Environment Agency: Regulatory Guidance Assistant
An AI Assisted search and retrieval tool for regulatory guidance documents.
1. Summary
1 - Name
Regulatory Guidance Assistant
2 - Description
What is the tool?
The Regulatory Guidance Assistant (RGA) is an AI‑enabled pilot tool developed within the Environment Agency’s Regulatory Services Programme to support officers by helping them find, navigate, and apply regulatory guidance more quickly and consistently. It runs in a controlled, non‑production environment with restricted access and operates as an assistive search and retrieval tool rather than a decision‑making system.
Why is it being used?
The tool is being used to address long‑standing challenges with fragmented, inconsistently formatted guidance and inefficient retrieval processes. Its purpose is to reduce search friction, improve the speed and reliability of guidance discovery, and ensure greater consistency in how regulatory guidance is applied. It also aims to test the capabilities and limitations of AI in regulatory contexts under strong governance and assurance.
3 - Website URL
n/a
4 - Contact email
Tier 2 - Owner and Responsibility
1.1 - Organisation or department
Environment Agency
1.2 - Team
Regulatory Services Programme (RSP)
1.3 - Senior responsible owner
RSP - Data and AI Lead
1.4 - Third party involvement
Yes
1.4.1 - Third party
Hitachi Solutions, Defra Digital, Data, Technology and Security Teams (DDTS)
1.4.2 - Companies House Number
Hitachi Solutions Europe Ltd: 04924233
1.4.3 - Third party role
Hitachi Solutions: Discovery, development and testing of solution plus 50/50 split in delivery management
DDTS: Delivery management
1.4.4 - Procurement procedure type
The solution uses incumbent technologies available within Defra, primarily based on Azure cloud and MS Power Platform infrastructure, aligned with Defra CCoE best practice. Programme-level commercial arrangements with Hitachi, under the broader SERP contract, provide industry expertise in roles such as cloud architecture, data engineering, UR, UX, UI, content design, software development expertise and test capabilities, which is leveraged via specific outcomes-based Statements of Work for deploying the RSP Compliant project capabilities specifically.
1.4.5 - Third party data access terms
All individuals involved in the build work held the appropriate Security Check (SC) clearance. The data sources used—limited to approved SharePoint locations and Content Cloud repositories—were authorised by the responsible Deputy Director prior to use. All material ingested or processed was at Official‑Sensitive (OS) or lower classification and already publicly available. At no stage were third‑party developers given access to personal data, sensitive information, or any form of Personally Identifiable Information (PII/PIII).
Tier 2 - Description and Rationale
2.1 - Detailed description
Purpose of the Tool
The algorithmic tool — the Regulatory Guidance Assistant (RGA) — is designed to help Water Quality permitting officers locate and apply regulatory guidance more efficiently. It addresses the problem of fragmented, inconsistently formatted guidance and the difficulty officers face in retrieving the correct information quickly. It supports the Regulatory Services Programme’s (RSP’s) aims to increase consistency, streamline regulatory services, and improve the user experience for permitting officers.
Intended Users
The tool is currently used only by:
- Small Sewage Discharge (SSD) Water Quality permitting officers in England,
- Within a controlled pilot user group,
- Accessed through the Defradev environment with restrictions enforced via Azure Active
- Directory (AAD) security groups and DEFRADEV licences.
How the Tool Works (High‑Level Functionality)
The RGA is an AI-enabled guidance retrieval tool. Its key operational functions include:
- Ingesting and organising regulatory guidance: Guidance materials are extracted, transformed, and loaded (ETL) through ongoing ETL processes to ensure the tool works from up‑to‑date, structured source material.
- Enabling faster, more accurate search: The tool uses AI to support more efficient and consistent discovery of policy and technical guidance. Officers can quickly retrieve authoritative guidance. It reduces time spent manually searching across multiple fragmented documents.
- Providing assistance, not decisions: The RGA does not make regulatory decisions. All AI‑generated outputs require human review and remain subject to regulatory judgement by the permitting officer.
- Guardrails and governance controls: The tool operates with strong assurance processes, including:
- DDTS/Defra governance
- Stage‑gates
- Weekly risk/assurance workshops
- Confidentiality, Integrity, Availability (CIA) assessments
These controls ensure safe, transparent, and responsible use of AI in regulatory contexts.
Monitoring, metrics and iterative improvement
The pilot tracks:
- Baseline and post‑use performance metrics (speed, accuracy, adoption)
- Functional Acceptance Testing (FAT) findings
- Usability testing feedback
This data informs decisions on future scaling.
