Field Purpose Justification
Explanation
Field Purpose Justification checks whether every data field the AI system extracts and uses has a documented, legitimate purpose tied to the business and legal basis for processing — preventing the model from quietly collecting or relying on data it has no lawful reason to use (for example pulling an applicant's religion or unrelated personal attributes from a scanned document). This matters for data-minimisation and trust: under RBI's 'trust is the foundation' expectation and ISO legal-requirements clauses, banks must justify what they process. It is measured by the Purpose Alignment Score, calculated as the number of aligned fields divided by total extracted fields. To implement, maintain a catalogue mapping each extractable field to an approved purpose and legal basis, run an automated reconciliation over document-extraction/RAG outputs that flags any extracted field lacking a justified purpose, and log the field list, the matched purposes and the resulting score as evidence per NIST GOVERN 1.1 and ISO Clause 5.2/6.1.3. The proposed thresholds are: target a score of at least 0.90, investigate when it falls below 0.85, and remediate when it drops below 0.80 — a breach triggers review of the unjustified fields, removal or re-justification, and tightening of the extraction scope.
# aligned fields / total extracted