Practical Guide: Retail and Consumer
Individually small consequences multiplied by everyone, plus a handful of systems that quietly make decisions about people rather than products.
- Typical top tier
- Tier 3 — pricing, in-store vision, workforce and age-restricted decisions
- Already-owned ground
- Consumer law compliance, advertising substantiation, payment security
- Hardest gate
- G1 — deciding which of a hundred small systems are actually about people
- First record to fix
- The inventory. Retail estates are wide, shallow and mostly unrecorded
1. Where the risk actually concentrates
Retail inverts the usual risk shape. Most systems have a low D1 and a maximum D4: a recommendation that is wrong costs a customer thirty seconds, and it happens forty million times. The framework handles this correctly — impact is the average of consequence, exposure and sensitivity, so scale alone does not manufacture a high tier — but it means the sector's governance effort should go into breadth and speed, not depth. A hundred Tier 1 systems governed lightly and recorded properly is the right outcome.
Inside that breadth sit a small number of systems that are not about products at all. Personalized pricing, workforce scheduling, loss-prevention vision, age verification and fraud or returns-abuse scoring make decisions about identified people, and they carry consequences that customers and staff experience directly. These are the systems to find first, and they are usually owned by functions that do not think of themselves as running AI.
The third factor is speed of public consequence. A generated product description, an offensive recommendation adjacency, or a pricing pattern that looks discriminatory becomes a public story in hours. The control that matters is not review depth but the ability to stop and correct quickly, and to know which system produced the output.
Indicative classification of the systems this sector keeps building. The scores are illustrative, not authoritative: they show how the anchors in Chapter 6 read against sector facts. Score your own system; do not copy a row.
| Typical system | Illustrative D1–D5 | Tier | What is usually mis-scored |
|---|---|---|---|
| Personalized or dynamic pricing at individual level | D1 3 · D2 3–4 · D3 3 · D4 4 · D5 3 | Tier 3–4 | Treated as commercial optimization; it is a decision about what this person pays |
| Loss prevention or in-store vision on customers and staff | D1 4 · D2 2–3 · D3 4 · D4 4 · D5 4 | Tier 4 | A false accusation is irreversible, and biometric data raises D5 to 4 in many jurisdictions |
| Age or identity verification for restricted goods | D1 3–4 · D2 3–4 · D3 3 · D4 4 · D5 4 | Tier 3–4 | Both error directions matter: a sale that should not have happened, and a customer wrongly refused |
| Workforce scheduling and shift allocation | D1 3 · D2 3 · D3 3 · D4 4 · D5 3 | Tier 3 | Scored as operations; it determines income stability for hourly workers |
| Fraud, chargeback and returns-abuse scoring | D1 3–4 · D2 3 · D3 3 · D4 4 · D5 3 | Tier 3 | Account restriction on a false positive is close to irreversible for the relationship |
| Recommendation, ranking and search relevance | D1 1–2 · D2 3–4 · D3 2 · D4 4 · D5 2 | Tier 2 | Correctly low tier; the exception is adjacency and safety of what is surfaced to minors |
| Generated product content, imagery and marketing copy | D1 2–3 · D2 3 · D3 3 · D4 4 · D5 2 | Tier 2–3 | Substantiation: a generated claim about a product is a claim the retailer made |
| Demand forecasting, replenishment and markdown | D1 2 · D2 3–4 · D3 2 · D4 3 · D5 1–2 | Tier 2 | Genuinely low tier — resist the urge to govern it heavily |
| Customer service assistant with account actions | D1 3 · D2 3 · D3 3 · D4 4 · D5 3 | Tier 3 | The action scope, not the conversation, sets the tier |
2. The regulatory interface
Regulatory note. The regimes below are named so each IRGF record can be pointed at the obligation it evidences, not to restate them. Applicability, thresholds and commencement dates differ by jurisdiction and several have moved during implementation. Nothing here is legal advice: confirm the current position with your own counsel, and record the answer in the Regulatory Overlay Reference so it is checkable later.
