Answers for your risk review.
Reviews at banks and wirehouses ask the same questions in roughly the same order. Here are the short answers. The full engagement briefing, written for legal, risk, compliance, privacy and information security reviewers, is available on request.
How it's structured
- Who you contract with
- Blue Eye Consulting LLC, a Florida limited liability company operating as BlueEye Advisory, in a consulting capacity, under a master services agreement and statement of work. Where your firm already has an approved vendor we work alongside, we can contract through that relationship instead.
- What BlueEye does
- Scenario and scorecard design, coaching design, manager enablement, reporting and program management. People do the work. AI is a tool inside it, not the service itself.
- Platforms
- Where an AI practice platform is used, it's a third-party tool, named in the engagement briefing. We tell you up front about any referral or reseller relationship with a platform we recommend, before anything is signed.
- Human review
- Scenarios and scorecards are defined by your firm and reviewed by people. The AI doesn't make customer-facing decisions.
What the engagement touches
- In scope
- Participant rosters (name and business email), hypothetical practice scenarios, employees' practice conversations and the scores on them, and aggregate reporting.
- Out of scope
- No customer or consumer data. No account-level financial information. No CRM or custodial integration. In the reviews we've been through, practice activity hasn't been treated as a books-and-records event.
- Voice
- Zero data retention for voice is the default for financial services deployments. Transcripts and scorecards are the only persisted artifacts.
- Model training
- Your data isn't used to train or fine-tune any AI model. The platform reaches its models through enterprise cloud services with training disabled, and the briefing lists each model provider.
- Hosting
- US public cloud, US regions only. Encryption is TLS 1.2 or higher in transit and AES-256 at rest.
Who holds what
BlueEye is a consulting firm, not a software vendor, so the platform certifications belong to the platform. We name it in the briefing so your third-party risk team can verify it directly.
- SOC 2 Type II
- Held by the AI practice platform we deploy. Report available under NDA.
- ISO/IEC 27001:2022
- Held by the platform. Certificate valid to June 2028.
- GDPR and HIPAA
- The platform offers a data processing addendum for EU and UK personal data and maintains HIPAA-aligned safeguards. Our financial services engagements involve no health information.
- BlueEye insurance
- Professional liability (errors and omissions) and general liability coverage in force. Certificates on request.
- Subprocessors
- A current subprocessor inventory for the platform, with what each one does and where it runs, is included in the briefing.
Documents we can share
The engagement briefing, which covers the questions reviews ask in the order they ask them. Under NDA, we can also share the platform's SOC 2 Type II report, its ISO certificate, its security questionnaire, its subprocessor table, its data processing addendum, its responsible AI use policy, and our certificates of insurance.
We can also set up a working session between your information security team and the platform's head of security.