top of page

OneTrust 

Governance, risk, and compliance platform

Our team's first AI feature. No time to test it before launch. Every decision came down to one question: will users trust this enough to act on it?

POLICY AI 

CONTEXT

Policy and compliance managers need to know exactly where their data is, where it's going, and what's happening to it, because missing a gap has real consequences for the business. Today that means jumping between multiple parts of the platform and cross-referencing by hand. It's easy to get wrong and hard to feel confident about, with no room for error.

 

This was our team's first major AI feature, with a tight deadline and no time to test with real users. We weren't introducing AI to users starting from neutral ground. Inconsistency across the platform meant many of them already didn't fully trust it. If users don't trust what the AI surfaces, they won't use it, and a feature nobody uses doesn't help anyone.

The ask was to use AI to surface policy gaps faster. If someone acts on a recommendation without understanding where it came from, or without questioning it at all, that's not okay in a compliance context. Getting people to trust the AI wasn't straightforward.

THE PROBLEM

Two things I kept coming back to.

 

The AI needed to show its work. It explains what it found and why, so users can evaluate the recommendation themselves.

 

The analysis had to be user-initiated. I pushed back on running it automatically in the background. In compliance, changes happening without the user's knowledge are a problem. Trust requires consent and transparency.

 

I also changed the layout. The original design stacked two tables on top of each other, which felt like a lot to take in. I split them into tabs, recommendations and controls, one section at a time.

 

The shareable report was another feature I pushed for. It gives users a chance to review the AI's recommendations with their team before anything goes out the door.

DESIGN DECISIONS

Recommended Controls.png

Tabbed structure: Recommendations and policy controls separated. One thing at a time.

1.06.png

AI-generated report: Users review before anything goes out the door. That step is what builds trust over time.

  • Shipped on time

  • AI outputs include context and explanation, not just results

  • Users control when the analysis runs
     

No user testing before this went live. Every decision was based on principle and what I knew about how this user base thinks. I'd want to go back and find out if it held up.

OUTCOME

Five users before launch would have been enough to pressure-test the mental model. I'd fight harder for that time next time.

 

Introducing AI is a UX and trust problem. It comes down to accountability: who's responsible for acting on a recommendation, and whether they feel confident enough to.

WHAT I'D DO DIFFERENTLY

bottom of page