A.2 / AI control area

AI policies

Set direction for responsible AI use and make policy expectations clear to builders, buyers, operators, and users.

AIMSEVIDENCEDATAEVIDENCEMODELEVIDENCEHUMANEVIDENCEAI GOVERNANCEA.2 AI EvidencePOLICY / CONTROL / EVIDENCE / REVIEW

How to implement it

  1. 01Approve an AI policy and acceptable-use rules
  2. 02Define prohibited AI use cases and exception handling
  3. 03Review policy after incidents, regulatory change, or major AI adoption
  4. 04Publish role-specific guidance for staff and product teams

Evidence to keep

  • - AI policy
  • - Acceptable-use standard
  • - Policy approval record
  • - Exception register

Metrics to watch

  • - Policy acknowledgement rate
  • - Open policy exceptions
  • - Days since last policy review
Put this area into the AI Statement of Applicability with a short rationale: included, excluded, or partially included. Tie that decision to the AI risk assessment, impact assessment, and system inventory.

Policy templates for this control

Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.

Open the control-to-policy map