AI Assistant for Corporate Regulations and Policies

We design and deploy artificial intelligence systems: from prototype to production-ready solutions. Our team combines expertise in machine learning, data engineering and MLOps to make AI work not in the lab, but in real business.
Showing 1 of 1All 1564 services
AI Assistant for Corporate Regulations and Policies
Medium
~1-2 weeks
Frequently Asked Questions

AI Development Areas

AI Solution Development Stages

Latest works

  • image_website-b2b-advance_0.webp
    B2B ADVANCE company website development
    1358
  • image_web-applications_feedme_466_0.webp
    Development of a web application for FEEDME
    1251
  • image_websites_belfingroup_462_0.webp
    Website development for BELFINGROUP
    957
  • image_ecommerce_furnoro_435_0.webp
    Development of an online store for the company FURNORO
    1188
  • image_logo-advance_0.webp
    B2B Advance company logo design
    646
  • image_crm_enviok_479_0.webp
    Development of a web application for Enviok
    929

Imagine: a company of 500 people, 23 regulations, monthly updates. Employees spend 20 minutes searching for answers in PDFs, HR answers the same questions 2-3 hours a day. Every day, the HR department spends up to 10% of work time on regulation-related answers. Meanwhile, 40% of violations occur due to unawareness of the current document version. Corporate regulations—work schedule, security policy, approval procedures—hundreds of pages that almost no one reads. Result: repetitive HR questions, risk of violations, and wasted time. We build an AI assistant that makes regulations accessible through dialogue. An employee simply asks, and the assistant instantly finds the exact norm with the document and version. This is not just keyword search—it's a full RAG pipeline with version control and access control.

Specifics of the Regulation Assistant

A regulation assistant differs from a generic RAG in three key requirements: citation accuracy (norms verbatim, not paraphrased), currency (version control without errors), and role-based access control. These requirements affect the architecture: vector search, prompt system, and metadata filtering.

How the AI Assistant Ensures Citation Accuracy?

The assistant constructs answers based on extracted document fragments. It uses vector search (text-embedding-3-small, Chroma). The system prompt explicitly states: cite norms verbatim, do not paraphrase, always mention the document, version, and section. If a norm allows exceptions, the assistant must mention them. For the LLM we use Claude Sonnet: it handles contextual accuracy well. As stated in the citation guidelines, any deviation from the letter of the regulation is unacceptable.

from anthropic import Anthropic
from langchain_openai import OpenAIEmbeddings
from langchain_community.vectorstores import Chroma
from pydantic import BaseModel
from typing import Optional
import json

client = Anthropic()

class PolicyAssistant:

    def __init__(self, db_path: str = "./policy_db"):
        self.vectorstore = Chroma(
            collection_name="policies",
            embedding_function=OpenAIEmbeddings(model="text-embedding-3-small"),
            persist_directory=db_path,
        )

    def answer(
        self,
        question: str,
        employee_role: str,  # "employee", "manager", "hr", "admin"
        department: str = "",
    ) -> dict:
        """Answers a regulation question considering the employee's role"""

        # Access filter
        access_filter = self._get_access_filter(employee_role)

        results = self.vectorstore.similarity_search_with_score(
            question, k=5, filter=access_filter
        )

        if not results:
            return {
                "answer": "No information on your question was found in current regulations. Please contact HR.",
                "sources": [],
                "escalation_needed": True,
            }

        context = "\n\n".join([
            f"[{doc.metadata.get('document_name')}, version {doc.metadata.get('version')}, "
            f"effective {doc.metadata.get('effective_date')}]:\n{doc.page_content}"
            for doc, _ in results[:4]
        ])

        response = client.messages.create(
            model="claude-sonnet-4-5",
            max_tokens=2048,
            system=f"""You are a corporate assistant for company regulations and policies.

