Responsible-AI Framework.
PCI’s overall approach to using AI responsibly — for the profession and for itself.
Overview
This framework ties PCI’s AI policies together into one coherent approach. It defines the principles, the human-oversight requirement, and how responsible AI is taught, assessed and applied — so the credential and the institute practise what they certify.
At a glance
What the framework brings together
- The principles of the AI ethics standard
- The human-oversight requirement
- Data quality, confidentiality and explainability
- Application within the credential and PCI’s operations
Practising what we certify
PCI applies this consistently and documents what it does, so the approach can be checked and improved. Final detail is published as the institute matures, and is governed by the related policies below.
What the framework brings together
This framework ties PCI’s AI policies into one coherent approach — for the professionals it certifies, and for PCI itself.
Govern, don’t defer
AI proposes, the professional disposes — the principle behind it all.
One coherent approach
A single framework that connects PCI’s AI policies.
Assessed, not assumed
AI governance is examined as a competency in its own right.
Practising what we certify
PCI holds itself to the same standard it asks of others.
Common questions
Is this just about the exam?
No — it governs PCI’s own use of AI as well as what the credential teaches.
What is the core principle?
AI proposes; the professional disposes. AI can generate a schedule, a forecast or an analysis, but a competent human must validate it, explain it, and take responsibility for the decision. That principle runs through the whole standard, and it is ultimately what the credential protects: judgement and accountability staying with a qualified professional.
How is it kept current?
Through recertification’s AI-currency element and continuous improvement.
Why this matters
This matters because a credential earns its value from substance, not marketing — clear standards, fair process, transparent governance and honesty about status. Everything here is written to that test: useful to professionals and employers, and never claiming more than is true today.
PCI builds in the open. That means being candid about what is in place and what is still developing, designing around the ISO/IEC 17024 personnel-certification principles, and never implying recognition it does not yet hold. That honesty is part of how trust is earned.
- Substance over marketing
- Fair, transparent process
- Honesty about our status
- Responsible, governed use of AI
Founding-stage document · Version 1.0 — effective date to be confirmed · Reviewed under PCI governance. PCI makes no claims of accreditation or recognition beyond what is true today.
One framework, four layers
The framework is easiest to understand as four layers, each answering a different question — from why, down to how, and who checks:
Principles
The non-negotiables that everything else serves: transparency about when AI is used, accountability that stays with people, and human primacy in judgement — AI proposes, the professional disposes.
Practitioner standard
What responsible AI use looks like in real controls work — verification of outputs, disclosure of material AI use, and never presenting machine output as unexamined professional judgement.
Institutional policies
The rules PCI applies to its own use of AI — including the commitment that significant decisions about people are made by humans, not delegated to models.
Oversight and assurance
The checking layer: defined human review points, escalation routes when AI output is doubted, and periodic review so the framework improves as tools and risks change.
Taught, assessed and practised
What makes this framework unusual for a certification body is that it points in both directions. Outward, it is taught — governed AI is a domain of the body of knowledge, not an appendix — and assessed, with candidates examined on judgement about AI-assisted work: when to trust it, how to verify it, and who remains accountable. Inward, it is practised: PCI holds its own operations to the same rules it certifies, so decisions that significantly affect a candidate — eligibility, results, certification, sanctions — are made by people, with AI confined to assistive roles under the AI decision-making policy and the human oversight policy. An institute that certified governed AI while running ungoverned AI would fail its own examination; the framework exists so that can never be the arrangement.
What the framework does and does not do
Does the framework restrict professionals from using AI?
No — it governs use rather than discouraging it. PCI's position is that AI is now part of the discipline, and that avoiding it is as much a professional failing as using it carelessly. The framework's demands are about how: verify outputs, disclose material use, and keep accountability with the professional who signs the work.
Does PCI use AI to mark exams or decide certifications?
Decisions that significantly affect a candidate are made by people. AI may play assistive roles in operations, but it does not decide eligibility, award certification or impose sanctions, and any AI-assisted step feeding such a decision sits under defined human oversight. That commitment is written into policy rather than left to practice.