IRGF does not restate any of these obligations. It gives each one a record that carries the evidence, an owner, and a trigger that reopens it when the obligation or the system changes.
| Regime or standard | What it obliges in practice | IRGF record that carries the evidence |
|---|---|---|
| Consumer protection and unfair commercial practice law | No misleading actions or omissions, price transparency and reference-price rules, and substantiation for claims. | Generated claims registered as an assured output with a substantiation control in the Control Matrix |
| Data protection and profiling rules, including rules on automated decisions with significant effect | Lawful basis for profiling, transparency, objection rights, and special protection for children's data. | Lineage record; oversight point at G3 for anything with a significant effect on the individual |
| Biometric and image processing law where in-store vision is used (for example state biometric statutes and general data protection rules) | Notice and often consent, retention limits, and in some jurisdictions a prohibition on certain uses. | D5 anchored at 4; retention and notice recorded as controls; deployment location recorded per site |
| Competition law as it applies to algorithmic pricing | Prohibition on coordinated pricing behaviour, including through shared tools or signalling. | Pricing inputs and any third-party price signals recorded in the lineage record; constraint recorded in the architecture decision |
| Platform and digital services rules where the retailer operates a marketplace | Recommender transparency, advertising records, notice and action processes, and protections for minors. | Transparency obligations satisfied from the derived AI System Card rather than authored separately |
| Payment security and age-restricted sales law | Cardholder data protection, and legal duties on the sale of restricted goods. | Standard controls referenced, not restated; verification failure rates monitored as a runtime signal |
3. Calibrating the five dimensions
The dimensions do not change. What changes is what a 3 and a 4 look like when the subject matter is this sector, and which reading an assessor under delivery pressure reaches for first.
| Dimension | How to read it here | The mis-score to watch for |
|---|---|---|
| D1 Decision Consequence | Product-level errors are 1 to 2. Decisions about a person — price, refusal, accusation, shift, account restriction — start at 3. An accusation of theft is 4. | The reverse error: governing recommendation engines heavily and pricing or loss prevention lightly, because the first is visibly AI and the second is a business process. |
| D2 Autonomy | Nearly everything in retail is fully automated, and that is usually appropriate. High D2 with low D1 is a Tier 1 or 2 system and should stay one. | Inflating tiers because automation feels risky. Control Deficit is the average of D2 and D3; a reversible automated decision is not high risk. |
| D3 Reversibility Deficit | A refund reverses. A public statement, an accusation, a shared fraud flag and a price a customer already paid do not. | Assuming refundability equals reversibility for the customer relationship. |
| D4 Exposure and Scale | Almost always 4. That is why it must not be the dominant factor: the framework's averaging is doing deliberate work here. | Letting D4 = 4 drag routine systems into Tier 3 and exhausting the governance budget on them. |
| D5 Sensitivity and Uncertainty | Purchase history is 2 to 3. Biometric and image data of identifiable people is 4. Children's data is 4. | Treating in-store camera analytics as anonymous when the pipeline retains identifiable frames. |
4. One system, end to end
The overlay above is a map. This is one route across it: a single customer session followed from identification to outcome monitoring, with the record or control that attaches at each step.
5. What each gate adds
Additions only. Everything in the base gate definitions still applies; see the gate checklists for the common set.
