Answer · Self-built AI solutions

We have already built our own AI solutions — who checks them?

The short answer: an Operator Review. An independent check of your self-built AI solutions covering data protection, maintainability and risk — with an honest verdict on what can stay and what has to go. And that uneasy feeling? It is a good sign: something is running that nobody fully oversees any more.

Porträt von Matthias Eger — Experte für KI & IT im Mittelstand, Weiden in der OberpfalzAuthorMatthias EgerCertified Manager for Applied AI Transformation (IHK)
Last reviewed17 Jul 2026
To the verification record

That uneasy feeling is a good sign.

Because it means something has grown in your business. Your people built instead of waiting — that is the fastest route to improvement, and plenty of companies sleep through exactly this moment.

The problem is not that something was built. The problem is that nobody holds the whole map any more: which tools are running, which data they see, who maintains them — and what happens when one of them produces nonsense. That is precisely the feeling nagging at you. Listen to it.

The real risk

Not the AI itself — but what has grown up around it unchecked: customer data in other people's systems, processes that hang on one person, results that go out unchecked in the company's name. Each one an annoyance. Together, a liability case.

What the Operator Review checks.

Three levels, one written result:

  • Data protection: Which data flows into which systems — and is that allowed? GDPR, provider terms, data processing agreements.
  • Maintainability: Does it keep running once the person who built it leaves? Documentation, access, dependencies on tools and on people.
  • Risk: What happens when the AI gets it wrong? Who checks before anything goes out — and who is liable if nobody does?

At the end you get an honest verdict in plain English: what can stay, what needs safeguarding — and what has to go. Even if someone built it with real dedication. The review is the way into the Operator — the ongoing support with accountability for the judgement. But it also stands on its own: having it checked does not mean having to book.

“What holds up, stays. What endangers the business has to go — no matter who built it.”

Checklist

How do you know
a review is due?

Five signs from real projects. One on its own is a hint — two or more are an appointment.

01

Only one person understands the system.

The apprentice built it, the contractor is gone, the colleague is on holiday — and nobody else knows how it works. If a process hangs on a single head, your business hangs with it.

02

Nobody can say where the data goes.

Customer names, costings, perhaps health data — which tools do they end up in, on whose servers, under whose terms? If the answer is a shrug, the review is due.

03

There is no documentation and no managed access.

Passwords in people's heads, accounts on private email addresses, no overview of what runs where. That is not a state of affairs — that is a bet on the next staff change.

04

Results go out unchecked.

AI texts, answers or figures leave the building in the company's name without a human approving them. One wrong statement is enough — and you answer for it.

05

It grows faster than anyone can keep up.

A new tool every week, a new automation — but no rule about who is responsible for what. Sprawl scales too. That is exactly where the uneasy feeling comes from.

Recognised two or more of these? Then let's talk for 30 minutes — free of charge

Frequent questions

What owners want to know before the review.

What exactly does an Operator Review check?

Three levels: data protection (which data flows into which systems — and is that allowed?), maintainability (does it keep running once the person who built it leaves? documentation, access, dependencies) and risk (what happens when the AI gets it wrong, and who checks before anything goes out?). The result comes in writing.

Do I have to throw away what we built ourselves afterwards?

Usually not. Most self-built work is well thought out and only needs guardrails: rules, documentation, properly managed access. Only what seriously endangers data protection or operations has to go — and I will tell you that plainly rather than talk around it.

How does a review work?

First a free 30-minute initial assessment, then the check of the solutions running in day-to-day operations: data flows, access, documentation, responsibilities. After that you have it in writing — what stays, what has to go, what comes first. Where it goes from there is your decision.

An honest verdict instead of an uneasy feeling.

Review · Data protection, maintainability, risk · Result in writing

Request a review
Get in touch