Applies to Enterprise. Governance is part of the full configuration set,
guided during Enterprise onboarding. Starter and Growth don’t configure this,
see Configure Overview.
Purpose
Governance defines who can do what, how data is handled, and how oversight works, so evaluations stay controlled, private, and auditable. It’s the final stage of setup, wrapping the Foundation and Operations you’ve configured before everything is signed off and frozen.What Governance covers
Locations & Regions
Used for routing, data residency, and operational context.
Users & Roles
Roles and permissions: who can configure, run, and review.
Data Visibility
A second access axis on every role: which records a person sees. Choose
Organization, Department, or Own records.
Compliance Frameworks
Only confirmed or correctly labeled frameworks (see status below).
Data Privacy & Retention
Consent, residency, and deletion of candidate records on request. Upcoming:
retention settings by data type.
Human Review
A person makes every hiring decision. Decision changes and AI score overrides
require a stated reason, and below-bar candidates stay visible for review.
Audit Trails
The Activity Log records every action on your account, by a person or by an
agent, and each score records the model and prompt that produced it.
Knowledge Base
Your policies, templates, and approved reference material.
Compliance framework status
Frameworks are shown with accurate, current status, never as unconfirmed claims:
Legal obligation marks a law, not a certification. Exterview claims no certification or compliance attestation against it.
This is a summary. For the full certifications table, current evidence pack,
and any region-specific requirements, see Compliance
FAQs or contact your Customer Success representative.
FAQs
Can Exterview make an adverse decision on its own?
Can Exterview make an adverse decision on its own?
No. A person makes every hiring decision. No automated step sets a candidate to hired, rejected, or withdrawn.
How is access controlled?
How is access controlled?
Through two axes. Roles and permissions decide what a person can do, with
configuration, running, and review kept separate. Data Visibility decides
which records they see: organization, department, or own records.
Where is our data stored?
Where is our data stored?
Data residency is set by your locations and regions during setup. Candidate records can be deleted on request. Upcoming: retention settings in Governance.
What goes in the Knowledge Base?
What goes in the Knowledge Base?
Your approved policies, templates, and reference material, used to keep evaluations grounded in your own guidance.
Related
- Trust & Compliance. The full security, privacy, and responsible-AI posture.
- Go-Live Readiness. Confirm governance before you deploy.

