AI Governance Brief

AI Translation Governance: The Controls Regulated Buyers Should Require

By Rick Antezana, Chief Executive Officer, Dynamic Language. Over 30 years in the language services industry

Somewhere in your last multilingual deliverable, a machine most likely produced the first draft. Few buyers can say who reviewed that draft, what qualified the reviewer to review it, or whether any of it could be reconstructed for an auditor. AI translation governance is the set of documented controls that answers those questions: where AI is used, who reviews the output, what qualifies that reviewer, and how the process is verified by an independent body. Four controls carry it: disclosure, qualified post-editing, a certified review process, and secured data handling. Organizations in healthcare, government, and life sciences now carry the compliance burden for AI-assisted translation whether or not they selected the technology, which is why the controls belong in the contract rather than in the vendor’s marketing.

Why the governance question moved

Translation vendors have long been evaluated on quality, turnaround, and price. Most RFP templates still do not ask what happens when a machine produces the first draft: who reviews it, under what documented standard, and with what record left behind. At many providers the answer varies by project and by staff member, which is another way of saying there is no process to audit.

Regulation moved faster than the templates. Washington State’s Executive Order 24-01, signed January 30, 2024, directs state agencies to analyze the impact of generative AI before deploying it, and directs Washington Technology Solutions to issue guidelines for public sector procurement, deployment, and monitoring of the technology. In the European Union, Article 26 of the AI Act places a separate set of obligations on the organization deploying an AI system, including human oversight by people with the competence and authority to exercise it, and retention of logs. Several state AI laws follow the same pattern of attaching duties to the deployer. The practical consequence is that “we used a certified translation vendor” stops working as a defense at the moment a regulator asks for that vendor’s documented AI review process.

The failure mode that governance is built for

Ungoverned AI translation rarely fails loudly. The garbled sentence any reader would catch is not the expensive one. The expensive one is fluent, confident, and wrong: it survives a surface review, and it lands in a consent form, a benefits notice, a device instruction, or a contract where the meaning is the entire point. Terminology drift is where this concentrates, because models trained on general text handle narrow regulated vocabularies poorly.

The cost surfaces later and somewhere else, as a regulator’s question, a patient who misunderstood, a recall, or a rework cycle that lands on the buyer’s staff at the buyer’s hourly rate. None of it appears on the original quote. That timing gap is the reason the human review step functions as a control rather than a courtesy.

What determines whether AI is safe on a given file

The decision that matters most happens before anyone translates a word. Two files can carry the same word count, the same language pair, and almost nothing else in common: a marketing page moves quickly through a light-touch process, while a regulated consent form needs subject-matter linguists, a second reviewer, terminology matched to prior filings, and a record of who did what at each step. Sorting content by risk on day one, before quoting, sets the entire path.

This is where governance either exists or does not. A vendor who can describe the triage, the review layers, and the audit trail is running a process. A vendor who moves straight to a per-word rate is quoting the words and leaving the rest to chance. Buyers can test for this in a single question, covered in the FAQ below.

The standard behind the review step (ISO 18587)

The industry term for qualified human review of machine output is machine translation post-editing (MTPE), and the international standard for it is ISO 18587 (Machine Translation Post-Editing). Certification means an accredited body has audited the vendor’s post-editing process against the standard’s requirements for qualified post-editors, documented procedures, and quality measurement. Few language service providers hold it. A vendor without it may still post-edit; the buyer simply has no independent verification that the work is consistent, qualified, and reconstructable.

ISO 18587 answers what happens to the output. ISO 27001 (Information Security) answers what happens to the input: whether documents, recordings, and personal data stay inside a certified information security management system when a machine touches them. Governance questions about AI usually need both certificates, and buyers tend to ask for only the first.

The four controls to require in writing

01 ∙ Disclosure

The vendor states when AI translation is used in a deliverable and names the tools. Without this, nothing downstream can be audited.

