Governance and controlsPrivacy, Security, Compliance, and Accountability
Hallucination testing should operate within the organisation’s wider AI governance, data protection, information security, model-risk, supplier-risk, and change-management arrangements.
Privacy and confidentialityUse approved data, minimise sensitive content, define access and retention, redact where necessary, and prevent evaluation data from being reused outside authorised purposes.
Security and environmentsAgree test environments, credentials, logging, source access, supplier connections, tool permissions, export restrictions, and handling of prompts and outputs.
Regulatory interpretationMap relevant obligations and evidence needs, but obtain authorised legal, compliance, safety, or sector-specialist review where required. Testing is not a substitute for legal advice or certification.
Human accountabilityDefine who approves criteria, resolves ambiguous truth, accepts residual risk, authorises release, owns remediation, handles incidents, and reviews material changes.
Data and source governanceTrack authority, provenance, freshness, version, ownership, conflicts, access policy, and lifecycle of the evidence used to ground answers and judge correctness.
Third-party and model changeDocument provider dependencies, model versions, update notifications, service terms, data processing, regional availability, performance changes, and retesting triggers.