AI governance policy: what it must contain and how to write one

An AI governance policy is the top-level statement of how your organisation uses, oversees and takes accountability for AI. This guide covers what it must contain for ISO 42001 clause 5.2 and the EU AI Act, a section-by-section template, and how to roll it out.

The short answer: An AI governance policy is the top-level document in which leadership sets out why the organisation uses AI, what it will and will not use it for, who is accountable, and how AI risk, data, human oversight and incidents are handled. It is the policy that ISO/IEC 42001 clause 5.2 requires, and the anchor the rest of your AI management system hangs from. It is short, signed by top management, and backed by procedures that do the detailed work.

Two years ago an AI policy was a paragraph in the staff handbook. Now it is a line on customer security questionnaires, the first document an ISO 42001 auditor reads, and what a regulator asks for when an automated decision goes wrong. Most organisations have a one-page "be careful with ChatGPT" note that names no owner and covers no vendor tool. That is an acceptable-use note, and it will not carry the weight now being put on it.

{{snapshot}}

AI governance policy at a glance

  • One policy, procedures underneath. The governance policy states intent and accountability; the acceptable-use policy tells staff what they may do; procedures and controls do the work.
  • ISO 42001 clause 5.2 requires it. Top management must establish an AI policy that fits the organisation's purpose, frames AI objectives, and commits to meeting requirements and to continual improvement.
  • Annex A backs it up. Objective A.2 covers the AI policy, its alignment with other policies and its review; A.3 covers roles and the reporting of concerns.
  • Scope must include bought AI. Vendor features, embedded copilots and the tools staff sign up for on a company card all count.
  • The EU AI Act reads it too. AI literacy duties applied from February 2025; most high-risk obligations follow from August 2026.

{{/snapshot}}

Governance policy, acceptable-use policy, governance framework: which one do you need?

All three, and they are not interchangeable. People use "AI policy" to mean any of them, which is how a staff memo ends up doing the job of a management system.

The AI governance policy is the board-level statement. It sets principles, objectives, scope, accountability and the commitments the organisation is prepared to be measured against, for staff, customers, regulators and auditors alike. Two to four pages, signed at the top.

The AI acceptable-use policy is operational and addressed to staff. Which tools are approved, what data may go into them, what to do when the output looks wrong. It changes often, which is exactly why it should not be welded to the governance policy.

The AI governance framework is the whole structure: policy, roles, risk method, inventory, controls, evidence, review. We have written separately on building an AI governance framework and on why an AI policy on its own is not governance. A policy nobody can map to an owner, a control and a piece of evidence is a document, and auditors do not certify documents.

What ISO 42001 clause 5.2 and the EU AI Act actually ask for

ISO/IEC 42001:2023 follows the same harmonised structure as ISO 27001, so clause 5.2 does the same job in both: it requires top management to establish an AI policy. The policy must be appropriate to the purpose of the organisation, provide a framework for setting AI objectives, and commit to satisfying applicable requirements and to continual improvement of the AI management system. It must be documented, communicated internally and available to interested parties where appropriate.

Annex A then adds teeth. Control objective A.2 requires an AI policy, its alignment with other organisational policies and its planned review. Objective A.3 requires defined AI roles and responsibilities and a process for reporting concerns. A.9 covers responsible use of AI systems and A.10 third-party and customer relationships. An auditor will trace each back to the policy, so the policy should point at them. Our guide to ISO 42001 clauses 4 to 10 walks through the full set, and the AI management system hub explains how the policy sits inside the AIMS.

The EU AI Act does not use the words "governance policy" anywhere, but its obligations assume one exists. Article 4 has required providers and deployers to ensure AI literacy among staff since February 2025, which is hard to evidence without a policy and a training record. Deployers of high-risk systems must assign human oversight to competent people, monitor operation and report serious incidents, mostly from August 2026. A policy that already names oversight roles, a monitoring cadence and an incident route is a large share of that paperwork done early.

In the UK there is no single AI statute. The ICO's guidance on AI and data protection is the practical reference for anything that processes personal data, including automated decision-making under UK GDPR. Cite it by name rather than gesturing at "applicable law".

The section-by-section template

Each row is a section of the policy. The last column is what that section evidences, so you can show an auditor the mapping rather than describe it.

Policy sectionPurposeWhat to writeISO 42001 clause or Annex A objective
Purpose and principlesState why the organisation uses AI and the values it holds itself toThree to five testable principles: fairness, transparency, accountability, safety, privacyClause 5.2; A.2
ScopeDefine which AI systems, uses and people the policy coversBuilt, bought and embedded AI; all staff and contractors; named exclusions with reasonsClause 4.3; A.2
Roles and accountabilityMake one person answerable for each system and for the programmeExecutive sponsor, AI governance lead, AI system owner, risk owner, legal and data protection reviewClause 5.3; A.3
Acceptable and prohibited usesDraw the lines staff and product teams must not crossApproved use categories, prohibited practices (mirroring EU AI Act Article 5 where relevant), approval route for new usesA.9
Risk and impact assessmentCommit to assessing every AI system before and during useReference to the AI risk method and the AI system impact assessment; who signs off; review triggersClause 6.1; A.5
Human oversightGuarantee a person can intervene where it mattersWhere a human must review, override or approve output; competence required; how overrides are loggedA.6; A.9
Data, privacy and intellectual propertyControl what goes in and who owns what comes outData permitted per tool tier, lawful basis, provenance of training data, ownership of generated output, confidentialityA.7; UK GDPR
Third-party AI and suppliersTreat bought AI as in scopeDue diligence questions, contract clauses on model changes, data use and region, mandatory inventory entryA.10
Incidents and concernsGet bad news to the right people fastDefinition of an AI incident, reporting route and timelines, link to the security incident processA.3; A.6
Training and communicationMake the policy real for the people it bindsRole-based training, attestation on joining and annually, where the current version livesClauses 7.2 to 7.4; EU AI Act Article 4
Review and improvementKeep it currentReview cadence (at least annually plus triggers), version control, who approves changesClause 10; A.2

