Public Sector Service

Responsible AI in Government with Practical Oversight and Control

4.9 out of 5 from 6,842 reviews

DataConsultant helps government organisations assess, design, implement and operate responsible AI controls across public services, internal operations and policy delivery. We connect accountability, impact assessment, data governance, transparency, human oversight, procurement and assurance so that AI adoption can progress with clearer evidence, decision rights and risk management.

  • Public-sector accountability mapped to AI decisions
  • Risk-based assessments and documented controls
  • Vendor-neutral governance and assurance guidance
  • Knowledge transfer for policy, delivery and oversight teams
Direct answer

What is Responsible AI in Government Service?

Responsible AI in Government Service is a structured advisory, governance, assurance and implementation service for public bodies that use or plan to use artificial intelligence. It helps accountable officials, policy teams, digital leaders, data teams, risk functions and procurement teams define where AI may be used, what evidence is required, who can approve it, how affected people are protected and how performance is monitored.

The work commonly produces an AI inventory, risk classification, impact-assessment process, accountability model, control library, procurement requirements, assurance plan and implementation roadmap. Its effectiveness depends on access to system evidence, decision-makers, legal and policy interpretation, suppliers and operational teams. It supports governance and delivery decisions but does not replace authorised legal advice, statutory audit or specialist security testing.

Service offering

From AI policy to operational assurance

The service can be configured around a single high-impact system, a departmental portfolio or an enterprise-wide responsible AI programme.

01

Assess and prioritise

Establish the AI inventory, intended public purpose, affected groups, system dependencies, risk tiers and evidence gaps.

  • Inputs: use-case records, contracts, data flows, model information and policies
  • Outputs: risk register, assessment findings and prioritised actions
  • Client role: provide evidence and accountable stakeholder access
02

Design governance and controls

Define decision rights, impact assessment, approval gates, transparency, human oversight, redress, monitoring and supplier obligations.

  • Inputs: legal duties, operating model, service standards and risk appetite
  • Outputs: governance model, control library, templates and policy standards
  • Client role: approve roles, tolerances and escalation routes
03

Implement and sustain

Mobilise controls, support assessments, establish reporting, train teams and transition responsible AI into routine governance.

  • Inputs: prioritised roadmap, delivery capacity and system access
  • Outputs: implemented workflow, evidence packs, dashboards and training
  • Client role: assign owners and operate approved controls
Value propositions

Practical value for public-sector decision-makers

A

Clear accountability

Assign named ownership for policy, system approval, data, operational use, monitoring and escalation so responsibility does not become fragmented.

B

Proportionate control

Apply stronger evidence and review requirements to higher-impact systems rather than treating every AI tool as equally risky.

C

Better procurement evidence

Translate responsible AI expectations into supplier questions, contract requirements, acceptance criteria and ongoing assurance obligations.

D

Transparent public service

Design notices, explanation routes, record keeping and redress processes appropriate to how AI affects people and public decisions.

E

More reliable oversight

Create repeatable assessment, approval, monitoring and issue-management workflows supported by documented evidence.

F

Internal capability

Equip policy, digital, procurement, risk and operational teams to make informed decisions without permanent dependence on external advisers.

Problems addressed

Where government AI programmes commonly lose control

Responsible AI issues usually arise from unclear ownership, incomplete evidence and disconnected policy, technical and operational decisions.

Unregistered and shadow AI

Teams may adopt embedded or generative AI without a reliable inventory. This limits oversight, supplier management and incident response. We establish registration criteria and ownership, subject to departments disclosing systems and contracts.

Unclear accountability for decisions

Responsibility can be split between policy owners, vendors, data teams and frontline staff. We map decision rights, approval authority, human intervention and escalation while recognising that statutory accountability remains with authorised public bodies.

Weak impact and fairness evidence

Performance testing alone may not show who is disadvantaged or how errors affect access to public services. We design impact assessment and subgroup evaluation requirements, dependent on lawful access to representative data and domain expertise.

Opaque supplier solutions

Government buyers may receive limited information about model changes, training data, testing or subcontractors. We define procurement questions, minimum evidence, change notification and audit rights, although supplier cooperation and contract leverage remain important.

Insufficient monitoring after launch

Models and service conditions change over time. We define operational metrics, drift and incident triggers, review frequency, records and retirement criteria. Effective monitoring depends on telemetry, ownership and capacity to act on findings.

