Free guide · Section by section · Plain English
AI Policy Template
An "AI policy" means two different things: the rules for staff using AI tools, and the governance documents an auditor expects behind them. This page is a guide to writing the first one yourself - every section it needs and why, the wording of the clauses people get wrong, and what an auditor will ask you for. When you would rather have this one document written and checked for your business, PolicyMint does that, and your first document is free.
Card required; no charge today.
The writing guide
How to write an AI use policy
- 9
- sections the document needs
- 4
- wordings people reliably get wrong
- 7
- things an auditor asks to see
- a day or two
- to write it yourself
Two very different documents get called an AI policy: the acceptable-use rules staff follow, and the governed set an ISO 42001 auditor reads. This guide covers the first one in full, in the order it should be written. Four clauses carry more weight than the rest, so those come with example wording and the reason it holds up.
-
Opening statement
What it must contain
One short paragraph naming the AI in play - the assistants you license and the AI features already built into software you use - and the outcome you want from it.
What the auditor checks
It is the first evidence of intent. An auditor reads the opening to judge whether the policy was written for your business or lifted from a search result.
-
Purpose and scope
What it must contain
Who the policy binds (employees, contractors, third parties), on which devices, and that it covers both the tools you provide and public tools reached from a browser.
What the auditor checks
Scope decides what the rest of the audit can touch. A policy that quietly covers only company laptops leaves your real exposure - personal phones and free web tools - ungoverned.
-
Approved tools
What it must contain
The named list of AI tools people may use, and the route to getting one added: who to ask, and at what point in the process.
What the auditor checks
They compare the list against what is actually in use. A list nobody maintains is treated as worse than no list, because it shows a control that was written once and then abandoned.
Wording that works If you want to use a tool that is not on the list, ask [role, e.g. IT Manager] before putting any company or customer information into it.
It names a role and a moment. A list of approved tools with no route to adding one gets ignored the first time somebody needs a tool that is not on it, and the shadow use that follows is what an auditor eventually finds. Naming the role rather than a person means the clause survives that person leaving.
-
What you must not put into a public AI tool
What it must contain
Named categories of data rather than adjectives: information that identifies a person, credentials and keys, source code, anything covered by a contract or NDA.
What the auditor checks
This is the clause a data-exposure incident gets judged against. If it is vague, there is nothing to have breached, and nothing to train people on.
Wording that works Never paste the following into a public or unapproved AI tool: customer personal information or anything that could identify a person; confidential business information, credentials, API keys or passwords.
It names data types instead of adjectives. "Do not share confidential information" is unenforceable because nobody agrees where confidential starts, whereas "anything that could identify a person" and "credentials, API keys or passwords" can be followed without a judgment call and tested after the fact.
-
Check the output before you rely on it
What it must contain
That output is a draft until checked - facts, figures, code, and legal or compliance statements - and that responsibility for the result does not move to the tool.
What the auditor checks
Human oversight. They want the checkpoint named, and where a decision affects a person, some record that the check actually happened.
Wording that works Treat every output as a draft: check facts, figures, code and legal or compliance statements before you use or send them. You remain responsible for anything you produce with AI, exactly as if you had written it yourself.
The first sentence sets the standard of care; the second closes the gap people actually fall through, which is the quiet assumption that using a tool moves the responsibility onto it. That second sentence is what turns a review step from advice into an obligation.
-
Transparency
What it must contain
Where the use of AI has to be disclosed - customer-facing content, decisions that affect people, anything a regulator or auditor might review - and that AI output is not presented as human work where the distinction is material.
What the auditor checks
Disclosure duties are turning up in customer contracts and in law. The auditor checks that you have taken a position at all, and that the position matches what your customers were told.
-
Data and privacy
What it must contain
That a tool must meet your privacy and security requirements for the data involved, a preference for tools that do not train on your input (or that setting turned off), and who to ask when it is unclear.
What the auditor checks
It ties AI use back to the data-protection commitments you already made elsewhere. Auditors specifically look for the training-on-your-data question being answered, because most policies skip it.
-
Accountability and breaches
What it must contain
That misuse runs through the disciplinary and incident processes you already have, and the immediate reporting route when information may have been exposed through a tool.
What the auditor checks
They test whether AI incidents land in the same incident register as everything else, rather than on a separate track that nobody reviews.