CRITICAL RULES:
1. Cite norms VERBATIM, do not paraphrase
2. Always mention the document, version, and section
3. If a norm allows exceptions, explicitly state them
4. If the question requires manager/HR decision, redirect to them
5. Do not interpret norms broadly—stick to the letter of the regulation

Employee role: {employee_role}
Department: {department or "not specified"}""",
            messages=[{
                "role": "user",
                "content": f"""Question: {question}

Applicable regulations:
{context}"""
            }]
        )

        return {
            "answer": response.content[0].text,
            "sources": [
                {
                    "document": doc.metadata.get("document_name"),
                    "version": doc.metadata.get("version"),
                    "section": doc.metadata.get("section"),
                    "effective_date": doc.metadata.get("effective_date"),
                }
                for doc, _ in results[:3]
            ],
            "escalation_needed": False,
        }

    def _get_access_filter(self, role: str) -> Optional[dict]:
        """Determines access filter by role"""
        if role == "admin":
            return None  # Full access

        access_levels = {
            "employee": ["public", "employee"],
            "manager": ["public", "employee", "manager"],
            "hr": ["public", "employee", "manager", "hr"],
        }

        allowed = access_levels.get(role, ["public"])
        if len(allowed) == 1:
            return {"access_level": allowed[0]}
        # Chroma does not support $in natively—use OR via multiple queries
        return {"access_level": {"$in": allowed}}

Indexing Regulations with Access Control

Each document is split into chunks of 800 characters with 100 overlap before loading. Metadata recorded for each chunk: document name, version, effective date, access level, and section. This enables filtering chunks by employee role during search.

class PolicyIndexer:

    def index_document(self, doc_path: str, metadata: dict, vectorstore: Chroma):
        """Indexes a regulation document with metadata"""
        from langchain.text_splitter import RecursiveCharacterTextSplitter

        content = self._read_document(doc_path)

        # Split by sections, preserving structure
        splitter = RecursiveCharacterTextSplitter(
            chunk_size=800,
            chunk_overlap=100,
            separators=["\nСтатья ", "\nПункт ", "\n\n", "\n"],
        )
        chunks = splitter.split_text(content)

        vectorstore.add_texts(
            texts=chunks,
            metadatas=[{
                "document_name": metadata["name"],
                "version": metadata["version"],
                "effective_date": metadata["effective_date"],
                "access_level": metadata.get("access_level", "employee"),
                "category": metadata.get("category", "general"),
                "section": self._detect_section(chunk),
            } for chunk in chunks]
        )

    def _detect_section(self, text: str) -> str:
        """Detects section from chunk text"""
        import re
        match = re.search(r'(?:Статья|Пункт|Раздел)\s+[\d.]+[.\s]+(.+?)(?:\n|$)', text)
        return match.group(1)[:100] if match else ""

    def _read_document(self, path: str) -> str:
        """Reads document (PDF, DOCX, TXT)"""
        from pathlib import Path
        ext = Path(path).suffix.lower()

        if ext == ".pdf":
            import pdfplumber
            with pdfplumber.open(path) as pdf:
                return "\n".join(page.extract_text() or "" for page in pdf.pages)
        elif ext in (".docx", ".doc"):
            import docx
            doc = docx.Document(path)
            return "\n".join(p.text for p in doc.paragraphs)
        else:
            return Path(path).read_text()

How is Access Control Configured?

Access to regulations is determined by the employee's role: employee, manager, hr, admin. Each document has an access_level tag. During search, the vector DB filters chunks by this tag. Admin sees everything, employee sees only public and employee-level documents. Managers additionally get access to managerial documents. We configure these levels according to your company hierarchy. HR time savings reach up to 30%, equivalent to 10 hours per week.

Practical Case: Manufacturing Company with 500 People

From our practice: a company with 23 regulations, constant HR questions about vacations, sick leave, business trips. HR spent 2-3 hours a day on repetitive answers.

Implementation:

  • Indexed all 23 regulations
  • Integrated into the corporate portal
  • Configured access rights (some regulations only for HR/managers)

Results:

  • 68% of repetitive HR questions resolved without contacting HR
  • Response time under one second versus 20 minutes waiting
  • Regulation violations "due to unawareness" dropped by 34%

Why Choose This Approach?

The AI assistant reduces HR workload 3 times more effectively than traditional search. Employees get instant answers with exact section references. Our engineers have implementation experience for companies from 100 to 5000 employees. We guarantee compliance with citation accuracy and data security requirements. Implementation pays for itself in 3 months due to time savings on information search.

