Review Discipline: What It Looks Like When It Is Actually Working

Every firm using AI tools says it has a review process. Far fewer can describe specifically what that process catches, which is usually a sign the process is not catching much.

Signs the process is working

Reviewers occasionally send drafts back with specific, factual corrections, not just tone edits. Someone can point to a real example, from the last month, of a mistake the review step caught before it reached a client. The review step takes a meaningful amount of time, not a rubber-stamp glance.

Signs it has become a rubber stamp

Every draft gets approved essentially as written. Nobody can recall the last time a review caught a factual error. The approval step has become a formality that exists on paper but does not change any outcomes in practice.

How the rubber-stamp version happens

It usually happens gradually, as trust in the tool builds after a string of good drafts. Each individual decision to skim rather than check feels reasonable in the moment; the cumulative effect is a review step that provides no actual protection by the time a real mistake does show up.

A simple check

Periodically, deliberately insert a known error into a draft before it reaches the reviewer, without telling them in advance, and see if it gets caught. If it does not, the review process needs attention regardless of how good the recent track record has been.

Why this discipline tends to fade without a check

Review discipline rarely collapses all at once. It erodes one skipped check at a time, each one individually reasonable given a busy week and a string of recent drafts that turned out fine. The planted-error test described above is valuable precisely because it interrupts that gradual erosion before it reaches the point where a real, consequential mistake gets through, and it does so without requiring anyone to admit the discipline had already started slipping.

A lightweight way to run the planted-error test without disruption

This does not need to be an elaborate exercise, a compliance lead inserting one deliberately wrong figure into a routine internal draft once a quarter, and simply noting whether it gets flagged, is enough to give a firm an honest read on whether its review discipline is holding. The test only works if it is genuinely unannounced and repeated periodically, not run once and treated as a permanent reassurance.

Where this leaves a firm

None of this is complicated in principle, which is exactly why it gets skipped under deadline pressure. The question worth returning to before treating handling client data and AI risk with real discipline as settled is what a careful reader would actually notice if the firm got it right. On the point raised above under “signs the process is working,” the answer is usually specific rather than clever: a working review process produces occasional, specific, factual corrections, not just tone edits. Firms that build this expectation into how they train new associates find it easier to sustain once experienced staff move on, because the standard lives in a documented habit rather than in one person's memory. The gap between a firm that talks about handling client data and AI risk with real discipline and a firm that actually practices it shows up over several quarters, not in any single engagement, and it tends to show up most clearly in the small, unglamorous checks that a client never sees directly but benefits from anyway.

It also helps to name, plainly, who is responsible for keeping this working once the novelty of a new tool wears off. Someone should own the point raised under “signs it has become a rubber stamp,” check it periodically rather than assume it stays true on its own, and be the person a colleague asks when a new situation does not fit the pattern described here. Put simply: periodically test the review process with a planted error to confirm it still works. That kind of ownership, named and specific, is a small addition to a firm's process, and it is usually the difference between a good idea that is followed for a month and a standard that actually holds up over a year of real client work.

None of this needs to be elaborate to be effective. A short, dated note in a shared file, reviewed at the next quarterly check-in, is usually enough to keep the responsibility from quietly disappearing when the person who first cared about it moves on to something else.

Key takeaways

  • A working review process produces occasional, specific, factual corrections, not just tone edits.
  • A rubber-stamp process approves everything as written and catches nothing.
  • Trust built from good drafts tends to erode review discipline gradually, not suddenly.
  • Periodically test the review process with a planted error to confirm it still works.