Unit 12 / 12

End-to-End Workflow, Governance and Responsible Use

Gains:

  • Ability to consistently embed AI at every stage from application to close with six human verification gates
  • Ability to establish a corporate governance framework with approved tools list, data policy, roles, registration, training and ongoing review
  • Ability to embed the principles of human responsibility, verification, privacy/KVKK, adherence to evidence, bias control and client-centeredness into the workflow

Throughout this module, we covered how to use artificial intelligence and where to stop it in different tasks of social work — documentation, assessment, risk support, referral, plan, report, communication, program design. In this final unit, we put the pieces together: where AI will sit end-to-end from application to closing of a case, which human verification door stops at each stage, and we will establish the governance framework needed for this to be sustainable in an organization. The goal is to turn scattered tips into a consistent and repeatable working discipline.

Integrative principle from the start: AI is an accelerator at every step of the workflow, not a decision maker at any step. There is a human door at each stage, and you cannot move on to the next without passing through one door. This layered structure prevents a single hallucination, bias, or privacy error from seeping into a decision that affects a client's life.

End-to-end flow and six human gates

Let's consider a case through its typical stages and place a verification gate at each stage:

1. Application / first contact — Door: Privacy. When the first information comes, AI is used for interview preparation (guide, question frame). Door: No actual client data enters the open tool; Ask for class, match vehicle.

2. Assessment — Gate: Clinical judgment. AI organizes notes into biopsychosocial dimensions and reminds of shortcomings and strengths. Door: Diagnosis and evaluation belong to the specialist; AI does not evaluate.

3. Risk — Door: Authority and team. AI reminds of risk/protective factors and creates a security plan skeleton. Door: Risk decision is made only by expert, team, supervision and legal process; AI does not produce scores/decisions.

4. Planning and guidance — Door: Validation and client. AI puts the goals into SMART, generates resource ideas and letter drafts. Door: The client sets the goals; The service/address/condition is verified from the official source.

5. Report and communication — Door: Evidence and accountability. AI structures the report, simplifies and translates the text. Door: Every case depends on evidence, the opinion belongs to the expert, critical information loss and bias are checked, the signature is in the person.

6. Closing and handover — Gate: Accuracy. YZ summarizes the file chronologically. Door: The summary is based on the record alone; The results and learnings are verified by the expert.

Tip: Use a single question to remember the doors: “In this step, does the AI ​​make a decision or produce a sketch?” If the answer is “decision,” stop — that step belongs to the human. If the answer is "draft", continue, but do not move to the next step without verifying the output.

Corporate governance: individual discipline is not enough

The good habits of an expert are valuable but fragile; Safe and consistent use of AI in an organization requires a governance framework. The key components of this framework are:

  • Approved vehicle list. It is written and clear which tool will be used for which job and which data can be entered into which tool. "Everyone should use whatever tool they want" is a security vulnerability.
  • Data classification policy. It is defined which data will be processed in the open tool and which will be processed only in the secure system.
  • Role and authority. It is clear who can do what and which decision depends on which authority (especially risk decisions).
  • Log and audit trail. Where and how AI is used can be monitored; When there is a problem, it can be looked back.
  • Education and awareness. Every employee knows the principles in this module; The newcomer is trained.
  • Constant review. Tools, risks and legislation change; The framework is updated regularly. Policy once written and forgotten becomes obsolete.

three mini cases

Case 1 — Doors caught a bug at the beginning of the chain. In one case, AI added an observation that the client did not mention during the evaluation phase. At the gate of "clinical judgment" the expert caught this and deleted it. If he had not been caught, this fabricated observation could have leaked into the plan, from there to the report, and from there to a court decision. Layered authentication stopped the error at the earliest point.

Case 2 — Governance prevented a breach. One organization was operating without an approved tool list and data policy; Everyone was using their own vehicle. An audit revealed that several employees were entering actual client data into open tools. The organization has established a governance framework: approved tools, data classification, training and registration. In the following period, the number of violations dropped to zero. Lesson: individual good will is not enough without institutional structure.

Case 3 — Continuous review kept up to date. An organization's AI policy, written a year ago, was outdated in the face of a new type of tool and updated legislation. The annual review captured this; The policy was updated, the training was renewed. The frame remained a living document, not a shelf ornament.

Four copyable templates

1) Case flow verification gate checklist:

Your role: supervisor. I get a validation checklist for the following case step: what can the AI draft in this step, which decision is necessarily human, what privacy and bias checks should be done, what should I verify before moving on to the next step? Step: [application / assessment / risk / plan / report / closure]

2) Confirmed vehicle matching:

For each of the task lists below, specify the type of AI tool that can be used (open tool / secure enterprise system only / No AI available) and justification. Mark each task containing client data as "secure system only".Tasks: [list tasks]

3) Corporate AI policy draft:

Your role: corporate policy editor. Draft a responsible AI use policy for a social service agency; Cover the following topics: purpose, approved tools, data classification, roles and authorizations, privacy/KVKK, risk decision limit, recording and auditing, training, review schedule. Set up the general framework; The institution will fill in its own details.