Need to assess an existing or planned government AI system?

Share the public purpose, affected users, technology environment and current evidence for a practical scope discussion.

Request a Consultation
Suitability

Who this service is for

Suitable for public organisations at policy, procurement, pilot, deployment or operational-assurance stages.

Good fit

  • Government departments, agencies, regulators, councils and public bodies
  • AI used in public service delivery, administration, enforcement, forecasting or resource allocation
  • Digital, data, policy, procurement, legal, risk, audit and operational leaders
  • Organisations requiring a common AI inventory and risk-tiering approach
  • Teams preparing AI procurement, pilot approval or production deployment
  • Public bodies able to provide accountable stakeholders and supporting evidence

May not be the right fit

  • A narrow technical test is the only requirement
  • A statutory audit, formal certification or licensed legal opinion is required
  • A specialist penetration test or incident-response engagement is needed
  • The platform vendor must perform proprietary model changes
  • A permanent internal hire is more appropriate for continuous ownership
  • The organisation cannot provide system information, decision-makers or evidence
Use cases

Common responsible AI use cases in government

Public benefits and eligibility

Situation
AI supports triage, document review or case prioritisation.
Scope
Impact assessment, human review, explanation, error handling and redress.
Deliverables
Control design, test requirements and decision records.
Model
Fixed-scope assessment plus implementation support.
KPI
Review coverage, exception handling and issue closure.
Dependency
Access to lawful, representative case data.

Generative AI for civil servants

Situation
Staff use assistants for drafting, search or summarisation.
Scope
Approved-use policy, data handling, verification and monitoring.
Deliverables
Usage standard, risk tiers, training and escalation process.
Model
Policy and enablement project with managed support.
KPI
Approved-tool adoption and policy exceptions.
Dependency
Identity, access and logging capabilities.

AI-enabled regulatory oversight

Situation
Models identify cases, anomalies or inspection priorities.
Scope
Purpose limitation, explainability, contestability and assurance.
Deliverables
Assessment pack, governance gates and monitoring design.
Model
Cross-functional advisory and assurance engagement.
KPI
Assessment completion and reviewed escalations.
Dependency
Clear legal authority and domain validation.

Smart city and public infrastructure

Situation
AI supports transport, safety, maintenance or environmental decisions.
Scope
Data governance, surveillance risk, vendor controls and public transparency.
Deliverables
Control matrix, procurement clauses and community-impact review.
Model
Programme advisory with stage-gate assurance.
KPI
Control adoption and unresolved high-risk findings.
Dependency
Cross-agency ownership and data-sharing agreements.

AI procurement assurance

Situation
A department is buying an AI-enabled product or service.
Scope
Requirements, evidence requests, evaluation criteria and contract controls.
Deliverables
RFP language, supplier questionnaire and acceptance plan.
Model
Procurement-stage fixed-scope advisory.
KPI
Material requirements evidenced before award.
Dependency
Early involvement before commercial commitments.

Enterprise AI governance office

Situation
Multiple departments need a consistent operating model.
Scope
Inventory, risk tiers, committees, workflow, reporting and training.
Deliverables
Governance framework, playbooks and implementation roadmap.
Model
Build-operate-transfer or managed governance support.
KPI
Portfolio coverage, review timeliness and issue closure.
Dependency
Executive mandate and departmental participation.
Capabilities

Responsible AI capabilities for public-sector operating environments

AI inventory, classification and accountability

Creates a reliable view of AI systems, owners, purpose, users, suppliers, data and lifecycle status.

Activities: discovery, registration criteria, risk tiering, ownership mapping and governance routing.

Inputs: application portfolios, contracts, architecture records, use-case submissions and organisation charts.

Deliverables: inventory model, classification method, RACI, committee terms and escalation map.

Dependencies: portfolio visibility, senior sponsorship and agreement on what counts as AI.

Impact assessment and control design

Evaluates legal, ethical, operational, data, security and public-service impacts and converts them into proportionate controls.

Activities: affected-party analysis, data review, fairness questions, human-oversight design, transparency and redress mapping.

Inputs: service process, legal basis, data sources, model documentation, testing and user research.

Deliverables: assessment template, completed assessments, control library and acceptance criteria.

Exclusions: formal legal opinions and independent statutory audit unless separately commissioned.

