Policies

AI and Acceptable Use

AI assists a document-based assessment. Submit authorised, relevant evidence and have qualified people check recommendations before acting on them.

Last updated:

01How AI is used

ISOCheck sends your assessment scope, relevant organisation profile, approved criteria and extracted evidence to configured AI models through Vercel AI Gateway. The current assessment flow uses an auditor to generate findings and a challenger to review those findings. Model providers currently include OpenAI and Anthropic.

Automated checks require criterion coverage and verify cited quotations against submitted text. Reports that fail validation are not released. Findings requiring further review are held for staff, and consultant-tier reports require staff review before publication. These checks reduce risk but do not establish that every conclusion is correct.

Before checkout, you are asked to confirm your authority to submit the evidence and consent to its AI processing. The Privacy Policy explains sharing, overseas processing and retention. Contact us before submitting evidence if external AI processing is not permitted under your organisation’s requirements.

02Understand the limitations

AI may misunderstand context, miss evidence, produce inconsistent scores or suggest unsuitable actions. A quotation proves that text was supplied, not that the document is authentic or a control operates effectively. A lack of evidence is not proof of a breach.

Use findings as preparation support. Seek competent human review before legal, safety, employment, security or other consequential decisions. Do not use ISOCheck output as the sole basis for decisions affecting a person’s rights or wellbeing, or as proof of certification, accreditation or legal compliance.

03Responsible uploads

  • Use relevant, accurate and current evidence that you have authority to share.
  • Redact unnecessary personal information. Do not upload credentials, card details, identity documents or identifiable medical records.
  • Respect copyright, confidentiality and licences, including restrictions on machine processing of ISO standards.
  • Do not fabricate audit records or submit instructions intended to make the system invent, hide or falsify findings.

04Account and system misuse

Do not access another business’s records without authority, share credentials, upload malware, attempt to bypass access controls, overload the service or use it for unlawful activity. Do not resell another organisation’s evidence or impersonate Grey Meta, an auditor or a certification body.

Report suspected misuse or a misleading finding to info@greymeta.com.au, quoting the assessment and criterion identifiers where available. Avoid including sensitive evidence in an initial security report. Access may be restricted as described in the Terms of Service.

05Who operates this service

ISOCheck is operated by Grey Meta, trading as Grey Meta, ABN 92 917 977 661. This is the supplier identified on ISOCheck tax invoices and the entity responsible for this policy.

Back to top ↑