# AI use and governance policy

Source: https://aestech.com.au/policy-templates/#ai-use-and-governance-policy
Markdown URL: https://aestech.com.au/policy-templates/ai-use-and-governance-policy.md

Use for ISO 42001, AI governance, employee AI use, data handling, human review, and AI supplier risk.

Frameworks: ISO 42001, ISO 27001, SOC 2

Use this as a starting point only. Adapt it to your real scope, systems, legal obligations, customer commitments and operating process.

```text
1. Purpose
This policy defines how AI systems and AI tools are approved, used, monitored and reviewed.

2. Requirements
- Keep an inventory of AI systems and approved AI tools.
- Classify each AI system by purpose, data used, owner, affected stakeholders and risk tier.
- Prohibit uploading confidential, restricted, customer, source-code or regulated data to unapproved AI tools.
- Require human review for AI outputs used in consequential decisions, customer commitments, legal, security or financial workflows.
- Review AI suppliers for data use, model training terms, confidentiality, security and change notification.
- Record incidents, unsafe outputs, hallucination patterns, complaints, drift and material changes.

3. Evidence
Keep AI inventory, AI impact assessments, supplier reviews, approved tool list, human review records, incidents, exceptions and management reviews.
```

Full template pack: https://aestech.com.au/policy-templates/policy-pack.md