02 ∙ Qualified post-editing

Every AI-assisted deliverable is reviewed by a post-editor with documented subject-matter qualifications for that content type, producible on request. A general-purpose reviewer is not appropriate for clinical or regulatory content.

03 ∙ Certified review process

The post-editing process itself is certified to ISO 18587. Where a vendor lacks it, ask what independent verification of the review step exists instead.

04 ∙ Data security

AI tool usage sits inside an ISO 27001-certified information security management system, and client data stays out of consumer-grade tools.

One exposure sits inside the buying organization rather than the vendor. As these tools become easier to reach, staff in procurement, communications, and operations translate documents on their own, outside the language program entirely. A short internal policy covering approved tools, disclosure obligations, and the content categories that require certified vendor review closes a gap that no vendor contract can reach.

Where Dynamic Language sits

Dynamic Language advises buyers on where AI fits each content type and runs a human-plus-AI workflow under certified process control. The company holds ISO 18587 alongside ISO 9001 (Quality Management), ISO 17100 (Translation Services), ISO 27001 (Information Security), and ISO 13485 (Medical Devices Quality Management), so the governance a buyer needs to show a regulator exists as certificates rather than assurances. We sell no proprietary AI product. For a company of this size, the useful role is a clear-eyed guide to the technology, with the human step documented and independently certified.

One example from our own book. Dynamic Language has served the State of Washington since 2004, and under the current Department of Enterprise Services master contract, 03824, the review process, the certifications, and the named account team have stayed in place across the whole relationship. A public agency can ask what our process was on a given file in a given year of that contract, and there is a record to answer with. That is what documented governance looks like once it has been running long enough to be tested.

FAQ

What is AI translation governance?

The documented controls over where AI is used in translation work, who reviews the output, what qualifies the reviewer, and how the process is independently verified. In practice it covers four things: disclosure, qualified post-editing, certification of the review process, and data security.

Is AI translation accurate enough for regulated content?

Raw machine output is fast and consistent for high-volume, low-risk material. Regulated and high-stakes content needs qualified human review, because the typical machine error is fluent and survives a surface read rather than announcing itself.

What is MTPE, and what is ISO 18587?

MTPE is machine translation post-editing, where a qualified linguist reviews and corrects machine output. ISO 18587 (Machine Translation Post-Editing) is the international standard for that process, and certification to it means the human review step has been audited by an accredited body.

What is the single best question to ask a vendor that uses AI?

How do you categorize a request on day one, before you quote it, and who is accountable for the review at the end? The answer separates a vendor running a documented process from one pricing words and hoping.

What should we require from a vendor in writing?

Disclosure of when and which AI tools are used, documented post-editor qualifications for your content type, ISO 18587 certification of the review process, and confirmation that client data stays inside an ISO 27001-certified security system.

Does ISO 27001 matter for AI translation?

Yes. ISO 27001 (Information Security) certification independently verifies that a vendor has documented controls over how client data is handled in its workflow, including any AI tools. It answers where your content goes when a machine touches it, which ISO 18587 does not cover.

Do we need an internal AI translation policy?

Yes. Staff outside the language program may run documents through consumer AI tools on their own initiative. A short policy defining approved tools, disclosure obligations, and the content types that require certified vendor review addresses exposure that sits inside the organization.

Does Dynamic Language build its own AI?

No. Dynamic Language advises clients on where AI fits their content and runs a human-plus-AI workflow governed by ISO 18587. We hold no proprietary AI product and sell none.

Bring your AI translation workflow under documented control.

Tell us where AI already touches your multilingual content. We will map the review, certification, and data controls your auditors will ask about.

Talk to a Specialist
This website uses ‘cookies’ generated by Google Analytics, a third-party service, to give you the best experience during your visit. This anonymous collection of data allows us to improve our website periodically. Dynamic Language does not share, sell or market the data obtained through this service. Read our Privacy Policy.