AI you can defend to a patient, a funder and an auditor.
How KY & Company builds, safeguards and measures AI across healthcare, social impact and public-sector systems — and what every institution should ask before switching it on.
AI can now draft a grant assessment, summarise a patient questionnaire or flag a duplicate application in seconds. For the organisations we serve, the question is no longer whether AI can do the task. It is whether the output can stand up to scrutiny.
Our view is simple: responsible AI is not a policy document. It is an engineering discipline — decided in the design, enforced in the architecture and proven with evidence.
Adoption is racing ahead of trust.
of organisations using AI have already experienced at least one negative consequence — inaccuracy is the most common.
McKinsey, The State of AI 20252of business and technology leaders say their AI risk and governance controls are fully in place. Only 6% fully trust AI agents with core processes.
Harvard Business Review Analytic Services, 20253of senior IT leaders are concerned about the security risks of generative AI; 73% worry about biased outcomes.
Harvard Business Review, 20231Generative AI should be “accurate, safe, honest, empowering, and sustainable.” Kathy Baxter & Yoav Schlesinger, Harvard Business Review1
Engineering trust where the stakes are highest.
In a consumer app, a wrong answer is an inconvenience. In our sectors, it carries real consequences.
Healthcare & Life Sciences
A misleading output can distort a clinical conversation or a patient’s understanding of their care. The World Health Organization’s guidance on generative AI in health sets out more than 40 recommendations for developers, providers and governments.5
Social Impact & NGOs
Grant and award decisions shape who receives funding. AI assistance has to be fair, explainable and accountable to donors and boards.
Government & Statutory Bodies
Public services need transparency, audit trails and documentation that meets procurement standards. In Hong Kong, the PCPD’s AI Model Framework guides how organisations procure, implement and use AI under the PDPO.6
Three disciplines, one accountable partner.
The same principle behind our consultancy, platforms and managed services applies to every AI feature we ship.
We govern it.
We decide where AI belongs before we build it. AI assists; people remain accountable for decisions.
We safeguard it.
Your data stays protected and in region, and every model is kept to a narrow, well-defined job.
We measure it.
No feature goes live without evidence that it works — and it stays monitored after launch.
Our approach follows the structure of the NIST AI Risk Management Framework — Govern, Map, Measure and Manage — the reference model used by public and private organisations worldwide.4
We govern it.
Decide where AI belongs before you build it.
The most important responsible-AI decision happens before a model is chosen: deciding which tasks AI should assist with, and which it must never decide alone. Human oversight is one of the seven ethical principles Hong Kong’s Privacy Commissioner sets for AI.6
AwardScience™ — AI scoring comes with its reasoning, so judges can see why a submission scored as it did. Panels review, challenge and override those scores; final decisions stay with the people accountable for them.
Pati™ — Validated self-assessment instruments remain the clinical backbone. AI never replaces a validated questionnaire or produces anything that could be read as a diagnosis.
For bespoke portals, every AI feature is documented: what it does, what data it touches and who owns its output. Users can always see when content was AI-generated.
We safeguard it.
Protect the data. Constrain the model.
Your data is not training data. Customer data is never used for AI training, model improvement, benchmarking, advertising or any other secondary purpose.
Inference stays close to home. We are moving AI inference onto Amazon Bedrock inside each client’s selected hosting region — EU, US or Singapore — so prompts and outputs stay within the same boundary as the rest of your data.
Access is tightly controlled. Customer data is accessible only to our Hong Kong-based team, with role-based access and full audit trails.
The model is kept in a narrow lane:
- Outputs are grounded in your own source material, not open-ended generation.
- Applicant-, patient- and public-facing inputs are treated as untrusted, guarding against prompt injection.
- Sensitive workflows fail safe: if the model is uncertain or unavailable, the process falls back to a human path.
We measure it.
If you can’t measure it, don’t deploy it.
A demo that impresses on ten hand-picked examples says little about ten thousand real submissions. McKinsey found explainability is among the most commonly reported AI risks, yet not among the most commonly mitigated.2 NIST is equally clear that measurement must continue as systems and risks evolve.4
Led by PMP and Six Sigma-certified delivery, we treat every AI feature as a production process.
- DefineSet what “good” means for the task — factual faithfulness for summaries, precision and recall for duplicate detection, agreement with expert panels for scoring.
- MeasureBuild a representative, de-identified evaluation set with domain experts, and benchmark against the manual process it supports.
- AnalyseCheck for uneven performance across languages, formats and applicant groups — essential for multilingual programmes across APAC.
- ImproveRe-test every prompt or model change against the evaluation set before it reaches production.
- ControlMonitor reviewer overrides, error reports and output quality after go-live, and investigate when the numbers move.
Six questions to ask any AI vendor.
Whether you work with us or not. If a vendor can’t answer clearly, the feature isn’t ready for a regulated or mission-driven environment.
- Is our data used to train or improve any model — the vendor’s or a third party’s?
- Where are prompts and outputs processed, and does that match our data residency needs?
- Which decisions does the AI make, and which remain with people?
- How was performance measured before launch, against what data and what baseline?
- How is performance monitored after launch, and who is alerted when it drops?
- What happens when the AI fails or is unavailable?
Built for regulated environments
- No customer data used for AI training
- GDPR & CCPA Aligned
- AES-256 Encryption
- RBAC & Audit Trails
- Selectable Data Residency — EU / US / SG
- ISO 27001 Programme Underway
References
- Baxter, K. & Schlesinger, Y. (2023). Managing the Risks of Generative AI. Harvard Business Review, 6 June 2023.
- McKinsey & Company (2025). The State of AI in 2025: Agents, Innovation, and Transformation. QuantumBlack, AI by McKinsey.
- Harvard Business Review Analytic Services (2025). Agentic AI research report, survey of 603 business and technology leaders, July 2025. Reported by Fortune, 9 December 2025.
- National Institute of Standards and Technology (2023). Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1.
- World Health Organization (2024). Ethics and Governance of Artificial Intelligence for Health: Guidance on Large Multi-Modal Models. Geneva: WHO.
- Office of the Privacy Commissioner for Personal Data, Hong Kong (2024). Artificial Intelligence: Model Personal Data Protection Framework; and Guidance on the Ethical Development and Use of Artificial Intelligence (2021).
Engineering AI where it matters most.
Whether you’re scoring a global award programme or supporting patients between appointments, AI should earn its place with evidence. Partner with KY & Company for AI that is governed, safeguarded and measured.
Get In Touch →