about accountability falls back on.

See the solution

Service

Consultancy

Working out what needs to happen, in what order, including which of the four questions above is most urgent for you.

See the service

Work with us

Realise your project together?

The people who build it also run it afterwards. Eindhoven, since 2014.

Martijn van Grieken

Martijn van Grieken

Director Data & AI

Get in touch