From Using AI to Governing It: How InComm Payments Built an AI Governance Engine with :Harvey:

InComm Payments logo
“:Harvey: helped us move from using AI to governing it.”

Nicole Ibbotson

Chief Privacy Officer, InComm Payments, and General Counsel, InComm Financial Services

Key Highlights

  • Turned a manual, multi-person AI approval process into an automated, evidence-based risk-rating system
  • Built a complete governance framework with Harvey: an intake form, a four-tier risk matrix, and a 70-plus page risk classification logic guide
  • Generates 5-to-10 page risk memos from a single workflow, each traceable to source contracts, security documentation, and certifications

About InComm Payments

InComm Payments is a global payments technology company connecting brands, merchants, financial institutions, health plans, and consumers across gift cards, incentives, healthcare benefits, and other financial products, processing billions in annual transaction volume. Its regulated affiliate, InComm Financial Services, operates as a financial institution. That dual identity creates a unique challenge: InComm Payments and InComm Financial Services have to move at the speed of a technology company while carrying the risk obligations of a bank. When generative AI arrived, it represented both a productivity opportunity and a governance problem. Someone had to decide which AI tools employees could safely use, which needed review, and which to prohibit.

Opportunity

InComm Payments’ early answer to that question didn’t scale. Every request meant a long manual survey, repeat vendor-onboarding questions, and multi-person subject-matter review, with little standardized documentation to show for it. The process created diligence but couldn’t keep up with demand — no consistent risk standard, no artifact library for auditors, customers, or regulators.

Nicole Ibbotson, as both Chief Privacy Officer and General Counsel, saw that the technology creating the demand could also manage it. Her legal and privacy teams already used Harvey daily for contract review, regulatory analysis, DSAR responses, and compliance research. The next step was to turn Harvey from a tool they used into the engine that governed AI itself.

Solution

“InComm Payments employees now use AI to decide which AI other employees can use,” says Ibbotson. “Harvey structures the analysis; our people keep the judgment.”

Building the governance engine

Ibbotson used Harvey to build the framework from the ground up:

  • Intake Form — captures the essential facts on any proposed AI system: ownership, prohibited-use screening, vendor documentation, data use, monitoring, security controls, and transparency. It lives in the privacy team’s OneTrust platform and drives the workflow logic.
  • Risk Rating Matrix — sorts every system into four tiers: Prohibited, High, Medium, and Low. Harvey drew on AI laws, NIST and ISO frameworks, and industry research to build it; Ibbotson then tuned the Low and Middle tiers to InComm Payments’ risk tolerance.
  • Risk Classification Logic Guide — a 70-plus page guide, generated with Harvey, that maps each intake answer to a tier and explains why. It gives reviewers a common language and a repeatable method for reaching the same conclusion on the same facts.

Together, the three turn every AI request from a bespoke policy debate into a consistent path: low-risk uses clear immediately, higher-risk uses escalate for review, and prohibited uses stop before they start.

Risk-rating Harvey with Harvey

The first system InComm Payments ran through the framework was Harvey. “It felt right to hold our own AI to the same standard we hold everyone else’s,” says Ibbotson. Drawing on InComm Payments’ intake responses, Matrix, and Logic Guide alongside Harvey’s own vendor contract and security documentation, the team generated a Harvey Risk Rating Memo — and classified Harvey as a Low Risk tool.

What made the memo credible was the evidence behind it. It tied its data-use conclusion to contractual commitments, and its security conclusion to verifiable controls — encryption at rest and in transit, SSO and MFA, role-based access, and certifications including SOC 2 Type II and ISO 27001, 27701, and 42001. “A risk memo is only as good as the evidence behind it,” says Ibbotson. “Harvey ties every conclusion back to the contract, the control, the certification — so our people can check the work, not just trust it.”

Impact

InComm Payments now runs a documented system for AI intake, risk classification, evidence-based memos, and ongoing review — one that compounds with every tool it evaluates. Business teams pursue new AI use cases without waiting for bespoke review each time, while the professionals accountable for the outcome keep the final call. Because every conclusion traces back to a source, oversight stays reviewable instead of buried in a black box.

“This isn’t about using AI more efficiently,” says Ibbotson. “It’s about building the infrastructure to decide how AI should be used in the first place.” For a company that has to innovate like a technology firm and answer like a bank, that infrastructure is fast becoming as fundamental as the payments it processes.