Corporate AI Governance Policy
Generated 30 July 2026 · Confidential — AuditSentinel Policy Builder
§1 Data Classification & IP Protection Strict
1.1 Scope. This policy applies to all employees, contractors, consultants, temporary staff, and third-party vendors who have access to corporate data or systems. It governs the submission of any organisational data — regardless of format or storage medium — into artificial intelligence tools, including large language models, generative AI platforms, code generation assistants, and image or audio generation services. Compliance with this policy is a condition of data access and employment.
1.2 Permitted Use. Employees may submit non-sensitive operational data to approved AI tools for legitimate business purposes. Permitted data includes publicly available information, aggregated and anonymised datasets, general business correspondence that does not contain customer or financial data, and synthetic test data created explicitly for AI evaluation. Any data submitted must be limited to the minimum necessary to accomplish the specific business task.
1.3 Prohibited Use. Under no circumstances may employees submit the following categories of data to any AI tool: proprietary source code, API keys, encryption keys, customer production data, or unreleased product specifications. Additionally, any data subject to a non-disclosure agreement, litigation hold, or regulatory restriction may not be submitted. The prohibition extends to all forms of input — typed prompts, file uploads, API calls, clipboard pastes, and screen sharing with AI tools — regardless of whether the tool claims to delete or not retain input data.
1.4 Enforcement and Consequences. Violation of this policy constitutes a disciplinary matter subject to the organisation's formal HR disciplinary process. Consequences may include mandatory retraining, revocation of system access, formal written warning, suspension, and — in cases of knowing or reckless violation resulting in material harm — termination of employment or contract. The Chief Information Security Officer (CISO) maintains a register of policy violations and reports material incidents to the Audit Committee quarterly.
1.5 Exceptions Process. Employees who require an exemption from this policy for a specific business use case must submit a written request to their department head and the CISO. The request must detail the data categories involved, the specific AI tool and vendor, the business justification, and the proposed duration of the exemption. Exemptions require written approval from both the department head and the CISO, must specify a defined expiry date not exceeding 90 days, and are logged in the corporate policy exemption register.
§2 Approved Tooling & Vendor Management Strict
2.1 Approved Vendors. Only enterprise-tier AI vendors that have executed a Data Processing Agreement (DPA) with the organisation, commit to zero-data-retention for model training, and provide contractual IP indemnification are approved for use with corporate data. The IT department maintains a published register of currently approved AI vendors accessible via the corporate intranet. Approved vendors are re-reviewed at minimum quarterly, or immediately upon any material change to their terms of service, privacy policy, or data handling practices.
2.2 Prohibited Vendors. Use of public or free-tier AI tools — including consumer-grade chatbots, AI-powered browser extensions, mobile AI applications, and any AI service that does not provide a signed DPA — is strictly prohibited for all organisational purposes. This includes uploading corporate documents to free transcription services, pasting code into public code-generation tools, and querying free-tier LLM interfaces with any data that could reasonably be linked to the organisation. The prohibition applies regardless of the perceived sensitivity of the input.
2.3 Vendor Review Process. Requests to add a new AI vendor to the approved register must be submitted to IT via the corporate service desk. The review process includes: (a) a security assessment conducted by the Information Security team evaluating the vendor's data handling, encryption, access controls, and breach history; (b) a legal review of the vendor's terms of service, DPA, and IP indemnification provisions; and (c) procurement sign-off confirming budget availability and commercial terms. The review timeline is 10 business days for standard requests; urgent requests may be expedited with CISO approval.
2.4 Free Trial Policy. Employees are prohibited from signing up for free trials, freemium tiers, or evaluation accounts of any AI tool using their corporate email address, corporate credentials, or corporate payment instruments. AI tool evaluation must be conducted through the formal vendor review process described in §2.3. IT may provision sandboxed evaluation environments for approved vendor assessments; these environments are isolated from production data and systems.
2.5 Vendor Monitoring. IT maintains a centralised register of all approved AI vendors, including contract dates, DPA status, data retention commitments, and assigned business owners. Each vendor is re-reviewed at minimum quarterly. The re-review examines changes to terms of service, privacy policy updates, security incident disclosures, and any regulatory actions against the vendor. Vendors that no longer meet the organisation's requirements are removed from the approved register and their access is revoked within 5 business days.
