Even where the same Applicable Policy applies, the Evaluation Criteria required for AI Vigilance do not necessarily remain identical across Organizations. Internal Authority, Internal Policy, Risk Appetite, Business Conditions, and Operational Environment may differ, requiring actual events to be evaluated against both the Applicable Policy and the Operational Context in which it is applied.

Importantly, Applicable Policy itself must not be rewritten by Company Context. Applicable Policy remains the higher-level Institutional Requirement, while applying that requirement to the Company Context produces Company-Specific Evaluation Criteria. Threshold / Sensitivity can then be defined according to the relevant Risk or Event, specifying what constitutes a normal state and which Changes or Deviations should be Detected, Evaluated, or Escalated.

Accordingly:

Applicable Policy → Company Context → Company-Specific Evaluation Criteria → Threshold / Sensitivity → Vigilance Evaluation

This structure allows Organization-specific Operational Conditions to be reflected in Evaluation while preserving the common Institutional Requirement.

For example, consider a Company Policy requiring that Personal Information be handled according to its Purpose and Authorized Use. The same Personal Information may be evaluated as Permitted when Employee Information is used by the HR Department for Performance Evaluation through an Approved Internal AI under appropriate Authority and Purpose. By contrast, where a General Employee enters Customer Information into an External AI Service, the activity may be evaluated as Restricted or Prohibited based on Operational Context, including the User, Purpose, Authority, and AI Environment.

This distinction means that AI Vigilance does not evaluate Information or Actions solely through fixed Categories. Even within the same Information Class, the Governance meaning may differ depending on who uses the information, for what Purpose, under what Authority, and through which System. Vigilance Evaluation therefore requires Company-Specific Evaluation Criteria that connect Policy with Operational Context.

This structure allows each Organization to maintain its own Internal Governance while conducting Evaluation without losing Alignment with higher-level Applicable Policy. Explicit Threshold / Sensitivity settings also make it possible to define, according to Organization-specific conditions, which Changes or Deviations should be Detected as Signals and at what stage they should be Evaluated or Escalated.

Company-Specific Evaluation Criteria do not modify Applicable Policy. They provide the contextualization layer that makes it evaluable within an Operational Context. This connects common Institutional Requirements with actual Organization Operations and transforms AI Vigilance into an operationally applicable Evaluation Function.