Technical assurance and monitoring

Defines evidence for model quality, robustness, explainability, change control, drift, incident handling and retirement.

Activities: test-plan review, subgroup analysis, traceability, logging, threshold and alert design.

Inputs: model cards, datasets, evaluation results, telemetry and operational procedures.

Deliverables: assurance plan, evidence checklist, monitoring specification and review schedule.

Technology: model registries, MLOps, evaluation tooling, observability and access controls where applicable.

Procurement, supplier and third-party governance

Strengthens responsible AI requirements across sourcing, evaluation, contracting, onboarding and supplier change.

Activities: due diligence, evidence requests, contract-control design, subcontractor review and exit planning.

Inputs: procurement route, draft specifications, vendor proposals and contract standards.

Deliverables: questionnaire, scoring model, clauses, acceptance criteria and assurance calendar.

Dependencies: commercial leverage, supplier transparency and coordination with procurement and legal teams.

Deliverables

Service deliverables

Deliverables are selected according to portfolio size, risk, maturity, jurisdiction and whether the engagement covers assessment, implementation or managed support.

Typical responsible AI in government deliverables
DeliverableWhat it includesFormatStageClient input requiredPrimary owner
AI system inventoryPurpose, owner, users, data, supplier, risk and lifecycle statusRegister and data modelAssessmentPortfolio and contract recordsAI governance lead
Risk-tiering frameworkClassification criteria, thresholds and governance routingMethod and decision treeDesignRisk appetite and policy dutiesRisk and policy owners
AI impact assessmentRights, service, fairness, privacy, security, accessibility and redress reviewTemplate and completed assessmentsAssessmentUse-case and technical evidenceService owner
Accountability modelDecision rights, committees, roles, escalation and approval gatesOperating model and RACIDesignOrganisation structureExecutive sponsor
Responsible AI control libraryPreventive, detective and corrective controls mapped to risk levelsControl matrixDesignExisting control environmentGovernance and assurance
Procurement assurance packSupplier questions, evidence requirements, clauses and acceptance criteriaProcurement toolkitProcurementSourcing strategy and contractsProcurement lead
Monitoring and reporting frameworkMetrics, thresholds, review cadence, incidents and governance reportingKPI catalogue and dashboard designOperateTelemetry and reporting capacityOperational owner
Implementation roadmapPriorities, dependencies, owners, milestones and capability actionsRoadmap and backlogMobilisationResources and delivery constraintsProgramme sponsor
Training and playbooksRole-based guidance for policy, procurement, delivery and oversight teamsWorkshops and reference guidesTransitionAudience and learning needsCapability lead

Define a deliverable set that fits your governance maturity

Scope the minimum evidence and controls needed for your current AI portfolio and public-service obligations.

Request a Consultation
Delivery process

How DataConsultant delivers responsible AI in government

The sequence is adapted to the use case and does not assume a fixed timeline before evidence and stakeholder availability are understood.

Discovery and public-purpose alignment

Objective
Confirm intended outcomes, affected people and decision context.
Client responsibility
Provide sponsors, service owners and core records.
Output
Agreed scope, stakeholder map and evidence request.
Quality control
Purpose and exclusions confirmed in writing.

System and evidence review

Objective
Understand data, models, suppliers, workflow and current controls.
Client responsibility
Enable access to technical and operational teams.
Output
Current-state map and evidence-gap log.
Quality control
Findings traced to supplied evidence.

Risk and impact assessment

Objective
Assess potential impact, obligations and control needs.
Client responsibility
Validate legal, policy and domain context.
Output
Risk tier, assessment and priority findings.
Quality control
Cross-functional review and challenge.

Target governance design

Objective
Define roles, approval gates, controls and evidence.
Client responsibility
Approve decision rights and tolerances.
Output
Operating model, control library and templates.
Quality control
Control-to-risk traceability.

Implementation and assurance

Objective
Embed controls into procurement, delivery and operations.
Client responsibility
Assign owners and implement agreed actions.
Output
Configured workflow, evidence packs and issue log.
Quality control
Acceptance criteria and remediation review.

Transition and continuous oversight

Objective
Build capability and sustain monitoring and review.
Client responsibility
Operate governance and escalate material changes.
Output
Training, reporting cadence and improvement backlog.
Quality control
Ownership and review calendar confirmed.
Technology and frameworks

Platforms, standards and regulatory context

Responsible AI governance should work across the government’s existing technology environment and should not depend on one platform vendor.

