Skip to main content

Work

Four Approval Patterns That Hold Up in Regulated Industries

Pre approval, sampled review, dual control and hard stop: four ways to put humans in front of AI output, what each suits, and where each one fails.

Written by Sicherhaven

You need humans reviewing AI output, and the rules you work under will not accept "someone checks it". They want a pattern you can name, describe and evidence.

There are four that hold up in practice: pre approval, sampled review, dual control and hard stop. Each suits a different kind of work. Each has a failure mode that shows up months later, and knowing that failure mode in advance is most of the value.

Pre approval

Every output waits for a named human before it goes anywhere. The agent drafts, a person reads, the person releases it, and that person is a named owner rather than a shared inbox.

This suits work where every item carries real consequence and volume is low enough for a person to keep up. Client communications, regulatory submissions, anything that goes to a customer with your name on it.

The failure mode is fatigue. When someone approves forty items a day, approval becomes a click. Within a couple of months the control exists on paper and not in the room. You can slow this down by putting the riskiest field first on the approval screen and by showing the change rather than the reasoning, but you cannot eliminate it. Pre approval is expensive attention, and attention degrades.

Watch for the sign: approval times dropping steadily while volume stays flat. That is not efficiency.

Sampled review

Output goes out automatically. A defined share of it is pulled and reviewed after the fact, and errors found in the sample trigger a wider check.

This suits high volume, low individual consequence work where the aggregate matters more than any single item. Internal summaries, categorisation, routine updates.

Two failure modes. The first is sampling the wrong things, usually by sampling at random when the risk is not randomly distributed. Weight your sample towards the unusual: new record types, first runs after a configuration change, outputs where the agent had thin context. Much of that is cheaper to catch earlier, by testing the agent before it touches live records. The second is having no defined response. A sample that finds errors and produces nothing but a note in a spreadsheet is theatre. Write down in advance what happens when the sample fails, including who has authority to pause the workflow.

Sampled review is the pattern most likely to satisfy an auditor and least likely to protect a customer, so be careful where you apply it.

Dual control

Two people, both required, usually with different roles. One prepares or checks the substance, the other authorises.

This is the pattern regulated industries already know, because it long predates AI. Payments, access changes, anything where a single person acting alone is the risk you are managing.

The failure mode is collusion by convenience rather than intent. The two approvers sit next to each other, one always follows the other, and the second check becomes a formality. Separation of duty needs to be real separation: different reporting lines, different incentives, ideally different teams. If your second approver has never once sent something back, the control is not working.

Dual control is slow, and it should be. Applying it to everything is how organisations end up quietly routing work around it.

Hard stop

Certain actions are simply not available to the agent. Not approved, not delayed, not possible.

This is the strongest pattern and the most underused. Deleting records, moving money, changing permissions, and whatever you decide an agent should never be allowed to email. An agent that cannot do a thing cannot do it by mistake, and cannot be talked into it by a cleverly worded input.

Wealthwise takes this approach in a consumer setting: it is advisory only, so it ranks cards against what someone actually spends on and shows the annual cost of using the wrong one, but it never moves money or places trades. The boundary is in what the product can do, not in what it promises not to do.

The failure mode is scope creep at the edges. Someone needs an exception, an exception is granted quietly, and the hard stop becomes a soft one. Hard stops need to be enforced in the system and reviewed on a schedule, with every exception recorded and expiring by default.

Choosing between them

Most organisations need more than one. A sensible default: hard stop for irreversible or money moving actions, dual control for anything with an external regulator watching, pre approval for named customer contact, sampled review for everything else.

The mistake is applying one pattern uniformly. Pre approval everywhere buries your best reviewers in trivia and leaves them tired when something serious arrives. Sampled review everywhere leaves the serious things unchecked.

SicherOne is built around a human approving agent output before it ships, which makes the pattern a configuration question rather than a rebuild. Whatever you use, write down which pattern applies to which workflow, and review that mapping when the work changes. The most common failure is not a bad pattern. It is a good pattern still attached to a workflow that has quietly become something else.

← All posts

We're building the future of community events and financial wellness

See how Eventify and WealthWise change the way people find events and manage money.

Get Started