
Human Oversight
Human oversight in automated processes
Place human approval, exception handling and monitoring where people can understand, stop and correct automated work.
Human oversight works when a person has a clear decision, the information and authority to make it, and a way to stop or correct the process. Place that control where it can still affect the outcome. Approval shown after an irreversible action reviews what happened; it is not prior approval.
Separate routine actions the system may complete, decisions that need approval before the next step, and outcomes that can be monitored afterwards. Consider the consequence of an error, whether the rule is clear, whether the result can be reversed, and who owns cases outside the routine route.
Place the control at the decision point
Follow one case from its trigger to its business result. At each decision, ask what the system can establish, what a person must judge, and what remains blocked while they decide. Checking that required fields are present does not establish that a request should be granted.
| Arrangement | When to consider it | Control to define |
|---|---|---|
| Approval before action | The decision needs an authorised judgement or the action may be difficult to reverse | What the reviewer sees, what approval permits and what waits |
| Review of a flagged case | The routine rule can recognise a case it cannot finish safely | The flag, owner, next action and route to a result |
| Monitoring after action | The routine action is bounded and its result can be checked and corrected | What is reviewed, who investigates and when the rule is reconsidered |
These are design options, not fixed risk categories. A low-cost action may still affect sensitive access or a person’s interests. Asking someone to approve every predictable case can create a queue without giving them a useful decision.
Human Oversight Control Options by Decision Type
- Approval before action
- Decision requires authorised judgement or action may be difficult to reverse
- Review of a flagged case
- Routine rule recognises case it cannot finish safely
- Monitoring after action
- Routine action is bounded and result can be checked and corrected
Give the reviewer a meaningful choice
Show the proposed action, relevant facts, rule or reason, and known uncertainty. State whether the reviewer may approve, return, decline or escalate the case. If the system has already acted, show its actual result and make clear that the person is reviewing an outcome.
Set a deadline and a backup owner for time-sensitive work. A case awaiting approval should remain pending unless an authorised alternative route applies. An unopened notification or an absent approver should not become consent.
Keep departures and results visible
Before launch, define what happens when information is missing, a decision is disputed, a system fails or an action may have partly succeeded. Give the case a visible state, an owner and a next check. If a write may have succeeded despite an error response, check the destination before retrying; if its state cannot be established, keep the case held for resolution.
Join the business case to the automated action, any human decision and the observed result. A workflow marked successful does not by itself prove the business outcome in another system. Record corrections as subsequent events so a reviewer can follow the sequence.
Limit access to records and avoid retaining unnecessary personal information. For an Australian entity covered by the Australian Privacy Principles, security and disposal duties depend on the information and circumstances.
For an entity covered by the Australian Privacy Principles, APP 11 requires active measures to protect personal information it holds and active consideration of whether it is permitted to retain it. The OAIC says reasonable steps include technical and organisational measures, assessed in the circumstances.
When personal information is no longer needed for a purpose allowed under the APPs, reasonable steps must be taken to destroy or de-identify it. The requirement does not apply where the information is part of a Commonwealth record or must be retained under Australian law or a court or tribunal order.
For this purpose, an entity holds personal information where it has possession or control of a record containing it. That definition extends beyond physical possession, so consider which records the entity controls when identifying where personal information in a process is held.
Make public-facing automation visible
For a process that affects the public, consider whether people can find out that automated decision-making is used and what authority permits it. The Australian Information Commissioner’s report on automated decision-making and public reporting found gaps in agencies’ disclosure of automated decision-making.
The report found that 17% of agencies disclosed automated decision-making in their Information Publication Scheme information. A further 9% were identified as likely to be using it through external sources but had not disclosed it there; 74% could not be identified as using it through either source.
The Commissioner recommended that agencies authorised by legislation to use automated decision-making publish the relevant statute and whether they use it to provide information or services to the public.
Disclosure of Automated Decision-Making in Australian Agencies
- Agencies disclosing automated decision-making17%
- Agencies likely using automation but not disclosed9%
- Agencies undetermined on use of automation74%
Review whether the control works
Ask reviewers where they lack information or authority. Examine pending cases, overrides, corrections and outcomes discovered late. Repeated exceptions may indicate a changed input or an outdated rule; they do not automatically call for more approvals.
For a proposed launch, trace an ordinary case, a missing input, an unavailable approver and an uncertain system result through the design. Check that each has an owner and that an action requiring approval stays blocked until an authorised decision is made. Revisit the arrangement when the process, rule or consequences change.
In this guide
- Choosing decisions that still need human approvalScreen automated decisions for authority, judgement, consequence and reversibility before placing prior human approval.
- Defining an exception route before launchDefine the trigger, held work, owner, evidence and safe exit for cases an automation cannot finish.
- Keeping a record of automated and human actionsBuild a case history that connects automation attempts, human decisions, verified outcomes and later corrections.