Technology environment

Cloud platforms, data warehouses, lakehouses, analytics tools, machine-learning platforms, generative AI services, model registries, MLOps, identity, logging and collaboration systems.

  • Azure
  • AWS
  • Google Cloud
  • Microsoft Fabric
  • Databricks
  • Snowflake
  • Power BI

Governance and assurance tools

AI inventories, data catalogues, model registries, policy workflows, risk systems, privacy tooling, evaluation platforms and observability capabilities can support evidence collection and control operation.

  • Microsoft Purview
  • Collibra
  • Informatica
  • OneTrust
  • MLflow
  • Evaluation tooling

Standards and frameworks

References are selected for the organisation and jurisdiction and may include AI management, risk, privacy, security, data-governance and public-sector requirements.

  • ISO/IEC 42001
  • NIST AI RMF
  • ISO/IEC 23894
  • ISO/IEC 27001
  • ISO/IEC 27701
  • DAMA-DMBOK
  • DPDP Act
  • GDPR
  • EU AI Act
Regulatory review: Applicable law, administrative duties, sector rules, procurement requirements, records obligations and data-residency constraints must be validated by authorised legal, compliance and security specialists.

Align responsible AI controls with your actual technology estate

Review platforms, suppliers, data flows and control evidence without locking governance to a single vendor.

Request a Consultation
Engagement models

Flexible engagement models

Responsible AI engagement options
ModelBest forClient involvementFlexibilityBilling approachMain advantageMain limitation
Fixed-scope assessmentOne system, pilot or procurementFocused evidence and interviewsModerateAgreed project feeClear boundaries and outputsDoes not cover broad implementation
Programme consulting projectDepartmental or enterprise governance designHigh cross-functional participationHigh within governed scopeMilestone or time-and-materialsConnects policy, technology and operationsRequires sustained sponsorship
Dedicated specialist or teamExtended implementation and assuranceShared day-to-day deliveryHighMonthly capacityContinuity and embedded supportClient retains prioritisation responsibility
Managed governance supportOngoing inventory, assessments and reportingNamed accountable owners requiredService-basedMonthly managed feeRepeatable operational supportPublic accountability cannot be outsourced
Build-operate-transferCreating an internal responsible AI functionHigh during transitionPhasedProgramme plus transitionCombines delivery with capability buildingDepends on internal staffing and adoption
Training engagementPolicy, procurement, delivery or oversight teamsAttendance and contextual inputModularWorkshop or programme feeRole-specific capabilityTraining alone does not implement controls
Illustrative examples

How the service may be applied

The following examples are illustrative and do not represent named clients or measured results.

Illustrative example

Department-wide AI inventory

Situation: Multiple teams use analytics, automation and generative AI with inconsistent records.

Scope: Define AI, discover systems, assign owners, classify risk and establish review routing.

Engagement: Fixed-scope discovery followed by governance implementation.

Measurement: Inventory coverage, owner confirmation and assessment backlog.

Limitation: Completeness depends on departmental disclosure and supplier records.

Illustrative example

Assurance for an eligibility model

Situation: A public service plans to use a model to support case prioritisation.

Scope: Impact assessment, data and subgroup review, human decision design, explanation and redress.

Engagement: Independent advisory and stage-gate assurance.

Measurement: Evidence completeness, unresolved findings and review performance.

Limitation: Legal authority and policy decisions remain with the public body.

Illustrative example

Generative AI workforce policy

Situation: Staff are adopting AI assistants across drafting, analysis and knowledge work.

Scope: Approved uses, restricted data, verification, access, logging, training and incident handling.

Engagement: Policy design, enablement and managed review support.

Measurement: Training, approved-tool use, exceptions and reported incidents.

Limitation: Policy effectiveness depends on technical enforcement and management behaviour.

Outcomes and KPIs

Expected outcomes and how to measure them

Outcomes should be expressed as governed capabilities and evidence, not guaranteed service or policy results.