4) Self-regulation (personal usage review):

Create a self-checklist of 10 questions for me to review my use of AI as a social worker: privacy, verification, bias, evidence fidelity, decision limits, and client-centeredness. Let every question be answered with "yes/no".

Weak prompt / Strong prompt

Weak prompt:

I give you the whole of this case; You handle everything from the application to the report, I'll just sign it at the end.

This is outsourcing the entire process—including privacy, clinical judgment, risk judgment, adherence to evidence—to software. The single signature at the end blinds us to all the errors, fabrications, and biases in between.

Powerful prompt:

Your role: editor who helps me every step of the way. I will proceed with the case step by step (assessment, plan, report...). At each step: work only with anonymous/secure data, produce a draft, let me decide, don't add what isn't in the note, and remind me what I need to verify before moving on to the next step. Let's start with this step: [step]

The difference: guarding the door at every step and positioning the AI as a step-by-step assistant keeps safety and responsibility human while maintaining speed.

Stage-gate-responsibility summary

Stage

Contribution of AI

human gate

critical control

Application

Interview preparation

privacy

Data class

Evaluation

Size editing

clinical judgment

No diagnosis, no fabrication

Risk

Factor reminder

Authority + team

No score/decision

Plan/guidance

draft + idea

Validation + client

Source confirmation, client priority

Report/contact

Structure + simplification

Evidence + responsibility

Opinion in expert, bias control

Closing

Chronological summary

accuracy

record-based

Common mistakes

  • Handing over the entire process to AI and signing a single signature at the end. The errors in between are not visible; There should be doors at every step.
  • Passing through a door without verifying it. The fabrication of one stage is inherited by the next; Every output is validated.
  • Leaving governance to individual discipline. Without an institutional framework, good habits are fragile.
  • Write the policy once and forget it. Tools and legislation change; Constant review is necessary.
  • Not keeping records. Without an audit trail, a problem cannot be looked back on and cannot be held accountable.

In summary

In social work, AI is a catalyst at every step, a decision-maker at no step, from application to closure of a case. Place six human gates (confidentiality, clinical judgment, authority/team, validation/client, evidence/accountability, integrity) into the end-to-end flow; Do not pass from one door to another without passing through. Making this sustainable requires corporate governance: approved tools list, data policy, roles, registration, training and ongoing review. The module's six driving principles—human responsibility, verification, privacy/PDPA, commitment to evidence, bias control, and client-centeredness—should be woven into every workflow.

Application task

Mentally chart a fictional case from application to closing; Produce a checklist for each stage with a “case flow verification gate” template. Then classify the tasks in this case as open vehicle / secure system / no AI with the “validated vehicle matching” template. Finally, evaluate yourself by creating a list of 10 questions for your own use of AI with the "self-audit" template.

checklist

  • [ ] I have identified six human gates in the end-to-end flow.
  • [ ] At every step, "decision or draft?" I applied the question.
  • [ ] I matched the tasks to the correct vehicle type (open/safe/none).
  • [ ] I know the corporate governance components (tool, data, role, registration, training, review).
  • [ ] I implemented the module's six carrier principles into my own workflow.

Module Exam

1. Which of the following is the most accurate positioning for artificial intelligence in social work?

  • A) Artificial intelligence can decide a client's risk level and intervention decision without human approval
  • B) AI is a tool for summarizing, organizing, simplifying and drafting; Responsibility for clinical judgment, risk and final decision rests with the expert ✔
  • C) Artificial intelligence is only useful for translating text and has nothing to do with other social work tasks
  • D) Since artificial intelligence is always more impartial than humans, the evaluation should be left to it.

Description: Artificial intelligence; It is an assistant that organizes notes, summarizes the file, simplifies the text and produces drafts. Responsibility for clinical judgment, risk assessment, professional opinion and final decision rests with the competent professional; An unverified output could lead to a misjudgment of a client, a risk evasion, or the leakage of sensitive data.

2. What is the most correct instruction when having the raw notes of an interview converted into a case record by artificial intelligence?

  • A) Requesting artificial intelligence to fill in the missing parts in a reasonable manner so that it looks professional.
  • B) Allowing AI to add additional observations to enrich the record
  • C) Asking the student to use only the information actually included in the note, mark the missing items as 'needs clarification', and not add anything ✔
  • D) Putting it directly into the file without comparing it with the note as long as the output is fluent

Explanation: The most dangerous tendency of AI is to fabricate observations, numbers or quotes that are not in the note to make the record seem 'complete'. The correct approach is to say 'just use what's in the note, mark the missing ones, don't add anything'. The gaps are not filled, they are marked for clarification.

