What automation can and cannot do

Can: compare a draft against an approved policy corpus and list possible mismatches with citations. Cannot: certify legal compliance, replace auditors, or understand unwritten local custom without human context. Treat output as a checklist for humans, not a certificate of holiness.

Setup requirements

  • Authoritative policy library with owners and versions
  • Access control
  • Citation-first outputs
  • Human compliance or management review

Example uses

Check whether a new facilities procedure mentions required safeguarding referral language; whether a finance draft still matches approval thresholds; whether a school policy conflicts with a diocesan directive. Always verify. Pair with governance programme design in virtuous AI governance.

Lifecycle of the policy index

Every source needs an owner, a review date and a retirement path. Out-of-date policies in a retrieval system are worse than a missing document because they look authoritative. Schedule quarterly content hygiene the same way you schedule financial reviews.

False confidence is the main risk

A green checkmark from software can lull managers into skipping human reading. Configure interfaces to say “possible gaps—verify” rather than “compliant.” Log who accepted or rejected each flag. That log is how you prove governance if a regulator or bishop’s office asks what process you used.

Start with one policy domain (for example facilities or finance thresholds) before boiling the ocean.