Quality improvement method

Targeted review of institutional controls under risk-based artificial intelligence regulation

Quality Improvement Methods

Considers the controls required to improve institutional controls under risk-based artificial intelligence regulation and to distinguish completed activity from demonstrated change.

The immediate international context is the artificial Intelligence Act entered into force in August 2024. The principal risks associated with institutional controls under risk-based artificial intelligence regulation should be assessed as connected conditions. A failed safeguard may conceal another weakness or prevent timely correction. Corrective action concerning the corrective programme should address the identified cause, assign responsibility and set a review period. Residual risk should remain open until sustained improvement is demonstrated. Consequential decisions should be considered in light of learner impact, institutional duty and stewardship of educational resources. Suitability should be judged within the relevant system rather than against a presumed universal administrative model.

Examination of the matter should follow a stated and reproducible method, including the decision rule, sampling basis, treatment of exceptions and threshold for escalation. The contemporaneous reference point for the improvement priority is Artificial Intelligence Act entered into force in August 2024. Its status should be distinguished from the jurisdiction-specific evidence required for implementation. Any consequential application still requires evidence from the affected jurisdiction or institution. It does not remove the need to identify territorial reach, transitional provisions, competent authority and the domestic measures through which obligations concerning the corrective programme are administered. A provider should not infer either universal application or exemption from the date alone.

Purpose and present context

The European Union Artificial Intelligence Act entered into force on 1 August 2024. It applies a risk-based framework and includes provisions relevant to certain education and vocational-training uses, particularly systems capable of influencing access, evaluation or progression. Requirements apply according to the Act’s staged timetable. Providers should classify intended uses, identify their role in the supply chain and preserve human oversight, data governance and incident controls.

Responsibility for the matter under review should be identifiable at each consequential decision point. Delegation should identify both the operating role and the body retaining oversight of learner impact. The record for the matter under review should identify the responsible function, decision authority and escalation route. Gaps between public oversight and provider control should not remain implicit. Responsibility for the corrective programme should be identifiable at each consequential decision point.

Improvement work on the intervention should begin with a verified problem, defined baseline and measurable outcome. Completion should depend on evidence of effect rather than completion of planned activity. Risk assessment for the matter under review should consider severity, reach, duration, recurrence and detectability, with escalation where learner impact may be material. Frequency is relevant, but a rare event may still be material where the effect is serious or irreversible. A stated decision rule enables comparable examination and limits retrospective explanations of adverse evidence.

Responsibility for the intervention should be visible at the point where consequential decisions are made. Risk assessment for the affected practice should consider severity, reach, duration, recurrence and detectability, with escalation where learner impact may be material. Escalation should follow whenever the available record cannot support a safe conclusion for the affected learners.

Improvement work on the corrective programme should begin with a verified problem, defined baseline and measurable outcome. The conclusion should rely on evidence whose date, source and coverage are sufficient for the decision. The record should retain disagreement between sources until its cause and effect are understood.

  • Retain accountable human decision-makers, including material exceptions and unequal effects.
  • Control personal and confidential information and retain evidence sufficient for independent review.
  • Notify users of material limitations, and retain the basis, responsible function and affected scope.
  • Review incidents and supplier changes, recording who is responsible and which provision or learners are affected.
  • Classify uses by effect on learners, recording who is responsible and which provision or learners are affected.

Responsibilities and material risks

Failure in relation to institutional controls under risk-based artificial intelligence regulation may arise even where the stated policy is reasonable. Analysis of the affected practice should state the unit of analysis, reference period, coverage, exclusions and treatment of missing information. Comparative findings should not conceal differences capable of changing their meaning. Risk assessment for the improvement priority should consider severity, reach, duration, recurrence and detectability, with escalation where learner impact may be material.

Intervention in the intervention should be proportionate to the identified condition and tested where risk permits. Wider implementation should follow evidence of benefit and acceptable unintended effects. For the affected practice, the reviewer should define escalation thresholds before reviewing cases, consider severity, reach, duration, recurrence and detectability, and record the reason for the final classification. Reassess materiality when new evidence changes the likely scope or consequence. Observations may inform further enquiry, but only supported findings should determine conformity or effectiveness.

Risk assessment for the intervention should consider severity, reach, duration, recurrence and detectability, with escalation where learner impact may be material. Each test should record the starting condition, change introduced, population affected and result. Intervention in the affected practice should be proportionate to the identified condition and tested where risk permits. Corrective action concerning the affected practice should address the identified cause, assign responsibility and set a review period.

Interpretation of the affected practice should not extend beyond the population, period and setting examined. Accuracy measured in one setting may not transfer to another population, language, curriculum or decision context. In reviewing the improvement priority, improvement data should not be selected only because it is readily available. The measure must correspond to the outcome the intervention is intended to change. A finding should not be separated from limitations capable of changing how it is understood or applied.

Decisions concerning the corrective programme should remain traceable to the information available for the stated reference period. Changes in condition, evidence, method and interpretation should be recorded separately when a conclusion is revised.

Accountability for the intervention should follow decision-making authority. Oversight is effective only if the responsible body receives the evidence and records its decision on resources, policy and residual risk. The operating function may change, but responsibility for oversight and learner protection should remain clear.

Any indicator used in relation to the improvement priority should distinguish description from causal explanation. Material variation and uncertainty should be reported together with any restriction on wider application. Performance should be judged by outcomes and timely response to shortfalls, not by the volume of administrative activity.