Scope of the Tool
The scope is intentionally narrow as part of a controlled pilot. Included in scope:
- SSD Water Quality permitting guidance
- Defined user group
- Non‑production “defradev” environment
- Guidance retrieval and support functions only
Not in scope:
- Automated regulatory decision‑making
- Use outside Water Quality SSD permitting
- Wider Defra/regulator rollout (until pilot evaluation is complete)
- Performance measurement of individual officers (Change, Adoption & Learning (CAL) guidance frames the pilot as exploratory, not evaluative)
Limitations and Contexts Where the Tool Does Not Apply
- Not suitable for decision-making: The tool does not apply to any determinations requiring regulatory judgement and cannot be used as a substitute for applying statutory requirements.
- Every output requires human oversight.
- Limited content coverage: Only guidance that has been successfully onboarded through the ETL process is available. New guidance sources are integrated incrementally.
- Controlled environment only: Use outside the defradev environment or by any user not in the approved AAD security group is not permitted.
- Pilot‑stage constraints. Being a pilot, the tool:
- Is still undergoing testing (FAT, usability testing).
- Has evolving guardrails and data quality improvements.
- Has a limited set of validated metrics.
- Not suitable where guidance is absent or ambiguous: The tool can only surface what is present in the indexed guidance corpus; it cannot bridge policy gaps or interpret unclear instructions.
2.2 - Benefits
- Faster access to regulatory guidance The tool enables permitting officers to quickly locate relevant regulatory guidance, reducing the time and effort previously required to search through fragmented or inconsistently formatted documents. This improves operational efficiency and reduces search friction.
- More consistent application of guidance By providing a unified, structured access point for regulatory information, the tool supports greater consistency in how guidance is interpreted and applied across officers and teams.
- Increased accuracy and reliability of information retrieval AI‑assisted search enhances officers’ ability to discover the correct and most relevant guidance, contributing to improved accuracy in permitting work.
- Time savings that can be redirected to higher‑value activities Reducing the search burden allows officers to focus their time on substantive regulatory analysis, professional judgement, and customer engagement rather than administrative document‑finding tasks.
- Strengthened governance and responsible innovation The tool is deployed with rigorous governance controls (including DDTS/Defra assurance processes, risk workshops, and mandatory human oversight). This demonstrates a safe, transparent pathway for adopting AI in regulatory contexts and builds organisational confidence in responsible AI use.
- Reusable data and AI patterns for wider regulatory services The pilot develops reusable patterns for data ingestion, ETL, guardrails, and governance which can support future services across the Regulatory Services Programme and enable efficiency savings.
- Evidence‑based decision‑making on future scaling Collection of baseline and post‑pilot metrics (e.g., speed, accuracy, adoption) provides evidence for assessing the tool’s impact and informs any future decisions on scaling to other domains.
2.3 - Previous process
Legacy process prior to deployment
Prior to the deployment of the Regulatory Guidance Assistant (RGA), permitting officers located and interpreted regulatory guidance manually using a combination of SharePoint sites, guidance documents, intranet resources, search functions and personal knowledge. Where relevant guidance could not be readily identified or interpreted, officers would seek clarification from Subject Matter Experts (SMEs), technical specialists, colleagues or line management.
The process relied heavily on users understanding where guidance was stored, how documents related to one another and which sources were most relevant to the specific permitting scenario being considered. This could require reviewing multiple documents and cross-referencing guidance from different locations before reaching a conclusion.
Consistency was achieved through professional judgement, established governance processes, peer discussion and escalation routes rather than through automation. Final regulatory decisions remained, and continue to remain, the responsibility of trained permitting officers.
The RGA does not replace this process or automate decision-making. Instead, it assists officers in locating and navigating approved guidance more efficiently, while maintaining existing governance, oversight and decision-making responsibilities.
2.4 - Alternatives considered
Alternative approaches considered
Prior to selecting a retrieval-augmented AI assistant approach, several algorithmic and non-algorithmic alternatives were considered.
Non-algorithmic alternatives
Continued reliance on existing guidance repositories, SharePoint sites, PDFs and search facilities. Trade-off: Low implementation risk and no use of AI, but users still faced significant effort locating relevant guidance across multiple sources and interpreting relationships between documents. Additional training, guidance consolidation and knowledge-sharing activities. Trade-off: Improves user capability but does not provide real-time support or address the challenge of navigating large volumes of frequently changing guidance at the point of need. Establishing a dedicated SME support model for guidance enquiries. Trade-off: High confidence in advice quality but not scalable, dependent on staff availability, and potentially increases demand on specialist resources.
