AI Ethics Standard.
AI can support project controls — but a competent professional stays accountable. PCI’s guiding principle: AI proposes; the professional disposes.
Overview
Project controls increasingly uses AI to forecast, analyse and report. That can be powerful and dangerous in equal measure: AI can be confidently wrong. This standard defines how AI should be used responsibly — within the profession PCI certifies, and within PCI's own operations.
At a glance
The five principles
- Human accountability — a competent professional owns every consequential AI-assisted output
- Data quality — outputs are only as good as the data and assumptions behind them
- Confidentiality — sensitive project and personal data is protected when using AI tools
- Explainability — professionals must understand and be able to justify AI-assisted conclusions
- Fairness — bias in data and models is actively considered and mitigated
Human accountability in practice
AI may draft a forecast, flag a risk, or summarise a dashboard — but it does not remove responsibility. Outputs must be validated, interpreted and owned by a competent person before they inform a decision. Unverified AI output is never treated as fact. This is the heart of human oversight.
AI proposes. The professional disposes.
Automation can accelerate the work, but judgement, accountability and integrity stay human. That is the line PCI draws — and certifies against.
Common questions
Is it acceptable to use AI in project controls?
Yes — responsibly. AI can support analysis and reporting, provided a competent professional validates and owns the output.
Can AI make a certification decision?
No — certification decisions are made by people, under the principle that AI proposes and the professional disposes. AI may support parts of a process, but the judgement about whether a candidate has met the standard rests with the certification body and its competent assessors, never with an automated system alone.
What is the biggest AI risk?
Trusting a confident output without checking the data, assumptions and project context behind it.
Founding-stage document · Version 1.0 — effective date to be confirmed · Reviewed under PCI governance. PCI makes no claims of accreditation or recognition beyond what is true today.
A working routine for AI-assisted outputs
The standard becomes real in small, repeatable habits. Before any AI-assisted forecast, analysis or report informs a decision, a competent professional should be able to answer four questions about it — quickly, and in writing where the decision is consequential.
1. State the question
Record exactly what the tool was asked to do and what data it was given. Vague prompts produce plausible answers to the wrong question, and nobody notices until the number is challenged.
2. Check the basis
Trace the data sources, assumptions and cut-off date behind the output. If the basis cannot be stated, the output is not analysis — it is a guess with good formatting.
3. Validate independently
Test the result against the schedule, the cost baseline and a simple manual cross-check. Agreement with your expectations is not validation; agreement with the evidence is.
4. Record and own
Note where AI assisted the work, what was verified and who approved the result. The signature on the output belongs to a person, never to a tool.
Where responsible use breaks down
Most breaches of this standard are not malicious — they are drift. Four patterns account for most of the damage:
- Automation bias — accepting a confident output because checking feels redundant. The better the tool usually is, the stronger this pull becomes.
- Confidentiality leakage — pasting commercially sensitive schedules, rates or personal data into tools that carry no duty to protect them.
- Stale or unrepresentative data — a model trained on projects unlike yours will be fluently wrong about yours.
- Unexplainable conclusions — presenting an output you cannot walk a decision-maker through. If you cannot explain it, you cannot own it.
These are exactly the risks that human oversight exists to close, and naming them is the first defence against them.
How this standard is examined and enforced
Governed AI is not an appendix to the PCI certifications — it is a weighted domain of the Body of Knowledge, assessed alongside planning, cost and risk. Candidates are examined on judgement: when to use AI, how to validate what it produces, and where accountability sits. The obligation does not end at certification. Certified professionals carry these duties into daily practice under the professional conduct requirements, and a confirmed failure to apply them — signing off unverified output, exposing confidential data, presenting machine output as independent analysis — is treated as a conduct matter, not a technical slip.