3. Why is the distinction between 'fact' and 'interpretation' important in a case record?

  • A) A fact is a concrete observation/statement, while an interpretation is a professional inference that requires basis; The two should be separated and the comment should be tagged ✔
  • B) The distinction is unnecessary; fact and comment can be written in the same way in the record
  • C) Only the interpretation matters; It is possible even if the facts are not recorded
  • D) Since artificial intelligence makes this distinction perfectly, there is no need for human control.

Explanation: 'He cried three times in the interview' is a fact; 'He was depressed' is a comment that cannot be written without clinical basis. The record foregrounds the fact and includes interpretation only with clear labeling and justification. AI can mix the two fluently; It is a person's duty to make the distinction and avoid stigmatizing language.

4. What role should AI play in deciding whether a child is safe at home or the risk level of a case?

  • A) Artificial intelligence can read the case, determine the risk level and make the security decision
  • B) The 'low risk' label given by artificial intelligence can override the expert's observation to the contrary
  • C) Artificial intelligence only reminds factors and organizes notes; Risk level and safety decision belongs to the expert, team, supervision and legal process ✔
  • D) Artificial intelligence is more reliable than humans in risk decision-making because it is unbiased.

Description: Risk level and security decision; It requires professional authority, clinical judgment, multidisciplinary team opinion, supervision and legal responsibility. Here, AI can only recall risk/protective factors and edit notes; cannot produce scores or decisions. It may also attribute systematic high risk to disadvantaged groups due to bias in the training data, so its output cannot be used as a decision.

5. What should be done when artificial intelligence gives a referral information for a client by saying 'this center, that phone'?

  • A) Confirming the address and phone number from the official and current source of the institution before giving it to the client ✔
  • B) Conveying information directly to the client as it is presented confidently
  • C) Assuming that the information is absolutely correct as long as the artificial intelligence gives a current date
  • D) Thinking that there is no need to investigate the accuracy of the information because it is mentioned somewhere.

Description: Artificial intelligence may make up services, application requirements, addresses and telephone numbers or provide outdated information; Institutions merge, move, close down. Sending the client to an unverified address will lead to a wasted journey and loss of trust. Therefore, the contact information provided by artificial intelligence must be confirmed through the institution's own official channel before being transmitted to the client.

6. Who should set goals in a response plan and what is the role of AI?

  • A) Artificial intelligence should both determine the goals and write the entire plan without asking the client.
  • B) The client (together with the specialist) determines the goals; AI puts them into SMART format and structures them, does not add new targets ✔
  • C) Goals are unimportant; The more goals the plan includes, the better.
  • D) Artificial intelligence may ignore the client's priorities because it looks professional

Description: The core value of social work is 'self-determination': the client sets goals and priorities, shaping them with expert professional knowledge. Artificial intelligence puts these goals into SMART format and suggests steps and indicators; but he cannot add new goals that the client does not say. A foreign, externally imposed plan cannot be applied to the client.

7. In a social investigation report to be submitted to the court, in which issue is artificial intelligence most dangerous?

  • A) Ability to invent non-existent dates, observations or quotes to make the report appear 'complete' ✔
  • B) Making the language of the text too formal
  • C) Writing the report shorter than requested
  • D) Alphabetical order of titles

Explanation: The most dangerous tendency of AI is to add a non-existent date, observation or quote to make the report seem 'complete'. A fabricated sentence in a court report can both mislead a decision and destroy the credibility of the expert. Therefore, each case should be connected to a real interview/observation/document, and the professional opinion should be formed by the expert.

8. Who should write the professional opinion and opinion (suggestion) section of a social investigation report?

  • A) Artificial intelligence; because it produces a more unbiased recommendation
  • B) The opinion section is never filled in when writing the report.
  • C) Artificial intelligence writes the opinion, the expert signs only at the end
  • D) Expert; professional opinion and opinion are his/her authority and responsibility, artificial intelligence only clarifies the language ✔

Statement: Professional opinion and opinion — 'this is the best interest of this child', 'this arrangement is appropriate' — is the legal authority and responsibility of the expert. 'What do I recommend to artificial intelligence?' It is not asked; A 'suggestion' he produces may be both fabricated and a transfer of responsibility. At best, artificial intelligence clarifies the language of the opinion written by the expert.

9. What is the most critical control when simplifying a heavy official help letter for a client with artificial intelligence?

