K · Practical guide

Practical Guide: Retail and Consumer

Individually small consequences multiplied by everyone, plus a handful of systems that quietly make decisions about people rather than products.

Typical top tier
Tier 3 — pricing, in-store vision, workforce and age-restricted decisions
Already-owned ground
Consumer law compliance, advertising substantiation, payment security
Hardest gate
G1 — deciding which of a hundred small systems are actually about people
First record to fix
The inventory. Retail estates are wide, shallow and mostly unrecorded

1. Where the risk actually concentrates

Retail inverts the usual risk shape. Most systems have a low D1 and a maximum D4: a recommendation that is wrong costs a customer thirty seconds, and it happens forty million times. The framework handles this correctly — impact is the average of consequence, exposure and sensitivity, so scale alone does not manufacture a high tier — but it means the sector's governance effort should go into breadth and speed, not depth. A hundred Tier 1 systems governed lightly and recorded properly is the right outcome.

Inside that breadth sit a small number of systems that are not about products at all. Personalized pricing, workforce scheduling, loss-prevention vision, age verification and fraud or returns-abuse scoring make decisions about identified people, and they carry consequences that customers and staff experience directly. These are the systems to find first, and they are usually owned by functions that do not think of themselves as running AI.

The third factor is speed of public consequence. A generated product description, an offensive recommendation adjacency, or a pricing pattern that looks discriminatory becomes a public story in hours. The control that matters is not review depth but the ability to stop and correct quickly, and to know which system produced the output.

Discover search, ranking, recommendation Tier 2 Price personalization, markdown Tier 3 Transact fraud, verification, payment Tier 3 Fulfil forecasting, replenishment Tier 1 Store and staff vision, scheduling Tier 4
The tier does not follow the technology. The most sophisticated systems in a retail estate sit in the two lowest columns, and the highest tier is reached by camera analytics and shift allocation — systems usually procured by functions that do not consider themselves AI owners.

Indicative classification of the systems this sector keeps building. The scores are illustrative, not authoritative: they show how the anchors in Chapter 6 read against sector facts. Score your own system; do not copy a row.

Typical system Illustrative D1–D5 Tier What is usually mis-scored
Personalized or dynamic pricing at individual levelD1 3 · D2 3–4 · D3 3 · D4 4 · D5 3Tier 3–4Treated as commercial optimization; it is a decision about what this person pays
Loss prevention or in-store vision on customers and staffD1 4 · D2 2–3 · D3 4 · D4 4 · D5 4Tier 4A false accusation is irreversible, and biometric data raises D5 to 4 in many jurisdictions
Age or identity verification for restricted goodsD1 3–4 · D2 3–4 · D3 3 · D4 4 · D5 4Tier 3–4Both error directions matter: a sale that should not have happened, and a customer wrongly refused
Workforce scheduling and shift allocationD1 3 · D2 3 · D3 3 · D4 4 · D5 3Tier 3Scored as operations; it determines income stability for hourly workers
Fraud, chargeback and returns-abuse scoringD1 3–4 · D2 3 · D3 3 · D4 4 · D5 3Tier 3Account restriction on a false positive is close to irreversible for the relationship
Recommendation, ranking and search relevanceD1 1–2 · D2 3–4 · D3 2 · D4 4 · D5 2Tier 2Correctly low tier; the exception is adjacency and safety of what is surfaced to minors
Generated product content, imagery and marketing copyD1 2–3 · D2 3 · D3 3 · D4 4 · D5 2Tier 2–3Substantiation: a generated claim about a product is a claim the retailer made
Demand forecasting, replenishment and markdownD1 2 · D2 3–4 · D3 2 · D4 3 · D5 1–2Tier 2Genuinely low tier — resist the urge to govern it heavily
Customer service assistant with account actionsD1 3 · D2 3 · D3 3 · D4 4 · D5 3Tier 3The action scope, not the conversation, sets the tier

2. The regulatory interface

Regulatory note. The regimes below are named so each IRGF record can be pointed at the obligation it evidences, not to restate them. Applicability, thresholds and commencement dates differ by jurisdiction and several have moved during implementation. Nothing here is legal advice: confirm the current position with your own counsel, and record the answer in the Regulatory Overlay Reference so it is checkable later.