Algorithmic alternatives
Traditional keyword and metadata-based enterprise search. Trade-off: Provides document retrieval but limited ability to understand natural language questions, synthesise relevant guidance across multiple sources, or explain why information is relevant. Rules-based decision trees and guided workflow tools. Trade-off: Effective for highly structured processes but unsuitable for the breadth, complexity and evolving nature of regulatory guidance, requiring significant maintenance effort.
Rationale for selected approach
The Regulatory Guidance Assistant was selected because it combines natural-language querying with retrieval from approved guidance sources, enabling officers to locate and interpret relevant guidance more efficiently while maintaining human oversight and professional judgement. The tool does not automate regulatory decisions; rather, it supports users in accessing and understanding existing guidance. This was considered a proportionate response to the identified problem of finding and navigating complex regulatory guidance.
Tier 2 - Deployment Context
3.1 - Integration into broader operational process
The Regulatory Guidance Assistant (RGA) supports Water Quality (WQ) permitting officers—specifically those handling Small Sewage Discharge (SSD) permits—by helping them locate and apply the correct regulatory guidance more quickly and consistently. It informs and supports:
Interpretation and application of regulatory guidance needed during the assessment of SSD permit applications. Operational decision-making by reducing friction in retrieving authoritative guidance that officers require to complete permitting work. Quality and consistency checks, by ensuring officers refer to the same guidance material rather than local or outdated sources.
The tool does not make regulatory decisions; instead, it informs and supports human regulatory decisions by improving access to information.
What information does the algorithmic tool provide to its user(s)? The RGA provides:
- Faster, more reliable search results drawn from up‑to‑date regulatory guidance content.
- Structured retrieval of guidance that has been ingested, processed, and indexed through the project’s ETL pipeline.
- AI‑assisted access to relevant regulatory material, helping officers surface the correct documents or sections more efficiently than manual searching.
It provides guidance discovery, not regulatory advice or decisions.
How is that information used by the user(s)? Officers use the information to:
- Identify relevant regulatory requirements more quickly during casework.
- Verify that guidance has been interpreted correctly, increasing consistency across permitting decisions.
- Reduce time spent searching for documents, allowing greater focus on professional judgement and customer-facing tasks.
- Apply the most current, authoritative guidance when determining permit conditions or evaluating compliance with policy.
All outputs are subject to mandatory human review, and the tool is used strictly as an assistive search and guidance-retrieval mechanism, not a decision-maker.
3.2 - Human review
The RGA’s outputs are reviewed by a permitting officer every time the tool is used. All outputs require mandatory human oversight and cannot be used directly in decision‑making. Review quality is assured through DDTS governance, FAT testing, weekly RAID/CIA sessions, structured user feedback, and ongoing oversight from the Steering Committee. These mechanisms ensure that human interpretation, not AI output, drives all regulatory decisions.
3.3 - Frequency and scale of usage
Usage frequency: RGA is in pre‑production/approval; production telemetry is not yet available. During the initial pilot, we will capture monthly active users and prompt volumes. For planning only, we use an upper‑bound proxy based on observed M365 Copilot usage in our organisation of ~94 prompts per user per 30 days until RGA telemetry is available.
Scale of deployment: ~150 Internal EA staff only, beginning with SSD and FRAP permitting teams in a pilot, with the intention to extend to other regulatory areas following approval.
Automated decisions per month: 0 — RGA is assistive; officers retain full responsibility for regulatory determinations.
Citizens interacting with the tool: 0 — RGA is not public‑facing; it is only accessible to EA staff via Microsoft Teams.
3.4 - Required training
Drop in sessions to be held before and during pilot phase. Mandatory EA AI training has also been prescribed by the business to cover basic AI training.
3.5 - Appeals and review
Through normal permitting appeals processess
Tier 2 - Tool Specification
4.1.1 - System architecture
4.1.2 - System-level input
The system‑level inputs to the Regulatory Guidance Assistant (RGA) consist of:
Processed regulatory guidance content - The tool ingests and uses regulatory guidance documents that have been extracted, transformed, and loaded (ETL) into the system, forming the structured corpus on which the AI model performs retrieval. Format/Data Types:
- Text-based regulatory documents
- Structured and semi‑structured content generated by the ETL pipeline
- Document metadata
User search queries (officer prompts) - The officer provides a textual query or question, which the system uses to identify and surface relevant guidance. Format/Data Types:
- Free‑text natural‑language queries submitted by users
These two inputs operate together: the user’s query is applied against the indexed guidance corpus to return relevant guidance content.
