ISO 9001:2026 was published on 16 September. See what changed →


What Should Actually Be in an AI Governance Policy

Most of the advice circulating about AI governance stops at “you should have a policy.” It rarely gets to the next question, which is the one that actually matters: what goes in it. An AI policy that is one paragraph telling staff to “use AI responsibly” is not a policy. It is a wish. A real one has to answer specific questions, in writing, before anyone in the business can be expected to follow it consistently.

This matters more than it might seem, because ISO/IEC 42001, the international standard for AI management systems, does not treat the AI policy as a formality either. Clause 5.2 of the standard requires an organisation to develop this policy and make sure it is actually understood across the business, not just filed away.

The four things a real AI policy has to cover

Drawing on how ISO 42001 itself frames AI governance, and on guidance like Torys LLP’s AI policy checklist, a genuinely usable AI policy needs to answer four questions, not just gesture at them.

  • Accountability. Who in the business actually owns AI decisions? Who signs off before a new AI tool gets used on real client work, and who is responsible if something goes wrong? If the honest answer is “nobody specifically,” that is the first gap to close.
  • Transparency. Where is AI actually being used in the business, and does anyone outside that person’s desk know about it? This covers what data goes into AI tools, what the tool is allowed to be used for, and whether clients or staff need to be told when AI was involved in producing something.
  • Security. What happens to information once it is typed into an AI tool? Many free AI tools use what you type to train their models, which means confidential client information can end up somewhere it was never meant to go. The policy needs to say plainly what can and cannot be entered into an AI system.
  • Risk mitigation. What is the process when an AI tool gets something wrong, produces something biased, or is used in a way nobody approved? A policy without an answer to “what happens when this fails” only works when nothing ever does.

Why a vague policy is worse than no policy

A one-line policy that says “use AI tools responsibly” creates a false sense that the risk has been handled, without actually reducing it. Staff still don’t know which tools are approved, what information is safe to enter, or who to ask when they’re unsure. When something eventually goes wrong, a vague policy also offers the business no real defence, because it never specified what “responsible” was supposed to mean in practice.

The businesses that get real value from AI policy are not the ones with the longest document. They’re the ones where a new staff member could read the policy on their first day and know exactly which tools they’re allowed to use, what they can and cannot type into them, and who to go to if something feels off.

Where this sits inside ISO 42001

For businesses formally pursuing ISO/IEC 42001 certification, this policy work is not optional paperwork sitting alongside the real implementation, it is one of the standard’s core leadership requirements. Getting the policy genuinely right, with clear ownership and specific rules rather than general encouragement, is also most of the groundwork needed for the rest of an AI management system to function.

For businesses not pursuing formal certification but simply trying to use AI tools without creating unnecessary risk, the same four questions still apply. Certification changes how it gets documented and audited. It does not change what actually needs to be decided.

The bottom line

An AI policy is not a compliance checkbox and it is not a warning label. It is a working document that tells people in a business exactly who decides, what is visible, what is protected, and what happens when something goes wrong. A business that can answer those four questions in writing has a real policy. A business that cannot has a sentence pretending to be one.

Sources

Torys LLP — What should be included in my organization’s AI policy?

RSI Security — The 10 Comprehensive Clauses of ISO 42001



Leave a Reply

Your email address will not be published. Required fields are marked *