| Gate | Sector addition | Why it is here |
|---|---|---|
| G1 | One question decides the path: does this system make a decision about an identified person, or about a product? Route accordingly. | It is the cheapest triage in this guide and it prevents both over- and under-governance. |
| G2 | For people-affecting systems only: full lineage and a stated basis for the personal data. For product systems: pattern conformance and nothing more. | Depth has to be reserved, or the estate's breadth will consume the function. |
| G3 | A stop capability with a stated time-to-effect for anything customer-visible, and directional criteria for verification and fraud systems. | In this sector the ability to stop quickly is worth more than another review cycle. |
| G4 | Change is continuous and mostly Minor. Reserve Material for changes to who is affected, what data is used, and what the system can do. | A change process that treats every model refresh as material will be bypassed within a quarter. |
| G5 | Retention short by default, especially for image and biometric pipelines. | Retention is a liability here, not an asset. |
6. Controls and evidence worth adding
| Control | Where it attaches | Evidence it produces |
|---|---|---|
| Person-affecting register: the short list of systems that decide about people | Classification intake | A named list, reviewed quarterly, that focuses the governance budget |
| Time-to-stop measurement for customer-visible generation and ranking | Runtime capability; tested | A tested figure — minutes, not a claim — for how fast an output source can be disabled |
| Claim substantiation check on generated product content | Control Matrix | Sampled generated claims traced to a source attribute or specification |
| Directional thresholds for age verification and fraud scoring | Assurance Summary | False accept and false refuse rates reported separately, by segment |
| Human confirmation before any accusation or account restriction | Workflow control | Evidence a person reviewed the case, with the case retained |
| Price-input register for personalized pricing | Lineage record; ADR | Every input used to set an individual price, and the constraint list applied |
7. Runtime signals to wire first
Control Plane onboarding order matters more than coverage in the first year (Chapter 18). These are the signals that earn their place earliest in this sector.
| Signal | Drift category | Suggested response |
|---|---|---|
| A generated content source starts producing a claim pattern nobody approved | Behavioral | Sample continuously at low volume; the cost of the check is trivial next to a public correction |
| Verification refusal rate diverges by store, time or segment | Behavioral | Route to the operations and legal owners together; divergence here becomes a discrimination question |
| An image pipeline retains frames longer than approved | Data lineage and governance / configuration | Immediate: retention is the control that makes the whole deployment defensible |
| Pricing model begins using a newly available attribute | Data lineage and governance | Block at the feature layer if possible; a new pricing input is a Material change |
| Third-party recommendation or pricing service changes model version | AI-model behavioral | Log at Tier 1–2; re-run acceptance tests for the person-affecting systems |
8. Failure modes this sector produces
Governing the visible and missing the consequential
The tell. The recommendation engine gets a full review; the workforce scheduling module and the loss-prevention camera analytics were procured as operational tools and never classified.
The response. Run the person-affecting question across every system in the estate once, including tools owned by store operations, HR and security.
Governance that does not scale to the estate
The tell. A process designed for twelve systems meets four hundred, and teams route around it.
The response. This is exactly what the minimum viable framework and tier scaling exist for (Chapter 27). Self-certification against pre-approved patterns should cover the majority of retail systems.
The pricing model that learned a protected pattern
The tell. Individual pricing uses location, device and browsing signals that reconstruct something the retailer would never price on deliberately.
The response. Maintain the price-input register and test outcomes by segment. A constraint that exists only in the design document is not a control.
Stop capability that has never been tested
The tell. When a generated description goes wrong publicly, nobody can say which system produced it or how to turn it off without a release.
The response. Test time-to-stop as part of G3, record the number, and re-test after any platform change.
9. A ninety-day start
If the sector is yours and the framework is new, this is the order that produces something defensible fastest. It assumes one part-time architect and one risk lead, not a programme.
- Build the inventory first, and accept that it will be long and shallow. Completeness beats depth here.
- Apply the person-affecting question to every entry and produce the short list.
- Score the short list properly, with an independent countersigner. Everything else can self-certify against patterns.
- Publish two or three pre-approved patterns covering recommendation, forecasting and content generation, so the long tail has a fast route.
- Test and record time-to-stop for every customer-visible generation path.
- Set directional thresholds for verification and fraud systems, by segment.
- Review retention on every image and biometric pipeline. Shorten it.
- Run a G3 dry run on the loss-prevention or pricing system, whichever is larger.