-
Review, ownership and approval
What it must contain
The named owner, the review cadence, the events that force an early review, and an approval block: name, title, date and version.
What the auditor checks
The first page they turn to. An unowned, undated policy reads as unmaintained no matter how good the rest of it is.
Wording that works This policy is owned by [role] and reviewed at least once a year, and whenever the tools we use or the law change.
An owner, a cadence and a trigger in a single line. The trigger is the part most policies leave out, and it is what stops an annual cycle from running a year behind the tools your staff are already using.
Length is not the goal. One or two pages that people read once and then follow beats eight pages nobody opens, and the shorter version is far easier to keep current - which is the test it has to pass every year afterward.
On the day
What an auditor actually checks
Reviewing an AI policy takes minutes, and almost none of it is about writing quality. These are the questions that come up, and what actually closes each one.
- Show me your AI policy.
-
Satisfies One current document with a version number, an owner, an approval date and a next-review date that has not passed.
Fails Two differing copies in two drives is a finding on its own.
- Who approved it, and when?
-
Satisfies An approval block with a real name and title, plus the thing that records the decision - a meeting note, an email, a ticket.
Fails A signature line left blank is the most common single failure.
- How do your staff know it exists?
-
Satisfies Evidence it was distributed: an induction step, an acknowledgment list, a link in the handbook people actually open.
Fails Approved but never circulated does not count as implemented.
- Which AI tools are approved right now?
-
Satisfies A current list that matches reality. Expect it to be cross-checked against your single sign-on app list, expense claims, or the browser extensions visible on the screens in the room.
- What happens when someone wants a tool that is not on the list?
-
Satisfies The named approver, plus one worked example: a request, what was considered, and the decision. One real case is worth more than a paragraph describing the process.
- Where does a human check AI output before it reaches a customer?
-
Satisfies A named checkpoint inside a named process, and a record showing the check happened on a specific piece of work.
Fails "Output is reviewed" with no location gives them nothing to sample.
- What happened the last time an AI tool caused a problem?
-
Satisfies An entry in your normal incident register and what changed afterward.
Fails "It has never happened" is accepted once; the second time it reads as nobody looking.
The pattern is consistent: the document is the small half of it, and the evidence that the document is being used is the large half. Write the policy so that each rule leaves a trace somewhere you can find later.
What goes wrong
The mistakes that get a policy sent back
Almost every AI policy that fails a review fails for one of these reasons. None of them are about how well it is written.
-
Placeholders survive into the approved version
[Organization] and [role, e.g. IT Manager] still sitting in the signed PDF. It is the quickest way to be told the document is not real, and it happens because the approval step never included anybody reading it end to end.
-
Prohibitions written as adjectives
"Do not share sensitive or confidential information" cannot be followed or enforced, because nobody agrees where the line is. Name the data types instead, so a person on their first day can apply the rule without asking.
-
A tool list frozen on the day it was written
Staff move to whatever they saw last month. Within two quarters the approved list describes nothing, and the gap between the list and reality is the finding - not the tools themselves.
-
A blanket ban with no approved alternative
Prohibition without a sanctioned option does not stop AI use, it moves it to personal accounts where you cannot see it and cannot govern it. You lose the visibility you wrote the policy to get.
-
No named owner and no review date
Every other clause can be right and the document still reads as abandoned. Review dates that have quietly passed are just as bad: an expired review is evidence the control is not operating.
-
Oversight asserted but never located
"AI output is reviewed before use" names no step, no role and no record, so there is nothing for an auditor to sample and nothing for a staff member to actually do.
-
An HR conduct template used as governance evidence
Most templates on the market are written for behavior. They never touch data, tools, model training or oversight, so they answer the staff question and none of the audit ones.
-
Treating the staff policy as the whole system
One acceptable-use policy is the people-facing layer. It is not an AI management system, and presenting it as one is the mismatch that stalls an ISO 42001 audit before it starts.
When one policy is not enough
ISO 42001: the AI management system auditors expect
If you are pursuing ISO/IEC 42001 - or a customer is asking how you govern AI - the policy this guide teaches will not clear the bar on its own. ISO 42001 is a management-system standard: it expects a governing AI policy plus the documents that operationalize it - roles and responsibilities, an AI risk assessment, an AI system impact assessment, data governance for AI, and a transparency policy, each tailored to the AI systems you build, provide or use.
