The Operational Framework
for Automated Decisions.

Four duties every automated decision inherits — competence, candor, recourse, non-abandonment — rooted in a professional obligation of trust and the highest duty of care. This is the reference your team writes its own Automation Style Guide against.

Four dutiesDrawn from medicine & lawA framework your team adapts

The duties are quick to agree. The hard part is who they belong to.

Most teams nod at all four inside a minute. The difficulty is that the decision they govern belongs to no single function — engineering sets the threshold, product owns the funnel, risk carries the exposure, legal weighs the defence, support takes the call. Each holds a real piece; none holds the whole.

So the Standard isn't a policy from one corner. It's the reference the whole room reads the same way — duty by duty, with a plain test for each. Soma has built a framework that makes it easy and functional for your team to write its own — in a day.

Standard · Article I

Competence

First, do your best
Whose call it is
EngineeringData ScienceRisk

Framework · I

The decision must meet a real standard — sound, current, and fit for the person it concerns — not merely whatever the model returned.

I.AWould a competent professional, in full view of this person's case, stand behind the decision?
I.BHas it been tested on the people it will actually affect — not just a benchmark?
I.CWhen the evidence is thin, does the system say so?
MetThe system decides at least as carefully as a conscientious professional would — tested on the real population and its hardest cases, and honest when the evidence is thin.
Breach
Engineering breach

Ships because the average score looks good — and never checks the hard cases it quietly fails.

Data Science breach

Validates on clean benchmark data, then releases onto a population the model never saw.

Risk breach

Signs off on aggregate accuracy without asking who the system fails, or how badly.

Team barTogether, we set the bar this decision must clear — and how we'll know it still holds. Written in the workshop.
Standard · Article II

Candor

Informed consent
Whose call it is
ProductDesignLegalComms

Framework · II

The person has a right to know that a machine decided, and to understand the grounds in terms they can act on.

II.ADo we tell the person a machine was involved in the decision?
II.BDo we give a reason specific enough to act on?
II.CIs our explanation written for the person, not the auditor?
MetThe person is told plainly that a machine decided, given a specific reason they can act on, in language written for them — not buried in terms.
Breach
Product breach

Designs a flow where the decline is silent — the person never learns a machine made the call.

Design breach

Surfaces a generic “does not meet our criteria,” with no reason a person could act on.

Legal breach

Hides behind “proprietary” and buries the disclosure in terms no one reads.

Comms breach

Writes the notice for the regulator, not the person it lands on.

Team barTogether, we set what we tell people, and how. Written in the workshop.
Standard · Article III

Recourse

The second opinion
Whose call it is
SupportOperationsProduct

Framework · III

Every automated decision needs a door back to a human with the authority to look again, and to overturn.

III.ACan the person reach a human able, and permitted, to reverse it?
III.BIs the way to ask for review obvious, not hidden?
III.CCan they contest it without exhausting themselves?
MetThere’s a clear, reachable path to a human empowered to look again and overturn — obvious to find, and not exhausting to use.
Breach
Support breach

Takes the call but has no authority to change anything, and no one to escalate to.

Operations breach

Routes the appeal straight back into the system that already said no.

Product breach

Buries the path to review, or makes it take more steps than anyone will spend.

Team barTogether, we build the way back to a human. Written in the workshop.
Standard · Article IV

Non-abandonment

Continuity of presence
Whose call it is
RiskEngineeringThe named owner

Framework · IV

One does not deploy and walk away. The duty continues for as long as the system decides.

IV.AAfter launch, who owns what the system does?
IV.BWould anyone notice if it began harming a group?
IV.CWhen something goes wrong, how fast are people reached?
MetA named owner watches the live system for drift and harm, with thresholds that trigger action — and a plan to reach those affected before harm compounds.
Breach
Risk breach

Signs off at launch and never looks again as the population shifts.

Engineering breach

Ships with no monitoring for drift or disparate impact once it’s live.

Named-owner breach

No one is actually named — so when it starts failing a group, no one notices.

Team barTogether, we name who watches it, and what triggers action. Written in the workshop.
Where these come from

Drawn from the duty-of-care tradition in medicine and law.

These four are not invented from nothing, and Soma does not claim them as an official framework. They are a considered adaptation — drawn from the way medicine and law have long organised the care a professional owes a vulnerable person, and translated for systems that now decide at scale.

Soma's contribution is to carry them across — from a practitioner caring for one person, to an automated system deciding for many — and to state them plainly enough to be held to.

  • Competencethe professional duty to a real standard of competence and "first, do no harm" — the duty to perform to a real standard.
  • Candorthe duty of candour and informed consent — disclosure owed to the person, in terms they can use.
  • Recoursethe right to review and the second opinion — long-held in both care and law.
  • Non-abandonmentthe duty of non-abandonment and continuity of care — a named obligation in medical ethics.
Use it · adapt it · make it yours

Use the framework. Write your own in half a day.

Use the Standard as your reference — for internal policy, a vendor review, or documenting a system. Then bring your team into a room and leave with one written for your products.

Soma, The Standard of Conduct for Automated Decisions (2026). somastandard.org. Four duties: competence, candor, recourse, non-abandonment.
Book a workshop Your team writes its own, together