What's Included in the Work

Stage What We Do Result
Document Audit Collect regulations, define structure and access levels Document mapping, metadata
Indexing Split into chunks, load into vector DB with metadata Search index with versions and access
Assistant Development Configure LLM, prompts, citation and escalation logic Working bot with accurate answers
Access Control Filter by role (employee/manager/HR/admin) Access only to permitted documents
Integration Embed into corporate portal, Slack, Teams Single entry point
Testing Verify on 100+ real questions, fine-tune Citation accuracy >95%

Estimated Timelines

  • Regulation indexing + basic responder: 3 to 5 days
  • Role-based access control: 2 to 3 days
  • FAQ generation + updates on regulation changes: from 1 week
  • Integration with corporate portal: from 1 week

Contact us to discuss your case and get a customized quote. Order the development of an AI assistant for your regulations—get a consultation and project estimate in 2 days. The experience of our engineers and certified solutions guarantee results.

LLM Development: Fine-Tuning, RAG, Agents, and Production Deployment

Using GPT‑4 or Claude 3.5 Sonnet through a public API is not a solution — it's just a tool. When the requirement is to "make it like ChatGPT, but on our data," there is a real engineering challenge behind it: from prompt engineering to training a 70B model on your own infrastructure. End-to-end LLM solution development is a complex stack, and we have been doing it for over 5 years. During this time, we have completed over 20 projects in generative AI: from RAG systems for legal departments to custom support agents. Where exactly your task falls depends on data, latency requirements, budget, and how critical confidentiality is.

A typical situation: the client has already tried ChatGPT, but results are unstable — sometimes accurate, sometimes hallucinating. Or they need integration into a corporate portal while complying with security policies. Let's break down each layer of the stack in detail — from RAG to production deployment.

Why Do RAG Systems Break and How to Fix It?

RAG (Retrieval-Augmented Generation) looks simple: find relevant documents, put them in context, get an answer. In practice, it fails in several places.

Chunking without overlap. Classic mistake: chunk_size=512, overlap=0. If the answer lies across two chunks, retrieval won't find either with sufficient confidence. Solution: overlap 15–25% of chunk_size, or better yet, sentence-aware splitting with spaCy or NLTK instead of naive character splitting.

Poor embedder. text-embedding-ada-002 is good for general use, but on legal or medical texts, specialized models like E5-large-v2, BGE-M3, or fine-tuned sentence-transformers on domain data outperform it. Recall@5 differences can be 15–25%.

No re-ranking. Vector search optimizes for speed, not relevance. A cross-encoder re-ranker (ms-marco-MiniLM-L-6-v2, bge-reranker-large) after initial retrieval improves top-3 accuracy with acceptable latency (+50–150ms). This is often more impactful than improving the embedding model.

Hybrid search. Dense vectors alone work poorly on exact queries: names, SKUs, codes. BM25 (sparse) finds exact matches but misses semantics. Hybrid via RRF (Reciprocal Rank Fusion) is the optimal compromise. Qdrant, Weaviate, and pgvector 0.7+ support hybrid search natively.

Typical production architecture for a corporate knowledge base
  1. Documents → preprocessing (PyMuPDF, Unstructured)
  2. Chunking → embedding (BGE-M3)
  3. Qdrant (hybrid dense+sparse)
  4. Cross-encoder re-ranking
  5. Context → LLM (vLLM or OpenAI API)
  6. Answer with sources (RAGAS for quality evaluation)

When to Fine-Tune Instead of Prompt Engineering?

Prompt engineering solves ~70% of LLM adaptation tasks for a domain. The remaining 30% require fine-tuning. Three indicators: the model ignores a specific output format even with detailed prompting; the task requires deep knowledge of specialized vocabulary (medicine, law); you need to significantly reduce token costs by replacing a large model with a smaller specialized one.

LoRA and QLoRA are the standard for SFT. LoRA adds trainable low-rank matrices to attention layers. A typical configuration for Llama-3 8B: r=64, lora_alpha=128, target_modules=["q_proj","v_proj","k_proj","o_proj"] yields ~0.8% trainable parameters, training on one A100 40GB. QLoRA adds 4-bit quantization (NF4) and allows fine-tuning 70B models on two A100 40GB, though speed drops by half compared to bf16.