Expected outcomes

  • Clearer ownership and approval for AI use cases
  • More complete visibility of AI systems and suppliers
  • Consistent impact assessment and control expectations
  • Stronger procurement and change-management evidence
  • Better-defined human oversight, explanation and redress
  • Operational monitoring and issue escalation
  • Improved internal capability across policy and delivery teams
Illustrative KPI framework
KPIWhat it indicatesBaseline requiredImportant limitation
AI inventory coverageKnown systems with owner, purpose and status recordedEstimated portfolioUndisclosed shadow tools may remain
Assessment completionRequired reviews completed by risk tierSystems requiring reviewCompletion does not prove control effectiveness
High-risk finding closureMaterial issues resolved or formally acceptedOpen finding registerClosure quality requires validation
Review timelinessGovernance decisions made within agreed service levelsCurrent review cycleSpeed should not reduce scrutiny
Monitoring coverageOperational systems with defined metrics and alertsProduction AI inventoryMetrics depend on available telemetry
Training and role readinessRelevant personnel equipped for assigned responsibilitiesRole and skills mapAttendance does not prove behaviour change
Pricing factors

What affects responsible AI service cost

A written estimate should follow initial scoping because system risk, evidence quality and stakeholder complexity materially affect effort.

Portfolio size and risk

Number of AI systems, affected services, risk tiers, users, jurisdictions and suppliers.

Evidence and assessment depth

Availability of model, data, testing, process, contract and operational documentation.

Governance complexity

Departments, committees, delegated powers, procurement routes and review requirements.

Implementation scope

Policy drafting, workflow configuration, technical testing, training, assurance and managed support.

Request a scope-based estimate

Provide the system count, public-service context, stage, suppliers, key deadlines and existing governance materials.

Request a Consultation
Why DataConsultant

Why consider DataConsultant for public-sector responsible AI

Business, policy and technical alignment

We connect public purpose, operating processes, data, models, procurement and governance rather than treating responsible AI as a standalone ethics document.

Evidence-conscious delivery

Findings and controls are linked to available evidence, with assumptions, gaps, dependencies and specialist-review needs documented.

Vendor-neutral approach

Governance is designed around accountability and risk, while remaining compatible with the organisation’s chosen cloud, AI and data platforms.

Discuss your responsible AI requirement

Start with the public purpose, current stage, affected stakeholders, systems and principal governance concerns.

Request a Consultation
Assurance controls

Security, quality, privacy and compliance considerations

Security

Identity, privileged access, supply chain, threat modelling, logging, incident handling, secure development and model or prompt abuse considerations.

Quality

Data fitness, evaluation design, error analysis, robustness, traceability, change control, monitoring and acceptance criteria.

Privacy

Lawful purpose, minimisation, sensitive data, retention, residency, data-subject rights, vendor processing and privacy-impact alignment.

Compliance

Applicable AI, data, records, procurement, accessibility, administrative and sector-specific requirements, validated by authorised specialists.

Responsible AI assurance is multidisciplinary. DataConsultant records where legal, regulatory, cybersecurity, accessibility, records-management or independent audit review is required and does not present consulting advice as formal approval.
Delivery environment

Technology ecosystems and delivery considerations

Responsible AI controls must operate across policy workflows, service-management processes, data platforms, AI systems, supplier arrangements and assurance functions. The delivery design therefore considers integration, identity, logging, evidence retention, data residency, change management and the practical capacity of teams to operate controls.

Tooling can support inventory, workflow, testing and reporting, but accountability, judgement and public-law obligations cannot be automated away.

Responsible AIoperating model Public purpose & policyAI & data platformsProcurement & suppliersAssurance & oversight
Client feedback

How DataConsultant performs through the work clients value

These representative testimonials describe the communication, structure, delivery quality and practical support organisations may value in a responsible AI engagement. They are not presented as independently verified reviews or measured case-study evidence.

