Unit 11 / 11

Data Privacy, Authentication, Ethics and Governance

Gains:

  • Ability to protect data in four layers (classification, anonymization, vehicle selection, minimum data) and fulfill the KVKK responsibility
  • Ability to verify outputs according to risk level and filter recommendations that affect people through fairness and bias
  • Ability to establish a simple AI governance framework and ensure that AI output does not replace expert approval in financial/legal/HR/compliance decisions

As a manager, you have learned to use AI in every corner of your business: reporting, KPI, automation, operations, procurement, communication, summary, scenario. Now we are establishing the framework for using this power responsibly. Because when AI is used incorrectly, speed and convenience turn into serious risks: a leaked customer list, a decision based on a made-up number, a discriminatory suggestion, a KVKK violation. This unit is the safety net that holds the entire module together. The main principle in one sentence: AI is an assistant; The confidentiality of the data, the accuracy of the output and the ethics of the decision are always the responsibility of the manager.

Data privacy: four layers of protection

Business data is valuable and much of it is confidential. Protect privacy in four layers. First layer—classification: label each piece of data as “public/internal use/confidential/personal.” Confidential and personal data requires special attention. Second layer — anonymization: Translate identifiers such as name, ID, customer name, supplier price into codes before giving them to the AI ​​(Employee A, Customer 1). Third layer — tool selection: if possible, use company-approved corporate AI tools that do not store data for model training; Do not provide confidential data to free publicly available tools. Fourth layer — minimal data: give the minimum data needed to do the job, no more.

KVKK (Personal Data Protection Law) regulates your processing of employee and customer personal data; Violation brings both legal sanctions and loss of reputation. Pasting a client list or payroll into an open chat box is like leaving a locked file on the street.

Caution: "This tool appears safe" is not an assurance. Before giving any data to AI, ask: "What would be the harm to the company if this information leaked out?" If the damage is serious, either anonymise the data or do not release it at all. If in doubt, don't give.

Validation: unsigned output is not a decision

The discipline repeated throughout the module is gathered under one roof here. Validate each AI output in three steps: source (is the number from the data I provided?), recalculate (check the arithmetic), managerial filter (does it match my industry knowledge and field?). AI can produce hallucinations — inventing non-existent numbers, sources, or facts with persuasive language. Fluency is not accuracy. The more important the decision, the more rigorous the verification must be.

Consider risk on three levels. Low-risk deliverables (internal outline, formatting, summary): a quick look is sufficient. Medium risk deliverables (report to management, KPI comment): every number is validated. High-risk deliverables (financial decision, contract, compliance document, HR transaction): AI only produces drafts; Competent expert review, legal/financial control and signature are mandatory. In these areas, AI output can never replace competent expert approval.

Ethics and bias: fast but fair

AI learns from historical data; If there is a past bias, AI will repeat or even reinforce it. A hiring, promotion, or customer prioritization recommendation may unwittingly disadvantage a group. So put every AI proposal that affects humans through the filter of fairness: "Does this proposal unfairly exclude a group? Is the justification defensible?" Ask the AI ​​explicitly "which groups might be disadvantaged by this proposal?" ask.

Two more ethical principles: Transparency — Do not hide significant AI-generated output; You should be able to explain how the decision was made. Accountability — “The AI ​​said so” is not an excuse. The responsibility lies with the manager using the tool. When AI makes a mistake, you hold the accountable; so use him as a supervised assistant, not a blind authority.

AI governance: an institutional framework

Individual good will is not enough; Establish a simple AI governance framework for the business: what data can be given to which tool, which decisions can be supported by AI, which belong only to the expert, how the outputs are validated, who is responsible. A written, simple policy protects the entire team and prevents disaster on the next unit.

three mini cases

Case 1 — Returning from the brink of leakage. A sales manager would paste a list with real customer names and turnovers into a free AI tool. In a moment of hesitation, he asked, "What would happen if this leaked?" he asked, coding the customer names and converting the turnovers into tape. The analysis came out with the same quality; no real data went out. A small habit prevented a major KVKK risk.