4.1.3 - System-level output
The system‑level output of the Regulatory Guidance Assistant (RGA) is the AI‑assisted retrieval of relevant regulatory guidance content. The tool returns structured guidance material sourced from the onboarded and ETL‑processed document corpus. Expected output formats and data types include:
- Text excerpts from regulatory guidance documents
- Structured search results showing the most relevant guidance sections
- Document references or metadata, linking the user to authoritative source material
The output provides faster, more reliable discovery of guidance, helping users locate the correct information for regulatory tasks. It does not produce decisions, recommendations, classifications, or scores—only surfaced guidance that must be reviewed and interpreted by a human officer.
Extensive User Acceptance Testing (UAT) is scheduled to take place to ensure the output is consistantly grounded in knowledge from it’s available corpus of documents despite variations on repeated similar or identical queries.
4.1.4 - Maintenance
A formal maintenance and review schedule for the tool has not yet been defined. The Regulatory Guidance Assistant (RGA) will follow Environment Agency and Defra governance processes for updates, assurance, and monitoring as these are established during and after the pilot phase.
The underlying Large Language Model (LLM) used by the tool will not undergo any re‑training or fine‑tuning. The model remains closed and unmodified. However, the agent will automatically receive upgrades when the model provider releases a new stable version. These upgrades do not involve training on Environment Agency data and do not introduce any new model‑specific behaviour beyond the improvements supplied by the vendor.
Any updates to the tool during its lifecycle will focus on areas such as configuration changes, improvements to the content ingestion pipeline, enhancements to guardrails, and refinement of operational workflows—not on altering or training the LLM itself. Ongoing review will be integrated into the tool’s operational governance once the pilot concludes, including periodic checks on performance, accuracy, alignment with regulatory requirements, and continued compliance with Defra’s AI governance standards.
4.1.5 - Models
GPT-4.1 LLM is the default model for agents in Copilot Studio and the model used for the Regulatory Guidance Agent.
Tier 2 - Operational Data Specification
4.4.1 - Data sources
The Regulatory Guidance Assistant (RGA) operates using two controlled categories of input data:
- User Inputs (Natural‑Language Queries) - End users submit free‑text, natural‑language questions or prompts. These user‑initiated inputs act as the interactive runtime data that triggers the system’s retrieval workflow.
- Onboarded Regulatory Guidance Content (ETL‑Processed Corpus) - The RGA retrieves information exclusively from regulatory guidance documents and related materials that have been ingested through the project’s established Extract–Transform–Load (ETL) pipeline.
The onboarded corpus includes content sourced from:
- GOV.UK regulatory and statutory guidance
- Content Cloud+ materials
- Internal SharePoint repositories containing relevant regulatory documents
- Structured and semi‑structured text extracted and normalised through ETL processes
- Document metadata and indexed content generated during ingestion
These sources are curated, validated, and expanded throughout the pilot to ensure improved coverage and alignment with regulatory obligations. Pipelines exist to refresh the materials at 8am daily, and investigative trials are currently underway to trigger refresh of the corpus when a source document is updated, added or removed.
4.4.2 - Sensitive attributes
No Sensitive Attributes in source materials
4.4.3 - Data processing methods
all documents are converted to Markdown Format during ETL pipelines for easier LLM Search and retrieval
4.4.4 - Data access and storage
Operational data captured:
- The assistant stores conversation transcripts (user inputs, system responses, and metadata) and source documents (.docx, .pdf, and other file types) used to support responses. These documents are processed into markdown and vector chunks for retrieval.
Where data is stored:
- Conversation transcripts are stored in Microsoft Dataverse within the Defra Non‑Production environment, in line with Environment Agency and Defra platform governance.
- Source documents and derived artefacts (markdown, chunked representations) are stored in Azure Data Lake Storage Gen2 (ADLS2) within the same non‑production tenant boundary.
Access controls:
- Access follows Defra and EA role‑based security. Only authorised Environment Administrators and Makers with approved roles may view, retrieve, or manage stored transcripts and stored documents.
- Microsoft does not access EA/Defra data except under tightly controlled contractual support conditions.
Retention and deletion:
- Transcripts: retained for ~30 days by default. Environment Administrators may extend, shorten, or disable retention in accordance with EA/Defra records‑management policy.
- Source documents in ADLS2: retained according to the environment’s storage and lifecycle policies, which must align with Environment Agency data‑handling and information‑governance requirements.
Responsibility:
- Environment Agency (Data Controller): Sets retention rules, manages access permissions, governs document handling, and ensures compliance with EA/Defra policies, GDPR, and audit obligations.
- Microsoft (Data Processor): Provides the Dataverse and ADLS2 platform services and implements the required technical safeguards under the EA/Defra enterprise agreement.
