For Heads-of · Practitioner
AI acceptable use policy
A top-management-approved policy defining what AI use is permitted, what isn't, and where to escalate an edge case.
- directive
- governance
- policy
What it does
Documents the organisation's AI risk appetite, permitted and prohibited use cases, and escalation route, approved by top management and kept current.
Where it fits
The reference point every other governance control in this library assumes exists; without it, each new AI use case is decided from scratch.
Risks this mitigates
The risks this control addresses, ranked by effectiveness.
Inadequate AI resourcing and competence
AI systems are adopted without provisioning the compute, tooling, data quality controls, or trained personnel needed to operate them safely.
No documented AI policy
The organisation operates AI systems without a top-management-approved policy defining acceptable use, risk appetite, and escalation routes.
Framework and clause references
| Framework | Clause | Title |
|---|---|---|
| NIST AI Risk Management Framework (AI RMF 1.0) | Govern | Govern |
| ISO/IEC 42001:2023 | Annex A.2 | Policies related to AI |
| SS1/23: Model Risk Management Principles for Banks | Principle 2 | Model risk governance |