Case 2 — The cost of the made-up number. A chief financial officer presented an "industry average of 23 percent" figure given by YZ to the board without verifying it. The number was made up; The AI ​​had convincingly produced a number that had no source. An investment controversy based on the wrong figure ensued and took time to reverse. Lesson: not every number that claims to come from outside can be used without connecting it to the real source.

Case 3 — Catching biased recommendation. An HR manager asked the AI ​​to rank candidates. The AI ​​would highlight graduates from a particular school based on historical data. The manager asks “what groups does this proposal exclude?” he asked; He found that AI repeats past bias. He based the rankings solely on job-related, defensible criteria and left the final decision to the people committee.

Four copyable templates

1) Data privacy screening:

Your role: data privacy advisor. I'll give you a data set in a moment. First, list the personal/confidential fields (name, ID, customer, price, salary) and suggest how to anonymise each of them. Briefly write down the risks of giving this data to AI in terms of KVKK. Do not analyze yet.

2) Verification checklist:

I need to verify the following AI output before presenting it to management. List each numerical claim and external source claim in the output. For each one, ask "is the source of the data I provided or is it information that the AI may have produced/fabricated itself?" Collect those with unknown sources under the 'VERIFY' heading.

3) Ethics/justice filter:

The following AI proposal affects people: [proposal].Which groups might this proposal unfairly disadvantage? Could the recommendation be biased by historical data? What should I change to base the decision solely on business-related, defensible criteria? Be honest, don't defend the suggestion.

4) AI use risk classification:

I will perform the following task with AI: [task]. Place it at risk level: low (internal draft), medium (outgoing to management), high (financial/legal/HR consequence). Tell me what verification and approval steps are required based on the risk level. If it is high risk, remind that expert approval is mandatory.

Weak prompt / Strong prompt

Weak prompt:

Give me an analysis with this customer data. [real named data]

Provides real personal data to the open tool; It carries the risk of KVKK violation and leakage. There is also no plan to validate the output.

Powerful prompt:

Your role: analyst. In the data I gave you, all names are coded (Customer 1-50) and amounts are converted into tape. Perform segment analysis with this anonymous data. Just use the numbers I gave, do not add external sector numbers; If you add it, please state the source clearly so I can verify it.

Size

poor approach

Strong approach

Data

real name

anonymous

KVKK risk

high

low

source control

None

mandatory

Verifiability

low

high

Responsibility

uncertain

clarified

Common mistakes

  • Giving real confidential/personal data to open tool. Classify and anonymize first.
  • Not verifying external source claims. AI can make up numbers like “industry average”; connect to source.
  • Ignoring prejudice. Put proposals that affect people through the filter of fairness.
  • The "AI said so" excuse. The responsibility lies with the user; Assume accountability.
  • Skipping expert approval on high-risk decision. Financial/legal/HR/compliance output requires expert approval.
Caution: The most important sentence of this module: AI output in consequential areas such as compliance, finance, legal and human resources is NOT a substitute for competent expert approval. AI increases your speed, it does not fire your expert. An unverified AI output is as risky as an unsigned decision.

In summary

Responsible AI use rests on three pillars: privacy, authentication, and ethics. Protect data in four layers (classification, anonymization, tool selection, minimum data) and remember KVKK responsibility. Validate each output with source linking, recalculation, and administrative filtering; Increase diligence based on risk level. Put proposals that impact people through the filter of fairness and maintain transparency and accountability. A simple AI governance framework protects the entire team. And always: in high-risk, consequential areas, AI is no substitute for competent expert approval.

Application task

Write a half-page draft of the "AI usage guidelines" for your own business. Include: what data can be given to which tool, how the data will be anonymised, which outputs should be validated, which decisions belong solely to the expert and who is responsible. Using the “AI use risk classification” template above, place the 5 tasks you have done with AI in the last week into the risk level and write the correct verification step for each.

checklist

  • [ ] Have I classified and anonymized the data?
  • [ ] Did I use a company approved/secure tool and minimum data?
  • [ ] Have I validated each output against risk level?
  • [ ] Have I filtered the proposals that affect people through fairness?
  • [ ] Have I required expert approval for high-risk decisions?