★★★★★
“The team helped us turn broad responsible AI principles into a governance process our policy, digital and operational teams could actually use. Communication was clear, findings were well documented, and revisions were handled professionally.”
Government Digital DirectorCentral government administration
★★★★★
“The assessment brought procurement, legal, risk and technical stakeholders into one structured discussion. The supplier evidence checklist and decision gates gave us a practical basis for evaluating an AI-enabled service.”
Public Procurement LeadGovernment shared services
★★★★★
“DataConsultant explained model risk and human oversight in language that service owners could understand. Delivery was organised, questions were addressed promptly, and the final control model reflected our operating reality.”
Service Transformation DirectorLocal public authority
★★★★★
“The work gave our assurance team a clearer way to review AI use cases without applying the same process to every system. The risk-tiering approach, templates and knowledge transfer were particularly useful.”
Internal Assurance ManagerPublic-sector regulator
★★★★★
“The engagement connected data quality, privacy, security and operational monitoring rather than treating them as separate exercises. The team was responsive, transparent about limitations, and constructive during review cycles.”
Chief Data OfficerPublic health organisation
★★★★★
“We needed practical guidance for generative AI use by staff. The resulting policy, training and escalation workflow were clear, proportionate and easy to adapt as our approved tools and risks changed.”
Workforce Technology HeadGovernment-owned enterprise
Frequently asked questions

Questions government teams ask about responsible AI

Direct answers on scope, delivery, governance, technology, cost, ownership and ongoing operation.

What is responsible AI in government?

Responsible AI in government is the disciplined design, procurement, use and oversight of AI so that public decisions and services remain lawful, fair, explainable, secure, accountable and subject to appropriate human control. The exact control model depends on the use case, affected people, data, jurisdiction and level of potential harm.

What does this service include?

The service can include AI inventory development, risk classification, governance design, impact assessment, policy and control design, procurement requirements, documentation, testing, human-oversight design, implementation support, training and ongoing assurance. Scope is agreed according to the systems, agencies and regulatory obligations involved.

Which government organisations are suitable for this service?

The service is suitable for ministries, departments, local authorities, public agencies, regulators and government-owned bodies that are planning, buying, piloting or operating AI. Suitability depends on access to accountable stakeholders, system information, data documentation and decision authority.

What deliverables are normally produced?

Typical deliverables include an AI system inventory, risk-tiering method, governance and accountability model, impact-assessment templates, control library, procurement clauses, documentation standards, assurance plan, implementation roadmap, training materials and reporting framework. Final deliverables depend on maturity and scope.

How is a government AI system assessed?

Assessment normally reviews purpose, legal basis, affected groups, data provenance, model behaviour, human oversight, explainability, security, privacy, accessibility, vendor dependencies, monitoring and redress. Evidence gaps are recorded, and specialist legal, security or audit work may be recommended where required.

Can DataConsultant support implementation after assessment?

Yes. Implementation support can cover governance mobilisation, control design, documentation, testing coordination, monitoring design, supplier assurance, operating procedures, training and transition into business-as-usual oversight. Technology configuration or legal approval may require separate specialists.

How long does a responsible AI engagement take?

There is no reliable fixed duration before discovery. Timing depends on the number and risk of AI systems, stakeholder availability, evidence quality, procurement arrangements, policy maturity, review cycles and whether implementation is included. A phased plan is normally agreed after initial scoping.

How is pricing calculated?

Pricing is based on scope, system count, risk levels, agencies involved, assessment depth, workshops, documentation needs, technical testing, supplier review, training and ongoing support. DataConsultant provides a written estimate after clarifying requirements and dependencies.

Which standards and frameworks can inform the work?

Relevant references may include ISO/IEC 42001, the NIST AI Risk Management Framework, ISO/IEC 23894, ISO/IEC 27001, ISO/IEC 27701, public-sector policy requirements and applicable AI, privacy and administrative-law obligations. Selection must be validated for the organisation and jurisdiction.

How are privacy and security addressed?

Privacy and security are addressed through data mapping, purpose and access review, minimisation, retention, residency, supplier controls, threat considerations, incident response and monitoring requirements. This service does not replace penetration testing, formal certification or legal advice unless separately commissioned.

Who owns the resulting policies and intellectual property?

Ownership and permitted reuse are defined in the engagement terms. Client-specific policies, decisions and operational records normally remain under the client’s control, while pre-existing methods and reusable consulting materials may remain with their original owner. Contract terms should be reviewed before work begins.

Can the service operate as a managed responsible AI function?

A managed support model can be scoped for inventory maintenance, assessment coordination, control monitoring, reporting, supplier review, governance meetings and capability building. Accountability for public decisions remains with the authorised government body and cannot be outsourced to a consultant.

How are results measured?

Results can be measured through inventory completeness, assessed-system coverage, control adoption, issue closure, review timeliness, documentation quality, training completion, escalation performance and monitoring coverage. Baselines, ownership and attribution limits should be agreed before reporting benefits.