IRGF does not restate any of these obligations. It gives each one a record that carries the evidence, an owner, and a trigger that reopens it when the obligation or the system changes.

Regime or standard What it obliges in practice IRGF record that carries the evidence
Consumer protection and unfair commercial practice lawNo misleading actions or omissions, price transparency and reference-price rules, and substantiation for claims.Generated claims registered as an assured output with a substantiation control in the Control Matrix
Data protection and profiling rules, including rules on automated decisions with significant effectLawful basis for profiling, transparency, objection rights, and special protection for children's data.Lineage record; oversight point at G3 for anything with a significant effect on the individual
Biometric and image processing law where in-store vision is used (for example state biometric statutes and general data protection rules)Notice and often consent, retention limits, and in some jurisdictions a prohibition on certain uses.D5 anchored at 4; retention and notice recorded as controls; deployment location recorded per site
Competition law as it applies to algorithmic pricingProhibition on coordinated pricing behaviour, including through shared tools or signalling.Pricing inputs and any third-party price signals recorded in the lineage record; constraint recorded in the architecture decision
Platform and digital services rules where the retailer operates a marketplaceRecommender transparency, advertising records, notice and action processes, and protections for minors.Transparency obligations satisfied from the derived AI System Card rather than authored separately
Payment security and age-restricted sales lawCardholder data protection, and legal duties on the sale of restricted goods.Standard controls referenced, not restated; verification failure rates monitored as a runtime signal

3. Calibrating the five dimensions

The dimensions do not change. What changes is what a 3 and a 4 look like when the subject matter is this sector, and which reading an assessor under delivery pressure reaches for first.

Dimension How to read it here The mis-score to watch for
D1 Decision ConsequenceProduct-level errors are 1 to 2. Decisions about a person — price, refusal, accusation, shift, account restriction — start at 3. An accusation of theft is 4.The reverse error: governing recommendation engines heavily and pricing or loss prevention lightly, because the first is visibly AI and the second is a business process.
D2 AutonomyNearly everything in retail is fully automated, and that is usually appropriate. High D2 with low D1 is a Tier 1 or 2 system and should stay one.Inflating tiers because automation feels risky. Control Deficit is the average of D2 and D3; a reversible automated decision is not high risk.
D3 Reversibility DeficitA refund reverses. A public statement, an accusation, a shared fraud flag and a price a customer already paid do not.Assuming refundability equals reversibility for the customer relationship.
D4 Exposure and ScaleAlmost always 4. That is why it must not be the dominant factor: the framework's averaging is doing deliberate work here.Letting D4 = 4 drag routine systems into Tier 3 and exhausting the governance budget on them.
D5 Sensitivity and UncertaintyPurchase history is 2 to 3. Biometric and image data of identifiable people is 4. Children's data is 4.Treating in-store camera analytics as anonymous when the pipeline retains identifiable frames.

4. One system, end to end

The overlay above is a map. This is one route across it: a single customer session followed from identification to outcome monitoring, with the record or control that attaches at each step.

Worked example — personalized pricing at individual level D1 3 · D2 3–4 · D3 3 · D4 4 · D5 3 → IMPACT 4 · CONTROL DEFICIT 3 → TIER 3–4 IN THE WORLD IN THE RECORD, AND WHAT WATCHES IT Customer identified across session and device The person- affecting question at G1: this decides about a person, not a product Features assembled from behaviour and context Price-input register: every input used to set an individual price, and the constraints applied Price set and shown Constraint list enforced at the feature layer, not stated in the design document Customer pays, or leaves Time-to-stop tested and recorded: how fast this can be switched off without a release Outcomes accumulate across segments Drift watch: a new pricing input appears, outcome divergence by segment
The estate's exception. Almost everything in retail is high scale and low consequence, and should stay lightly governed. This system is the exception, and the tell is column one: it makes a decision about an identified person. Column four matters more than another review cycle — in this sector the ability to stop quickly is the control.

5. What each gate adds

Additions only. Everything in the base gate definitions still applies; see the gate checklists for the common set.