§3 Procurement & Provisioning Strict
3.1 Centralised Provisioning. All AI software seats, licenses, and subscriptions must be provisioned through the central IT procurement process. Individual employees, departments, and business units are strictly prohibited from purchasing AI tool access using corporate credit cards, personal cards with expense reimbursement, or any procurement channel outside the central IT workflow. All AI tool spend must be captured in a dedicated cost centre for visibility and audit.
3.2 Budget Approval. AI tool procurement with total contract value exceeding £5,000 per annum requires written approval from the relevant department head and the Chief Information Officer. Procurement exceeding £25,000 per annum additionally requires Finance Director sign-off. Budget holders must confirm that the AI tool is necessary for operational requirements and that no existing approved tool meets the same need before initiating procurement.
3.3 License Management. IT maintains a current inventory of all AI tool seats and licenses, including assigned users, cost per seat, contract renewal dates, and utilisation metrics. License utilisation is reviewed monthly; seats unused for more than 30 consecutive days are flagged for reassignment or cancellation. Department heads receive a quarterly license report detailing their team's AI tool access and spend.
3.4 Shadow IT Detection. The Finance department conducts quarterly audits of all corporate expense reports, accounts payable records, and procurement card statements to identify payments to unrecognised AI vendors. Any payment to an AI tool vendor not on the approved register is escalated to the CISO and department head for investigation. A summary of shadow IT findings is reported to the Audit Committee semi-annually.
3.5 New Hire Provisioning. AI tool access is not provisioned for new employees, contractors, or vendors until they have: (a) signed the Acceptable Use Policy, (b) completed the mandatory AI Governance and Data Handling training module, and (c) received written confirmation from IT that access has been granted. No employee may share their AI tool credentials or seats with colleagues; each user must have an individually assigned and auditable account.
§4 Incident Response & Breach Protocol
4.1 Immediate Actions. Upon discovery or reasonable suspicion of unauthorised data submission to an AI tool, the discovering party must immediately: (a) disconnect or suspend the affected user account from all AI tool access; (b) notify the CISO and the Data Protection Officer within one hour of discovery; and (c) preserve all relevant evidence, including system logs, browser history, API call records, screenshots, and any communications related to the incident. No evidence may be deleted, modified, or overwritten.
4.2 Investigation Requirements. The CISO, or their designated incident response lead, shall initiate a formal investigation within 4 hours of notification. The investigation must determine: (a) precisely what data was submitted to which AI vendor; (b) the method and timeframe of submission; (c) the number of data subjects or records potentially affected; (d) whether the vendor's data retention policy permits deletion of submitted data; and (e) whether the incident was isolated or part of a pattern. Investigation findings must be documented in a formal incident report within 72 hours.
4.3 Regulatory Reporting. Where applicable, the organisation shall comply with statutory breach notification requirements. Under the UK GDPR and EU GDPR, notifiable breaches involving personal data must be reported to the Information Commissioner's Office within 72 hours of discovery. Under the EU AI Act, serious incidents involving AI systems must be reported to the relevant market surveillance authority. Additionally, customer contractual breach notification may impose supplementary reporting obligations. The Data Protection Officer is responsible for determining notification requirements and executing all regulatory filings.
4.4 Remediation. Following the investigation, the organisation shall: (a) request in writing that the AI vendor delete all submitted data from their systems and confirm deletion in writing; (b) require the involved employee(s) to complete mandatory retraining on the AI Acceptable Use Policy before access is reinstated; (c) update this policy if the incident reveals a control gap not previously addressed; and (d) revise employee training materials to incorporate lessons learned from the incident. Vendor deletion confirmations must be retained for audit purposes.
4.5 Post-Incident Review. Within 14 calendar days of incident closure, the CISO shall convene a post-incident review meeting with representatives from Information Security, Legal, IT, and the affected business unit. The review shall produce: (a) a root cause analysis identifying the control weakness that permitted the incident; (b) a remediation plan with assigned owners and deadlines; (c) an assessment of whether the incident is material and requires notification to the Board of Directors or Audit Committee; and (d) a summary for the corporate risk register. Material incidents are reported to the Board at the next scheduled meeting.