For Heads-of · Practitioner

No documented AI policy

The organisation operates AI systems without a top-management-approved policy defining acceptable use, risk appetite, and escalation routes.

  • high
  • governance
  • policy
  • ai-management-system

How it happens

AI adoption happens organically across teams, procurement decisions, shadow IT, individual experimentation, with no single policy document that top management has actually approved and that says what's allowed, what isn't, and who to escalate to.

Why it matters

Every other governance control in this list assumes a policy exists to point back to; without one, 'is this allowed' has no answer until someone improvises one under pressure.

Mitigating controls

The controls that address this risk, ranked by effectiveness.

Framework and clause references

FrameworkClauseTitle
NIST AI Risk Management Framework (AI RMF 1.0)GovernGovern
ISO/IEC 42001:2023Annex A.2Policies related to AI
SS1/23: Model Risk Management Principles for BanksPrinciple 2Model risk governance

Related resources

The external sources behind this risk, from the Resources library.