Security and privacy measures:
- Technical: Encryption at rest and in transit, secure segregated tenant boundaries, ADLS2 fine‑grained access control, Dataverse security model, and optional customer‑managed keys where supported.
- Operational: RBAC, audit logging, restricted administrative privileges, and storage/retention policies aligned with Environment Agency governance.
- Privacy: No data is used to train Microsoft models outside the Defra tenant. Transcript capture and document storage can be restricted or disabled for high‑sensitivity scenarios.
4.4.5 - Data sharing agreements
N/A
Tier 2 - Risks, Mitigations and Impact Assessments
5.1 - Impact assessments
Impact assessments completed for the Regulatory Guidance Assistant (RGA) indicate that no personal data is processed in the current SSD and FRAP pilot phases; therefore a full Data Protection Impact Assessment (DPIA) is not required. An Equality Impact Assessment is underway as a live, iteratively updated document, reflecting requirements under the Public Sector Equality Duty and incorporating input from staff networks to ensure accessibility and inclusive design throughout development. Algorithmic or automated‑decision impact assessments are not currently required, as RGA does not perform automated decisions affecting individuals, though these will be commissioned if future increments introduce such capabilities
Governance and Assurance (Required for ATRS)
Oversight is provided by a dedicated Steering Committee with updates to Senior Responsible Officers (SRO) and Chief Technology Officer (CTO)/Head of AI delegates. Weekly Risks, Assumptions, Issues, Dependencies (RAID) and CIA reviews ensure risk and operational impacts are understood. Human review of AI outputs is mandatory prior to use in decisions or external-facing communication.
This governance ensures alignment with transparency, safety, and regulatory compliance expectations.
5.2 - Risks and mitigations
-
Unfair or biased outcomes Mitigation: The Regulatory Guidance Assistant is designed with a controlled, approved corpus; clear data‑quality checks; human‑in‑the‑loop review for sensitive outputs; and bias monitoring embedded in Functional Acceptance Testing, where representative prompts and regression checks are used to identify any systematic skew or omissions.
-
Hallucinations or misattribution Mitigation: The Regulatory Guidance Assistant is designed with retrieval‑augmented generation from an allow‑listed ADLS2 corpus, enforced inline citations, and monitoring to detect and address recurrent error patterns. As a search‑and‑retrieval tool, it does not require reviewer validation for high‑impact outputs.
-
Privacy risk: inadvertent capture of personal data in transcripts Mitigation: The Regulatory Guidance Assistant is designed with strict Dataverse RBAC, short default transcript‑retention periods (or full disabling), and established EA/Defra routes for data‑subject rights. A DPIA is pending for user‑entered queries; however, source documents did not require a DPIA due to their nature and classification.
-
Privacy risk: sensitive or OFFICIAL‑SENSITIVE content in source documents Mitigation: The Regulatory Guidance Assistant is designed with ingestion rules aligned to EA/Defra security policy. In practice, the tool does not process sensitive or OFFICIAL‑SENSITIVE material: all ingested documents are publicly available, externally facing, or releasable under FOI.
-
Security risk: misconfigured access controls (Dataverse / ADLS2) Mitigation: The Regulatory Guidance Assistant is designed with least‑privilege RBAC, periodic access reviews, and standard audit logging available within the Defra tenant. Controls focus on restricting access and minimising misconfiguration risk.
-
Over‑automation or inadequate human oversight Mitigation: The Regulatory Guidance Assistant is designed with an explicit “advice‑not‑decision” posture, clear escalation routes, and transparent governance and ownership recorded in the ATRS.
-
Out‑of‑date or superseded guidance Mitigation: The Regulatory Guidance Assistant is designed with version‑controlled knowledge assets, scheduled corpus refreshes, and change‑control gates to ensure outdated material is not surfaced.
-
Intellectual‑property and licensing risks Mitigation: The Regulatory Guidance Assistant is designed with provenance tracking for all documents, ingestion restricted to cleared/licensed content, and licence‑appropriate constraints aligned to EA/Defra policy.
-
Environmental impact (compute and storage) Mitigation: The Regulatory Guidance Assistant is designed with controlled call budgets, ADLS2 tiering and lifecycle rules, and short/default transcript retention to reduce compute and storage overhead.
-
Records‑management and retention misalignment Mitigation: The Regulatory Guidance Assistant is designed with Dataverse and ADLS2 retention settings aligned to EA/Defra schedules, short baseline transcript retention (or full disabling), and transparent documentation of operational‑data retention.
-
Equality and fairness impacts Mitigation: The Regulatory Guidance Assistant is designed with inclusive‑language checks, representative user testing during acceptance, and equality‑impact considerations where appropriate.