  • A) Keep the text as short as possible, do not look at details
  • B) The result looks fluent and aesthetic
  • C) Verifying that no rights, conditions, amounts, dates or notices have been omitted by comparing with the original ✔
  • D) Simplification provides comfort to the client by giving him or her less information.

Explanation: Simplifying does not mean distorting; By 'shorten' or 'simplify' the AI ​​can swallow a right, condition, amount, date or notice. The client may lose his right with 'easy' but incomplete information. Therefore, the simplified text should be compared with the original and verified that no critical information has been lost, and even have the artificial intelligence list the critical elements it protects.

10. How is it correct to treat statistics produced by artificial intelligence when drafting a funding application?

  • A) Directly using the statistics given by artificial intelligence to make it look impressive
  • B) Not making the artificial intelligence make up statistics, printing [DATA REQUIRED] where necessary and putting each number from the real source ✔
  • C) Considering that the source is unimportant as long as the number is included in an application.
  • D) Assuming that there is no need to verify statistics because the AI writes confidently

Description: Artificial intelligence can make up striking but unsourced statistics; A figure without a source is almost always unreliable. A fabricated statistic in the application will both reject the application and destroy the credibility of the institution. The correct approach is to not make the AI ​​make up numbers ('Write [DATA REQUIRED]') and put each number from the real, verified source.

11. Why is it harmful to ask artificial intelligence 'explain why this family is inadequate in raising children'?

  • A) Because the question is too long
  • B) Since artificial intelligence cannot provide any information on family matters
  • C) Because it assumes the result from the beginning, artificial intelligence (flatteringly) produces an unsubstantiated and biased confirmation; The question should be neutral and balanced ✔
  • D) Because artificial intelligence will always write in favor of the family

Explanation: This question presupposes the result ('insufficient'). The AI ​​produces an evidence-free and biased text that confirms this assumption with its tendency to flatter (confirm your insinuation). A biased question creates a biased answer. Indeed, it is a neutral question that does not assume the outcome, balances both strengths and concerns, and asks only for evidence.

12. How to apply 'under angle testing' to check for bias in AI output?

  • A) Thinking about the same situation for a different group and asking 'Would this be written in the same language?' ✔ Testing double standards by asking
  • B) Accepting the first answer of artificial intelligence as neutral and not looking for another angle
  • C) Asking only questions that support the client's group
  • D) Assuming that there is no need for additional control because bias does not exist in artificial intelligence at all

Explanation: AI can write the same behavior in a different tone for different groups (e.g. 'risk of neglect' for low-income family, 'forced parent' for high-income). The inversion test is 'if the client were from a different socioeconomic/ethnic group, would this be written in the same language?' is to ask; This makes visible double standards based on stereotypes, not evidence.

13. Which is the correct approach to summarize a client's actual file (including name, address, health information)?

  • A) For speed, paste it into the nearest public AI tool and have it summarized
  • B) Processing the file without paying attention to privacy because it is short
  • C) Enter everything including health information and save only the result
  • D) Process only in a secure system approved by the institution or with de-identified text, with minimum data ✔

Disclosure: Personal data that identifies the client — especially sensitive data such as health — is never entered into a public tool that the institution has not approved; the text may be processed, stored on external servers or used in model training, and the exfiltration is irreversible. This is also a KVKK violation. This type of work is done only in in-house, secure, approved systems that do not leak data or with de-identified text.

14. Why is deleting names from a document not always sufficient to commit it to a public tool?

  • A) Deleting names is always full anonymization and makes every document safe
  • B) As long as the document is short, it is impossible to infer identity from context
  • C) A document whose name has been deleted completely falls outside the scope of KVKK.
  • D) Context (neighborhood, age, event, family structure) may reassert identity; Protection is provided by choice of tool and environment ✔

Explanation: Even if names are deleted, context (a rare combination of neighborhood, age, event, date, family structure, etc.) can make a person identifiable; He may be the only person in a neighborhood who fits the description. Real protection is not provided by masking, but by choosing the right tool and environment; The context is also personal data and uncertain information should be protected as a higher class.

15. From application to closing of a case, what is the most effective way to prevent a single AI error from leaking into the final decision?

  • A) Delegating the entire process to a single AI tool and signing only once at the end
  • B) Putting a human verification gate and pass condition at each stage (layered verification) ✔
  • C) Removing intermediate validations for speed and checking only at the output stage
  • D) Allowing each expert to use his or her own tool freely without keeping records

Description: A human verification gate is placed at each stage (application/confidentiality, assessment/clinical judgment, risk/authorization, plan/verification, report/evidence, closure/accuracy); You cannot pass through one door without passing through another. This layered structure prevents a hallucination, bias, or confidentiality error at one stage from seeping into the decision affecting a client.