Policy Register

AI use policy (acceptable AI use)

Which AI tools people may use, for what, with which data, what must be checked by a person, and what must never be entered or relied on.

How the register reads it

Also calledgenerative AI policy, AI acceptable use, use of AI tools
FamilyAI and automated decisions
Document typePolicy. The regimes ask for the content, not the label; a line pasted as a standard, procedure, plan or schedule is placed here with the label noted.
Expected ownerThe AI governance lead (CTO, CDO or head of data science).
Review cadenceAnnual (the register's default: the clauses say planned intervals and on significant change, and do not fix a period).
On the gap list whenISO 42001 is ticked and no line resolves to it (ISO 27001 requires it too, inside a parent document, so it does not list it separately).
TemplateAi acceptable use policy.

Which standards require it, and what each expects it to contain

4 requiring clauses, 2 regimes

Shown on a register for the regimes you tick; with none ticked, ISO 27001 is applied. Requirement text drawn from a human-verified compliance corpus under licence: the corpus statement of each clause, not the instrument verbatim.

ISO/IEC 27001:2022

ISO 27001 5.10 Acceptable use of information and other associated assets

Define and enforce rules for how information and assets may be used and handled.

What the ISO 27002 guidance expects the document to say: Requires rules for acceptable use, and procedures for handling information and its associated assets, to be identified, documented and put into effect.

Evidence an auditor accepts: The acceptable use rules, covering personal use, removable media, cloud storage, email, messaging and use of artificial intelligence services where relevant; handling procedures per classification level, covering storage, transmission, printing, sharing and destruction; evidence rules were communicated and accepted by personnel and by third parties given access
Common gap: Policy not reviewed or updated regularly
Source: ISO/IEC 27001:2022; guidance ISO/IEC 27002:2022

ISO/IEC 42001:2023

ISO 42001 A.2.2 AI policy

The organization shall document a policy for the development, deployment, or use of AI systems that aligns with the organization's strategic direction.

Evidence an auditor accepts: AI policy; approval records; aI-specific policy (distinct from general IT policy)
Common gap: Does the AI policy address AI-specific concerns beyond restating IT policy?
Source: ISO/IEC 42001:2023
ISO 42001 A.9.2 Processes for responsible use of AI systems

The organization shall define and document processes for the responsible use of AI systems, including processes for the use by employees of AI systems provided by third parties.

Evidence an auditor accepts: Responsible use procedure; acceptable use policy for AI; training records
Source: ISO/IEC 42001:2023
ISO 42001 A.9.4 Intended use of the AI system

The organization shall ensure that the AI system is used according to the intended uses of the AI system and its accompanying documentation.

Evidence an auditor accepts: Intended use statements; use case approval records; monitoring of use
Common gap: Is off-label use detected and addressed?
Source: ISO/IEC 42001:2023

Do this for every document on your list

Paste the list and get this reading for every document at once, with the owner and cadence against each, the clauses quoted, and the documents the regimes expect that the list does not carry. Eight documents free, no account.

Build a register

AI system impact assessment procedure · Automated decision-making procedure