Templates and playbooks

Human Oversight Procedure Playbook

Download an human oversight playbook covering roles, approval Processes, queue management, override procedures, training requirements, and evidence capture.

Playbook preview (excerpt)

Part 2: Oversight Roles and Responsibilities

2.1 Oversight Role Definitions

RoleAuthority LevelTraining Required
AI OperatorLevel 1: Standard decisionsInitial cert + annual refresh
Senior OperatorLevel 2: Elevated decisionsAdvanced cert + quarterly review
Oversight SupervisorLevel 3: Override authoritySupervisory cert + monthly calibration

Part 5: Override and Reversal Procedures

5.1 Override Types

Override TypeAuthority RequiredDocumentation Level
Pre-execution overrideStandard approval authorityStandard
Post-execution reversalLevel 2+Enhanced with justification
Emergency overrideAny trained operatorEmergency protocol + retrospective
View the worked example

Override Reason Categories:

CategoryDescriptionReview Priority
SAFETYSafety concern for user or third partyImmediate review
ERRORObvious AI error or malfunctionHigh priority
CONTEXTAI lacked relevant contextStandard review
POLICYPolicy consideration AI cannot assessStandard review
JUDGMENTHuman judgment differs on edge casePattern analysis

Before you begin

For compliance, risk, product, and ML ops teams shipping agentic Processes into regulated environments.

EU AI Act Article 14 requires high-risk AI systems to be designed for effective oversight by natural persons. This playbook translates Article 14 requirements into operational procedures.

It covers 7 parts: Article 14 requirements, oversight roles, approval Processes, queue management, override procedures, training requirements, and evidence capture.

When to use this resource
  • You are inserting approval gates into AI Processes (high-risk actions, sensitive data access, production changes).
  • You need to prove who approved/overrode a decision and what context they saw.
  • You are preparing a human oversight section for Annex IV or an internal control review.

Information to gather

  • Role definitions with authority levels and competency requirements.
  • Approval Process triggers, steps, and documentation requirements.
  • Queue SLAs, prioritization rules, and bottleneck response procedures.
  • Override types, authority requirements, and reason categories.
  • Training curriculum with role-specific requirements and recertification.
  • Evidence data points, capture methods, and integrity requirements.

Review checklist

Use these checks in the review with your system owner. Confirm the applicable requirements and attach evidence for the decisions your team makes.

  • Roles and authority levels are explicit with competency requirements and recertification schedules.
  • Approval Processes define triggers, steps, and documentation for standard, escalation, and exception paths.
  • Queue management includes SLAs, prioritization rules, workload distribution, and bottleneck response.
  • Override procedures cover pre-execution, post-execution reversal, and emergency overrides with reason categories.
  • Training program defines curriculum, role-specific requirements, and ongoing competency verification.
  • Evidence capture specifies data points, capture methods, and integrity requirements for all oversight actions.

Operating controls and evidence

Govern

Policy-as-code checkpoints that block or require review for high-risk actions.

Versioned change control for model/prompt/policy/Process updates.

Assure

Risk-tiered sampling reviews (baseline + burst during incidents or after changes).

Near-miss tracking (blocked / nearly blocked steps) as a measurable control signal.

Prove

Configurable retention schedules, integrity verification, and an append-only Audit Trail.

Evidence Room export bundles (manifest + checksums) so auditors can verify independently.

Questions about this resource

What does Article 14 actually require?

Article 14 requires humans to understand AI capabilities and limitations, remain aware of automation bias, correctly interpret outputs, be able to override or reverse decisions, and be able to intervene or stop the system.

What should be recorded for each approval or override?

At minimum: decision ID, AI recommendation, context presented, reviewer ID, timestamp, action taken, rationale (if required), time spent on review, and policy version in effect.

How do we prevent rubber-stamping?

Define reviewer rubrics, require rationale for risky approvals, sample reviewer decisions, run calibration sessions, and track time spent on reviews.

What is a "two-person rule"?

A requirement that certain actions need two distinct human approvals, commonly used for high-impact or irreversible decisions like account closure or SAR filing.

How do we handle emergency overrides?

Allow immediate action by any trained operator, require "Emergency Override" documentation, auto-notify supervisors and compliance, and complete retrospective review within 24-48 hours.

What training competencies are required?

AI system fundamentals, domain knowledge, oversight procedures, automation bias awareness, override procedures, and compliance requirements. Recertification should be annual or more frequent.

Download oversight playbook

Download file language: English

Human Oversight Procedure Playbook | KLA