How Conrad works

The full advisory process behind every briefing.

This page sets out, in full, what the homepage summarises: the ten-step methodology, the source-authority hierarchy, how confidence is scored, the eight controls applied to every response, and where Conrad's advisory scope begins and ends.

Methodology

A disciplined advisory process behind every answer.

Each step adds a control: intake defines scope, discovery grounds the evidence, ranking filters by authority, analysis separates known from inferred, and review validates the output before delivery. No step is optional. The same process applies to every question.

01

Question intake

You submit one AI governance question. Conrad works out the question type first, whether it's board oversight, policy, risk management, vendor governance, responsible AI, compliance readiness, operating model, or implementation planning, before any analysis begins.

02

Scope classification

The question gets checked against advisory boundaries. If it's asking for legal, financial, cybersecurity incident-response, medical, tax, employment, or certified compliance advice, the response is limited or redirected. This scope check happens first, not after the analysis is already done.

03

Context assessment

Conrad works out whether there's enough context to answer safely. When something material is missing, like organisation size, sector, jurisdiction, or risk profile, the briefing either states the assumptions it's making or asks you to clarify before going further.

04

Evidence discovery

The system maps the question to relevant governance resources: standards bodies, regulator guidance, government publications, professional-body material, and curated internal reference material. None of this comes from general model memory.

05

Source ranking

Evidence gets ranked by authority before it's used. Primary sources like legislation, official standards, and regulator positions are prioritised over commentary. News and opinion only add situational awareness, and that use is declared in the briefing.

06

Framework mapping

The issue is mapped against governance concepts: accountability, transparency, risk classification, human oversight, data governance, monitoring, vendor assurance, auditability, incident management, and board reporting. The mapping is shown in the output.

07

Risk analysis

Conrad identifies governance risks, likely control gaps, stakeholder impacts, and key decision points. It separates what the evidence supports directly, what has been inferred, and what requires validation by the organisation or a specialist.

08

Answer construction

The response is structured into a standard executive format: direct answer, evidence basis, analysis, recommended actions, implementation considerations, governance risks, limitations, confidence level, sources, and suggested next question.

09

Control checks

The draft is assessed for hallucination risk, unsupported statements, professional-boundary violations, stale source material, missing assumptions, and unsafe recommendations. Controls are applied to the output, not just the process.

10

Human review and delivery

During the pilot, a human operator reviews the briefing against the methodology before the final structured response is delivered by email. The reviewer can reject a briefing, request re-analysis, or add caveats before delivery.

Evidence standard

Not all sources carry the same weight.

Every claim in a Conrad briefing traces to a ranked source. Primary material is prioritised over commentary or market opinion. The ranking is applied before the advice is constructed, not as an afterthought, and the tier is declared in the output so the client can assess the basis themselves.

Tier 1

Law, regulation, and official standards

Legislation, regulatory instruments, official standards bodies, court decisions, regulator publications, ISO, NIST, and equivalent authoritative material. This tier governs any analysis where primary authority exists. It is always preferred over lower tiers when available.

Tier 2

Government and regulator guidance

Government agencies, public-sector AI guidance, regulator consultation papers, official policy documents, and recognised safety frameworks. Carries high authority but is subordinate to enacted legislation and approved standards.

Tier 3

Professional and institutional guidance

Governance institutes, professional bodies, assurance organisations, audit bodies, and recognised sector authorities. Used where Tier 1 and Tier 2 material is absent or silent, and where the body has recognised standing in the domain.

Tier 4

Research and advisory material

Academic research, consulting reports, industry analysis, and implementation guides. Used where primary material is incomplete, emerging, or unavailable. Always declared when used as a primary basis and never used to contradict higher-tier material.

Tier 5

News, market signals, and emerging commentary

Used for situational awareness and emerging trend identification only. Never used as the primary basis for formal advice. When referenced, it is explicitly identified as contextual rather than authoritative material.

AI governance standards
AI risk management frameworks
Regulator guidance
Government policy papers
Responsible AI principles
Assurance and audit references
Vendor governance resources
Board oversight materials
Privacy and data governance guidance
Model risk management references
Internal methodology documents
Risk-control checklists
Confidence scoring

Uncertainty is made explicit, not buried.

Confidence is not a label appended to satisfy a checklist. It is a signal derived from ten factors. Where confidence is medium or low, the briefing explains the specific reasons, so the client knows what additional input would change the assessment.

High confidence

Used where authoritative sources align, the question falls clearly within advisory scope, the guidance is stable and settled, and the user has provided sufficient context for the analysis to be applied directly.

Medium confidence

Used where the direction is clear but implementation depends on organisational details, sector context, jurisdiction, maturity level, or risk appetite that the user has not provided. The answer is directionally sound; the application requires judgment.

Low confidence

Used where the topic is emerging, authoritative sources conflict, the question is too broad for a specific answer, context is insufficient, or regulated professional advice may be required before any action is taken.

Factors assessed in every confidence determination
  • Source authority
  • Source recency
  • Reference consistency
  • Topic maturity
  • Jurisdiction clarity
  • User context quality
  • Implementation dependency
  • Professional-advice risk
  • Inference reliance
  • Evidence directness
Application governance

Governance applied to the service that provides governance advice.

Eight controls are embedded in the advisory process. Each exists because uncontrolled AI advice has a specific failure mode that the control prevents. These are application design decisions, not marketing language.

01

Source control

Advice is grounded in an approved source hierarchy. General model memory is not used as the evidential basis for a claim. Sources are declared in the output.

02

Scope control

Every question is assessed against defined in-scope and out-of-scope categories before analysis begins. Questions that require regulated professional advice are redirected, not answered.

03

Prompt-injection resistance

User-provided text and external source material are treated as untrusted inputs until assessed. The system does not allow user context to override advisory boundaries or source discipline.

04

Unsupported-claim control

Material claims are assessed against the evidence before the briefing is finalised. Claims without adequate source support are flagged, qualified, or removed.

05

Professional boundary control

Conrad does not present regulated professional advice as a final organisational position. Where a question approaches a professional boundary, the briefing identifies the boundary and recommends specialist advice.

06

Confidence control

Every response includes a confidence assessment derived from ten factors. Uncertainty is made explicit, not suppressed. Where confidence is medium or low, the briefing explains the specific reasons.

07

Human review control

Pilot responses are reviewed by a human operator before delivery. The reviewer can reject, revise, or add caveats. No briefing is delivered without a review sign-off during the pilot phase.

08

Auditability control

The intended future state records source discovery, evidence approval, prompts used, reviewer decisions, output versioning, and delivery history, so the basis for any briefing can be reconstructed later.

Advisory boundaries

Scope discipline is a governance control, not a disclaimer.

Conrad's scope is defined by where general AI governance guidance ends and where regulated professional advice begins. Scope is assessed before every briefing. Where a question approaches the boundary, the briefing identifies it and recommends qualified professional input.

In scope

  • AI governance frameworks
  • Responsible AI principles
  • AI risk identification
  • Board AI oversight questions
  • Policy and control design
  • Vendor AI governance
  • AI adoption planning
  • Data governance awareness
  • Emerging AI regulation
  • Framework mapping
  • Control gap analysis
  • Implementation planning

Out of scope

  • Legal advice
  • Tax advice
  • Financial advice
  • Medical advice
  • Employment law
  • Cybersecurity incidents
  • Certified compliance opinions
  • Privacy audit opinions
  • Regulated professional sign-off
  • Confidential client matters
  • Due diligence certifications
  • Actuarial or valuation advice
Submit a question