Gate Sector addition Why it is here
G1One question decides the path: does this system make a decision about an identified person, or about a product? Route accordingly.It is the cheapest triage in this guide and it prevents both over- and under-governance.
G2For people-affecting systems only: full lineage and a stated basis for the personal data. For product systems: pattern conformance and nothing more.Depth has to be reserved, or the estate's breadth will consume the function.
G3A stop capability with a stated time-to-effect for anything customer-visible, and directional criteria for verification and fraud systems.In this sector the ability to stop quickly is worth more than another review cycle.
G4Change is continuous and mostly Minor. Reserve Material for changes to who is affected, what data is used, and what the system can do.A change process that treats every model refresh as material will be bypassed within a quarter.
G5Retention short by default, especially for image and biometric pipelines.Retention is a liability here, not an asset.

6. Controls and evidence worth adding

Control Where it attaches Evidence it produces
Person-affecting register: the short list of systems that decide about peopleClassification intakeA named list, reviewed quarterly, that focuses the governance budget
Time-to-stop measurement for customer-visible generation and rankingRuntime capability; testedA tested figure — minutes, not a claim — for how fast an output source can be disabled
Claim substantiation check on generated product contentControl MatrixSampled generated claims traced to a source attribute or specification
Directional thresholds for age verification and fraud scoringAssurance SummaryFalse accept and false refuse rates reported separately, by segment
Human confirmation before any accusation or account restrictionWorkflow controlEvidence a person reviewed the case, with the case retained
Price-input register for personalized pricingLineage record; ADREvery input used to set an individual price, and the constraint list applied

7. Runtime signals to wire first

Control Plane onboarding order matters more than coverage in the first year (Chapter 18). These are the signals that earn their place earliest in this sector.

Signal Drift category Suggested response
A generated content source starts producing a claim pattern nobody approvedBehavioralSample continuously at low volume; the cost of the check is trivial next to a public correction
Verification refusal rate diverges by store, time or segmentBehavioralRoute to the operations and legal owners together; divergence here becomes a discrimination question
An image pipeline retains frames longer than approvedData lineage and governance / configurationImmediate: retention is the control that makes the whole deployment defensible
Pricing model begins using a newly available attributeData lineage and governanceBlock at the feature layer if possible; a new pricing input is a Material change
Third-party recommendation or pricing service changes model versionAI-model behavioralLog at Tier 1–2; re-run acceptance tests for the person-affecting systems

8. Failure modes this sector produces

Governing the visible and missing the consequential

The tell. The recommendation engine gets a full review; the workforce scheduling module and the loss-prevention camera analytics were procured as operational tools and never classified.

The response. Run the person-affecting question across every system in the estate once, including tools owned by store operations, HR and security.

Governance that does not scale to the estate

The tell. A process designed for twelve systems meets four hundred, and teams route around it.

The response. This is exactly what the minimum viable framework and tier scaling exist for (Chapter 27). Self-certification against pre-approved patterns should cover the majority of retail systems.

The pricing model that learned a protected pattern

The tell. Individual pricing uses location, device and browsing signals that reconstruct something the retailer would never price on deliberately.

The response. Maintain the price-input register and test outcomes by segment. A constraint that exists only in the design document is not a control.

Stop capability that has never been tested

The tell. When a generated description goes wrong publicly, nobody can say which system produced it or how to turn it off without a release.

The response. Test time-to-stop as part of G3, record the number, and re-test after any platform change.

9. A ninety-day start

If the sector is yours and the framework is new, this is the order that produces something defensible fastest. It assumes one part-time architect and one risk lead, not a programme.

  1. Build the inventory first, and accept that it will be long and shallow. Completeness beats depth here.
  2. Apply the person-affecting question to every entry and produce the short list.
  3. Score the short list properly, with an independent countersigner. Everything else can self-certify against patterns.
  4. Publish two or three pre-approved patterns covering recommendation, forecasting and content generation, so the long tail has a fast route.
  5. Test and record time-to-stop for every customer-visible generation path.
  6. Set directional thresholds for verification and fraud systems, by segment.
  7. Review retention on every image and biometric pipeline. Shorten it.
  8. Run a G3 dry run on the loss-prevention or pricing system, whichever is larger.