AI policies
Set direction for responsible AI use and make policy expectations clear to builders, buyers, operators, and users.
How to implement it
- 01Approve an AI policy and acceptable-use rules
- 02Define prohibited AI use cases and exception handling
- 03Review policy after incidents, regulatory change, or major AI adoption
- 04Publish role-specific guidance for staff and product teams
Evidence to keep
- - AI policy
- - Acceptable-use standard
- - Policy approval record
- - Exception register
Metrics to watch
- - Policy acknowledgement rate
- - Open policy exceptions
- - Days since last policy review
Put this area into the AI Statement of Applicability with a short rationale: included, excluded, or partially included. Tie that decision to the AI risk assessment, impact assessment, and system inventory.
Policy templates for this control
Use these starting documents to turn the control into evidence. Adapt each template to your scope, systems, legal obligations and actual operating process.
Change management policyUse for ISO 27001 A.8.32, A.8.9, SOC 2 change management criteria, and PCI DSS requirement 6 change controls.Data breach response policyUse for ISO 27001 A.5.24 to A.5.28, SOC 2 incident handling, privacy notification, and PCI DSS requirement 12.10.AI use and governance policyUse for ISO 42001, AI governance, employee AI use, data handling, human review, and AI supplier risk.Acceptable use policyUse for ISO 27001 A.5.10, A.6.3, A.6.4, endpoint controls, remote work, and SOC 2 Security awareness.
Open the control-to-policy map