DPO instead of RLHF. Direct Preference Optimization requires only (chosen, rejected) pairs, not scalar reward signals. DPOTrainer from the trl library (Hugging Face) implements it in a few dozen lines.

Common mistake. A dataset of 500 examples, 5 epochs, validation loss 0.8 — seems fine. But on test, the model degrades on general instructions. Cause: catastrophic forgetting. Solution: add 10–20% general instruction-following examples (Alpaca, FLAN) to the training set to preserve original capabilities.

How to Choose a Base Model: 8B or 70B?

Model Parameters Strengths Context
Llama-3.1 8B 8B Quality/speed balance 128k
Llama-3.1 70B 70B Complex reasoning 128k
Mistral 7B / Mixtral 8x7B 7B / 47B Efficiency for size 32k
Qwen2.5 72B 72B Code, multilingual 128k
Gemma 2 27B 27B Open license 8k

For most tasks, fine-tuning an 8B model is sufficient. 70B is needed when deep reasoning is required or the 8B baseline does not reach the required quality even after fine-tuning. Inference cost for Llama-3 8B via vLLM on A100 is efficient; the exact cost depends on volume.

What Does PagedAttention Bring to Production?

vLLM is the first choice for serving open-source models. PagedAttention is the key technical innovation: KV-cache is managed like virtual memory in an OS, without fragmentation. This yields 2–4x higher throughput compared to naive HuggingFace Transformers inference. The vLLM documentation confirms that continuous batching and PagedAttention are the standard for high-load LLM services.

Typical numbers on A100 80GB for Llama-3 8B (bf16): 400–600 req/s, P50 latency 200–400ms, P99 latency 600–900ms at concurrency 64. For 70B on two A100 with tensor parallelism: 80–120 req/s, P99 latency 1.5–2.5s. AWQ or GPTQ quantization reduces memory consumption by 2x with quality loss within 1–3%.

Multi-Agent Systems

Agents are LLMs with access to tools: search, code execution, API calls, database interaction. Common patterns:

  • ReAct (Reason + Act): the model reasons → chooses a tool → observes the result → reasons again. LangChain and LlamaIndex implement it out of the box.
  • Multi-agent orchestration: multiple specialized agents with a coordinator on top. Example: coordinator → researcher (search + summarization) → coder (code generation and execution) → critic (verification). Tools: AutoGen (Microsoft), CrewAI, custom implementation on LangGraph.

In production, agent systems are non-deterministic. Essential: guardrails, step limits, logging of each step, human-in-the-loop for critical actions.

How We Work: Stages, Timeline, Deliverables

Stage Duration What You Get
Audit and data collection 1–2 weeks Eval dataset of 100+ examples, task formalization
Baseline (prompt + RAG) 1–2 weeks Working prototype, quality metrics
Fine-tuning (if needed) 2–4 weeks Trained model, LoRA weights, model card
Deployment and monitoring 1–2 weeks vLLM server, Grafana + Prometheus
Documentation and training 1 week API documentation, team training

What Is Included

We deliver:

  • Technical documentation (model card, configs, deployment instructions)
  • Access to infrastructure (code repository, trained weights)
  • 1 month of post-deployment support (consultations, bug fixes)
  • Customer team training (2–3 sessions on system operation)

Timeline: basic RAG prototype — 1–2 weeks. Fine-tuning with customer data — 3–6 weeks (including data preparation). Production system with monitoring and retraining — 2–4 months. Cost is calculated individually based on data volume, model complexity, and infrastructure requirements.

We guarantee the quality of the final model with performance benchmarks and ongoing monitoring. Our engineers have hands‑on experience with dozens of production LLM systems.

Want to evaluate your project? Leave a request — we will prepare a preliminary summary within 1–2 business days. Or get a consultation on choosing the approach: RAG, fine-tuning, or hybrid — we will tell you what works best for you. Contact us to discuss your LLM development needs. Schedule a free consultation today.