AI Sherpa Talk to us →

Insights · Framework sketch

AI-assisted coding: a framework sketch for a small F&B business

What a governance framework for AI-written code can look like in a business with no IT team: six parts, with the review step shown in full.

In September 2026 the PDPC accepted a voluntary undertaking from Bee Cheng Hiang, after an email script written with an AI tool exposed its members’ email addresses (our write-up of the incident). Under term (a), the company commits to “a governance framework for AI assisted coding, including requirements for independent technical review of AI-generated code involving personal data incorporating the 11 AI Governance Principles from the AI Verify Testing Framework” (the PDPC’s decision).

Staff in small businesses can now write scripts with a chatbot. This page sketches what such a framework could look like for one of them.

Illustrative only. This is not Bee Cheng Hiang’s framework and not legal advice. AI Verify is a voluntary testing framework, not a certification.

The business it is for

A family-run food brand. It sells online, keeps a members’ list for promotions, and has a marketing executive who uses a chatbot to write small scripts, for example to send the monthly promotion email. There is no in-house developer.

The framework in six parts

  1. Owner. One named person, usually the owner or the operations manager, is accountable for AI-written code and approves its use.
  2. Allowed tools and uses. A short list of approved AI tools and what staff may use them for. Customer data is never pasted into a chatbot.
  3. Independent review. Any AI-written code that touches personal data is reviewed by someone other than its author before it runs. The checklist is below.
  4. Pre-send test. Every bulk send is first tested on dummy accounts, and someone opens what arrives. The email platform is set to refuse a message with several recipients.
  5. Evidence kept. One log line for each review or test: who, what, when and the result.
  6. Training. A short session for anyone who writes or runs scripts, on these rules and the reasons for them.

Sample: the review checklist

The reviewer works through this list before the script runs on real customer data.

  1. The request to the AI tool said what the code must not do, for example “never put more than one address in the To or Cc field”.
  2. The reviewer did not write or prompt the code, and can explain what each line does.
  3. The reviewer has checked what personal data the code reads, where it sends it and what it writes to logs.
  4. The script has no passwords, keys or other secrets written into it.
  5. A test run on a dummy list is done. Each test email is opened, and the To and Cc fields show one recipient only.
  6. The first live run goes to a small batch, and someone checks the results before the rest go out.
  7. The sign-off is recorded in the log before the full run.
  8. If anything is unexpected, stop, fix and test again. If personal data has already gone out, follow the data breach procedure.

How the sketch maps to the 11 AI Verify principles

AI Verify lists 11 principles. For a small script that handles personal data, five carry most of the weight and the other six apply more lightly.

PrincipleWeightHow the sketch covers it
AccountabilityCoreA named owner, and a sign-off recorded before the full run.
Human agency and oversightCoreA person who is not the author reviews the code and can stop the run.
SecurityCoreNo secrets in scripts, and customer data stays out of chatbots.
RobustnessCoreA dummy-list test, a small first batch, and a platform that refuses messages with several recipients.
Data governanceCoreThe reviewer checks what personal data the code reads, sends and logs.
TransparencyLighter for this useThe allowed-tools list tells staff where AI tools are used.
ExplainabilityLighter for this useThe reviewer can explain the code line by line.
ReproducibilityLighter for this useThe log records who ran what, when, and the result.
SafetyLighter for this useStop, fix and test again when anything is unexpected, and follow the breach procedure if data is exposed.
FairnessLighter for this useA promotion email script makes no decisions about people. Fairness matters more when AI does.
Inclusive growth, societal and environmental well-beingLighter for this useTraining helps more staff use AI tools safely.

This page uses the principle names only. The AI Verify Foundation publishes the full framework, with its outcomes and process checks (see Sources).

Sources