For Heads-of · Practitioner

AI acceptable use policy

A top-management-approved policy defining what AI use is permitted, what isn't, and where to escalate an edge case.

  • directive
  • governance
  • policy

What it does

Documents the organisation's AI risk appetite, permitted and prohibited use cases, and escalation route, approved by top management and kept current.

Where it fits

The reference point every other governance control in this library assumes exists; without it, each new AI use case is decided from scratch.

Risks this mitigates

The risks this control addresses, ranked by effectiveness.

Framework and clause references

FrameworkClauseTitle
NIST AI Risk Management Framework (AI RMF 1.0)GovernGovern
ISO/IEC 42001:2023Annex A.2Policies related to AI
SS1/23: Model Risk Management Principles for BanksPrinciple 2Model risk governance