Module Exam

1. What question should a manager ask to determine the layer of work (mechanical / analytical / decision) and verification rigor before outsourcing a job to AI?

  • A) What will be the result if this output is wrong? ✔
  • B) Can artificial intelligence finish this job as quickly as possible?
  • C) Is this tool free?
  • D) Has this job ever been done before?

Description: The basis of correct use is to classify the job according to the level of risk. 'What will be the consequence if this output is incorrect?' The question determines whether the work is mechanical, analytical, or a responsible decision and therefore how much verification is required.

2. An 'industry average of 23 percent' figure given by artificial intelligence is presented to the board of directors without verification and it turns out that the figure is fabricated. What basic discipline was overlooked in this case?

  • A) The rule of using artificial intelligence only in the morning hours
  • B) The discipline of verifying the output by connecting it to the source ✔
  • C) Converting the report to a color table
  • D) Writing a longer prompt

Explanation: Artificial intelligence sometimes produces a non-existent number in a convincing language (hallucination). The step of connecting the output to the source checks whether each number comes from a real source or may have been made up. When this is omitted, there is a risk of wrong decisions.

3. While the total turnover in an e-commerce company appears stable, the segment breakdown reveals that a high-profit category decreased by 22 percent, and low-profit sales mask this. What principle does this example illustrate?

  • A) Total number is always the most reliable indicator
  • B) Profitability is unimportant, only turnover is important
  • C) Total numbers can hide reversals; segment breakdown reveals the truth ✔
  • D) Segment analysis is only valid for large companies

Explanation: Total numbers can hide internal reversals. Looking at the breakdown (segment analysis) rather than the total in decision support work reveals the truth; Large variations may be hidden under a fixed total.

4. A cafe manager interprets the finding that 'weekend sales move with the temperature' as 'hot weather increases sales' and turns down the air conditioning; However, the real reason was the increased customer traffic over the weekend. What is this error?

  • A) Mistaking correlation for causality ✔
  • B) Not collecting enough data
  • C) Choosing the wrong chart type
  • D) Not anonymizing data

Explanation: Just because two things act together (correlation) does not mean that one causes the other (causation). Temperature and sales coincidentally moved in the same direction; The common reason was weekend traffic. The relationships found by artificial intelligence are not evidence, but hypotheses to be tested.

5. What is at the top of the 'pyramid' structure of a good management report?

  • A) Raw data tables
  • B) Executive summary ✔
  • C) Additional documents and footnotes
  • D) All figures from previous years

Explanation: A good report is a pyramid: at the top, the executive summary (3-5 bullet points) designed for the busiest reader to understand in 30 seconds; critical findings below; At the bottom is the supporting detail. Thus, the top manager only reads the top, and anyone who is curious comes down.

6. When a call center makes 'number of answered calls per day' a KPI, representatives rush the calls and reduce customer satisfaction. What principle does this situation illustrate?

  • A) The more KPIs, the better the management
  • B) KPIs cannot be used in call centers
  • C) Speed always comes before quality
  • D) A KPI that can be manipulated may encourage adverse behavior rather than the outcome it is intended to measure ✔

Explanation: When an indicator becomes a target, people find ways to deceive it (Goodhart's Law). 'Call count' is easily manipulated and does not measure actual outcome (resolution, satisfaction). So before choosing a KPI you should ask 'what adverse behavior does it encourage?' should be asked.

7. What is the reason for the 'simplify the process first, automate later' rule in process automation?

  • A) Automation also accelerates failure in a broken process; The process must be corrected first ✔
  • B) Simplification makes automation impossible
  • C) Simplification is only a legal obligation
  • D) Automation is always cheaper than simplification

Description: Automation increases the speed of the process; It also accelerates the error if the process is corrupt. When the 5 unnecessary step process in an accounting unit was automated, the unnecessary steps just worked faster. First the process should be simplified, then accelerated.

