A Proposed Outcome Is Not a Decision Right

Since December 2025, three AI agents inside Deutsche Bank have been assessing vendor risk evidence — retrieving the right control questions, drafting answers, proposing pass-or-fail outcomes with citations, at roughly ninety percent accuracy. The bank's own principles name what did not move: decision rights remain with trained human assessors. The interesting question is why that separation gets more necessary, not less, as the accuracy climbs.

What happens

In December 2025, Deutsche Bank put an agentic AI platform called TPRM AI into production inside Global Procurement & Vendor Management — the function that decides whether an external vendor may work with the bank, and keeps deciding it through regular reviews. Vendors submit documentary evidence; the team checks it against the bank’s control framework.

The platform runs three specialised agents in sequence. The first retrieves the right control questions for the assessment. The second drafts answers based on the vendor’s evidence. The third proposes an outcome, with citations to the exact source passages. The numbers are concrete: a manual review typically takes around thirty minutes per evidence document; TPRM AI analyses up to five documents in under two minutes. In one recurring case — business-continuity evidence split across four or five files — a three-hour manual review became about thirty minutes of AI-supported review followed by human validation.

And the bank published its accuracy: around ninety percent of recommended outcomes match human validation, with improvement expected as the system evolves.

Then comes the sentence that matters. Under the bank’s responsible-AI principles, “decision rights remain with trained human assessors.” The agents propose. A person decides.

The usual reading

Read one way, this is an efficiency story: risk assessment at a fraction of the cost and time. Read the other way, it is a maturity story — the human step is training wheels, and at ninety-five or ninety-nine percent accuracy it will come off.

The second reading contains an assumption worth pulling into the open: that the human decision is a quality check on the recommendation, and once the recommendation is reliable enough, the check becomes redundant. If that assumption were right, the decision right would be a temporary artifact of imperfect AI.

It is not, and the reason is what this case is about.

The ninety percent question

Here is the uncomfortable arithmetic. At ninety percent accuracy, reviewing every recommendation still feels obviously necessary. At ninety-nine percent, it starts to feel like ceremony — the assessor agrees with the machine ninety-nine times in a row, and the hundredth review arrives with all the alertness that ninety-nine confirmations produce. Rising accuracy does not gently retire the human step. It hollows it out while leaving it formally in place, unless the organisation has decided — as a matter of structure, not of accuracy — where the decision actually lives.

That is what makes the bank’s phrasing notable. It did not say the assessor checks the AI until the AI is good enough. It said decision rights remain with trained human assessors — a statement about where an entitlement sits, not about how good the recommendation is this quarter. Accuracy is an argument for trusting the work. It is not a mechanism for transferring the decision right. No accuracy number converts one into the other, because they are not points on the same scale.

Two different objects

Pull the structure apart and the assessment workflow is holding two things separate.

The proposed outcome. A work product: evidence read, control questions mapped, an answer drafted, a pass-or-fail suggestion assembled with citations. Its quality can be measured, benchmarked, and improved — which is exactly what the ninety percent figure does.

The decision right. An entitlement: who may turn a suggestion about a vendor into the bank’s position on that vendor. It is held by trained assessors and exercised when the bank turns a proposed outcome into its actual decision. It does not accumulate inside the recommendation pipeline, however accurate the pipeline becomes — it is assigned by the organisation, and only the organisation can move it.

Collapsing the two is the quiet failure mode of assisted decision-making: the recommendation becomes the decision by default, because disagreeing takes effort and agreement is one click. The citations in every TPRM AI suggestion cut against exactly this — they hand the assessor the means to verify rather than merely ratify, keeping the exercise of the decision right a real act instead of a formality.

Where this is heading

Deutsche Bank calls this a first milestone, with a foundation to scale into other risk-assessment areas. That scaling is where the separation will be tested. A decision right that holds at one team’s assessment volume must still be genuinely exercised — verified and accountable — at ten times the volume, when the pressure to wave recommendations through will be strongest precisely because the recommendations will be best.

The pattern is the same one this series keeps finding at money movement and asset release, now appearing one layer earlier — at the judgments that feed those actions. The systems doing the work keep getting better. The question of who may decide does not get answered by that improvement; it only gets easier to forget.

The proposition

An AI that reads the evidence, maps the controls, and proposes the outcome — at ninety percent and climbing — has produced a better and better input to a decision. It has not acquired the right to make it. That right is a different object: conferred, held, and exercised, not approached asymptotically by accuracy.

Accuracy can make the recommendation better. It cannot, by itself, transfer the decision right.