UBC — AI Solutions

Audit — Dynamic Documentation Platform

Living documentation that stays in sync with engineering, cloud, AI, and compliance activity. Documents update themselves as the organization changes.

Back to library
SOP
Fresh

SOP-AIDLC-04 — Model / Prompt Design & Guardrails

Defines model selection, prompt engineering, tool-calling patterns, and mandatory safety guardrails.

Owner: AI Platform DirectorApprover: AI Governance CouncilVersion: 3.2Updated: 12/17/1969

1. Purpose

Ensure models and prompts are designed for safety, accuracy, and alignment with the intended use.

2. Scope

All LLM, RAG, agent, and voice-agent systems.

3. Definitions

  • Guardrail — A pre- or post-processing control that prevents unsafe or off-scope outputs.
  • System prompt — The instruction prompt configuring model behaviour.

4. Roles & Responsibilities (RACI)

ActivityRACICadence
Select modelAI EngineerAI Platform DirectorGRC, CostTeamPer use case
Author system promptPrompt EngineerAI Platform DirectorSME, LegalTeamPer use case
Implement guardrailsAI EngineerAI Platform DirectorSecurityTeamPer use case

5. Procedure

  1. Select the smallest capable model that meets task requirements; document trade-offs.
  2. Author the system prompt with a versioned template.
  3. Implement mandatory guardrails: PII/PHI redaction, off-topic detection, refusal patterns, medical-emergency handoff.
  4. For tool-calling: whitelist tools, validate arguments, cap costs and rate.
  5. Publish a Model Card and Prompt Card at time of release.

6. Inputs & Outputs

Inputs

  • Approved use case
  • Curated dataset
  • Design document

Outputs

  • Model Card
  • Prompt Card
  • Guardrail implementation

7. Controls & Metrics

MetricTarget
Systems with active guardrails100%
Prompt injection escapes in red-team0

8. Exceptions & Escalation

  • Experimental models are sandbox-only and cannot process PHI or affect users.

9. Records & Retention

RecordRetention
Model & Prompt CardsLife of model + 5 years
  • SOP-AIDLC-05
  • SOP-AIDLC-06
  • SOP-AIDLC-08

11. References

  • OWASP LLM Top 10
  • NIST AI RMF Manage

12. Revision History

See the Versions tab for the full change history maintained by the Auto-Doc Engine.


Document code: SOP-AIDLC-04 · Aligned to NIST AI RMF Manage / OWASP LLM Top 10. Controlled document — reproduction outside the UBC QMS requires the Quality Manager's approval.

Suggested by AI
No suggestions right now.
Frameworks
AI Governance
HIPAA
ISO 9001