8. What is the purpose of 'human-in-the-loop' design in automatic responses to the customer?

  • A) Stopping automation completely
  • B) Increasing the decision authority of artificial intelligence
  • C) Preventing the error from escaping with human approval at the critical point while maintaining most of the speed ✔
  • D) Completely eliminating the human workforce

Explanation: Human-in-the-loop design is a human approval at the critical point of the automated process. The AI ​​produces the draft, the human quickly approves it, then it is sent. This prevents a bug from going straight out while preserving most of the speed; When a team removed this approval, incorrect information reached the customer.

9. Production is slow in a furniture workshop; The manager wants to replace the most expensive machine (cutting), but analysis shows that the bottleneck is the dyeing-drying step. What is the basic principle of operations analysis?

  • A) The most expensive step should always be improved
  • B) Improvement should be targeted at the bottleneck that slows down the entire flow ✔
  • C) All steps should be accelerated equally
  • D) The concept of bottleneck is valid only on production lines

Explanation: The speed of a process is the speed of its slowest step (bottleneck). Accelerating steps outside the bottleneck is a waste of money and effort; The only thing that works is to widen the bottleneck. When the manager invested in a second drying oven instead of slaughtering, the speed increased by 28 percent.

10. In purchasing, a manager switches to the cheapest raw material supplier but ignores the supplier's poor delivery reliability; Two major delays are halting production. What is the lesson from this situation?

  • A) The most expensive supplier should always be chosen
  • B) Delivery reliability is irrelevant
  • C) The supplier should not be evaluated in one dimension (only price), but in multiple dimensions, including reliability and risk ✔
  • D) Supplier decisions should be left solely to artificial intelligence

Description: Supplier selection is multidimensional: price, quality, delivery time, reliability, financial soundness and risk must be evaluated together. Just looking at the price can lead to losses many times greater than the discount earned; lost production wiped out the discount.

11. What is the best thing for a manager to do before sending an angry, harsh email to a team that is constantly late?

  • A) Sending the message as it is, because emotions are real
  • B) Making the tone solution-oriented with artificial intelligence and then passing it through a human filter ✔
  • C) Not sending the message at all and ignoring the problem
  • D) Making the message stronger

Explanation: Messages written when angry should not be sent immediately. Telling the artificial intelligence 'change the tone to a respectful and solution-oriented tone while maintaining the same expectations and boundaries' preserves the essence of the message, corrects its tone and prevents hard-to-recover resentments; The output is then human-filtered.

12. A meeting summary says AI 'budget increase approved'; However, it was said at the meeting that 'the budget increase will be evaluated'. What is the right way to avoid this danger?

  • A) Distribute the summary immediately without reading it
  • B) Verify the summary, separate the decision from the possibility and have it confirmed by the participants ✔
  • C) Not making the meeting summary at all
  • D) Considering only the longest sentence as a decision

Description: AI may misattribute decisions; The difference between 'to be evaluated' and 'approved' is crucial. The meeting summary is often the 'official memory', so each summary should be read, differentiated from decision, and confirmed with participants before being distributed.

13. In scenario planning, what is the purpose of establishing at least three scenarios (optimistic, basic, pessimistic) instead of tying the future to a single prediction (for example, 'we will grow by 15 percent')?

  • A) Artificial intelligence can predict the future precisely
  • B) No matter which direction the truth goes, not to be caught off guard and put the plan into action instead of panic ✔
  • C) Collect less data
  • D) Choosing a single correct future in advance

Explanation: Reality is an interval; If the plan based on a single guess is not realized, it will collapse. Preparing responses to multiple scenarios in advance ensures that a plan can be put in place rather than panic, no matter which way reality moves. The aim is not to know the future, but to not be caught unprepared.

14. Which of the following is true about the use of artificial intelligence in business management?

  • A) Artificial intelligence output does not replace competent expert approval in decisions that have financial, legal and HR consequences ✔
  • B) If the artificial intelligence output is correct, there is no need for expert approval
  • C) Real customer data can be given to open tools as long as it appears safe
  • D) 'AI said so' is a valid justification for accountability

Disclosure: AI output is not a substitute for competent expert approval in consequential areas such as compliance, finance, legal and human resources. Artificial intelligence is a speed-increasing assistant; The confidentiality of the data, the accuracy of the output and the ethics of the decision are always the responsibility of the manager. An unverified output is as risky as an unsigned decision.