Generic templates fail here for a simple reason: the standard is about your specific AI context, and a copied document cannot show that. See exactly what ISO 42001 requires and the documents you need, and the full ISO 42001 controls each one satisfies.
For the control-level detail behind that, our sibling site ControlStack has a plain-English breakdown of what ISO/IEC 42001 asks for in practice.
See the real output
What PolicyMint generates
The cover in the hero and the body page below are the structure in this guide run through PolicyMint's export path, with an example company's branding applied. Generated for your business, it comes back naming the AI tools you actually approve, the role that signs off a new one, the concerns channel your staff really use, and an approval and version block already filled in rather than left as brackets.
Side by side
Writing it yourself vs generating it
Same document either way. The difference is who does the drafting, and what evidence comes attached to it.
| Dimension | Writing it yourself from this guide | Generating it with PolicyMint |
|---|---|---|
| What you end up with | One acceptable-use policy in your own words, as complete as the time you can give it | The same policy, written from your answers and exported in your branding as Word, PDF or Excel |
| Tailored to your business | As specific as you make it - every clause is on you | Written from your business profile, the AI systems you use, and your role for each (developer, provider or user) |
| Mapped to ISO 42001 | You work out which clauses and controls your wording answers | Each section cites the ISO 42001 clause or control it satisfies |
| Checked before you use it | Your own review, against your own judgment | Three independent verifiers on a different AI model, plus a repair pass |
| Time to a finished document | A day or two of drafting, then the rounds of edits before anyone will sign it | Answer a few questions and the document comes back written |
| Price | Your time, and you own every clause afterward | A$10.00US$6.50£5.00€6.00 for this document. If you later want the whole ISO 42001 set, that is one pack of A$350US$229£179€209 |
Card required; no charge today. Pay per document, not per month. See pricing.
- ISO 27001 documents
-
36
ISO 27001 documents
tiered by what you actually need
- ISO 42001 documents
-
21
ISO 42001 documents
for AI management systems
- Clauses and controls mapped
-
182
Clauses and controls mapped
every document cites the ones it satisfies
- Verifiers per section
-
3
Verifiers per section
on a different model to the writer
AI policy template FAQ
The questions people ask
Including the difference between a usage policy and an ISO 42001 system.
Do I need an AI policy for ISO 42001?
Yes, and more than one. ISO/IEC 42001 is a management-system standard: it expects a top-level AI policy plus supporting documents - roles and responsibilities, an AI risk assessment and an AI system impact assessment, data governance for AI, and a transparency policy, among others. A single staff acceptable-use policy is a good start but does not, on its own, satisfy the standard.
Is a free AI policy template enough for an audit?
No. A free template gets your acceptable-use rules on paper, which is worth doing. But an ISO 42001 audit looks for a whole AI management system, tailored to the AI you actually use and mapped to the standard's requirements. A generic template cannot show that, which is why auditors flag copied templates. PolicyMint generates the full, tailored set instead.
What is the difference between an AI usage policy and an AI management system policy?
An AI usage (acceptable-use) policy tells staff how they may use AI tools day to day. An AI management system policy is the top of an ISO 42001 system: it sets the organization's AI governance intent and commitments, and directs the risk assessments, roles, transparency and data rules beneath it. You typically need both - the usage policy for people, the management system for the audit.
How much does an ISO 42001 policy set cost?
A certifiable ISO 42001 or ISO 27001 set is around 36 documents. PolicyMint covers it with a single one-time pack of A$350US$229£179€209 including GST, about A$8.75US$5.73£4.48€5.23 per finished document, a fraction of a static toolkit and with no ongoing platform subscription. Your first document is free.
Can I use the example wording on this page commercially?
Yes. The guide and the example clauses on this page are free to adapt and use inside your organization, including commercially - that is what they are for. They are illustrations of wording that holds up, not a finished policy: you still write the document in your own language, naming your tools, your roles and your review cycle. When you want the audit-ready ISO 42001 set behind it, that is what PolicyMint generates.
Stop staring at an empty document set
Set up your business once. Get the documents you actually need, written for how you really operate, in your branding, checked before you see them.
Your first document is on us. We ask for a card to begin and you are not charged for it, and there is no sales call. See pricing