Keep the policy at the level of commitments and push the detail into procedures. "We assess every AI system before deployment" belongs in the policy. The scoring scale does not. Our guides to running an AI risk assessment and AI risk management cover what those procedures need to contain.

Scope: the AI you know about and the AI you don't

Most first drafts fail on scope, because they only cover the AI the IT team bought on purpose. Write it in three bands.

Systems you build or fine-tune. Models, agents and features your engineers ship, including anything wrapped around a third-party API. These get the full treatment: impact assessment, testing, monitoring, documentation.

AI you buy. Standalone AI tools plus the AI features inside software you already own: the CRM's summariser, the meeting-notes bot, the copilot that appeared in your office suite after an update. If it processes your data or shapes a decision, it is in scope, and the supplier contract is a control.

Shadow AI. Tools staff sign up to without asking. The policy should require registration of any AI tool used for work, offer an approval route fast enough that registering is worth the bother, and state plainly that unregistered tools handling company or customer data are prohibited. Build the inventory before you finalise the scope; the first pass usually turns up twice as many tools as anyone expected.

Rolling it out: ownership, approval, training, review

Four moments decide whether a policy becomes real or quietly dies.

Ownership. Name one accountable owner for the policy, usually the AI governance lead or the CISO, and one owner for each AI system on the inventory. Shared ownership is no ownership, and auditors know it.

Approval. Clause 5.2 makes this top management's policy, so it needs a board or executive signature, a version number and a date. Record the approval as a minute, not an email thread.

Training and attestation. Every person the policy binds reads it, is trained on the parts relevant to their role, and confirms both. Developers need the life-cycle and testing sections, everyone needs the acceptable-use rules. The EU AI Act's AI literacy duty makes this a legal expectation for anyone in its reach.

Review. Annually at minimum, plus triggers: a new high-impact use case, a significant incident, a regulatory change, a supplier changing its model or terms. Log each review even when nothing changes. Silence is a finding.

Hicomply's policy management module holds policy templates mapped to ISO 42001 controls, tracks versions and approvals, and records staff attestation, so you can show who read what and when. HealthBoxHR used policy and procedure templates linked to controls to go from nothing in place to ISO/IEC 27001:2022 certification in 12 weeks; the AI policy set follows the same pattern. Our guide to AI governance tools sets out what a platform should do beyond storing a PDF.

Mistakes that turn a policy into shelfware

Copying a template and changing the logo. Principles that do not describe how your organisation actually makes decisions are a finding waiting to happen.

Writing it for the auditor instead of the staff. If a new starter cannot read it in ten minutes and know what they may do, it will be ignored, and an ignored policy is a written record of a rule you do not enforce.

Prohibiting everything. A blanket ban drives AI use underground. Say what is allowed, make approval quick, and reserve prohibition for the practices that warrant it.

Leaving out incidents. Someone will paste a client contract into a public model. The only question is whether they tell you. A blame-light reporting route is the cheapest control you will ever write.

Never mapping it to controls. Each commitment in the policy should trace to a control, an owner and a piece of evidence. The ISO 42001 checklist confirms nothing in Annex A has been left without a home.

{{snapshot}}

Hicomply's take

We have read a lot of AI policies this year and most share one fault: they are acceptable-use notes dressed up as governance. The ones that work are short, signed at the top, and honest about scope, including the tools nobody in IT approved. Write the policy last, not first. Build the inventory, run a first-pass risk assessment, decide who owns what, then write down what you have decided. A policy that describes a system which exists will pass audit. A policy that describes a system you intend to build one day will not, and everyone in the room will know it.

{{/snapshot}}

Get your AI governance policy signed, mapped and evidenced

The policy is easy to write and hard to keep alive. Templates, versioning, attestation and control mapping turn a draft into something an auditor can rely on.

Run the free ISO 42001 readiness assessment to see where your policy set stands, then book a demo to see the policy templates, control mapping and attestation trail on one platform. Bring your current AI policy, however short. Short is fixable.

Ready to Take Control of Your Privacy Compliance?

Hicomply’s platform provides an all-in-one solution to streamline, automate, and centralise your compliance activities, ensuring complete control and efficiency.

Book a demo
Last updated
August 2026
Category
AI Governance
Topics
Lucy Murphy
Head of Customer Success

Lucy works closely with customers to help them get the most out of the Hicomply platform, from onboarding to audit success. She brings a user-focused mindset to everything she does, making her well-placed to write about day-to-day challenges, shortcuts, and success strategies. Her content is grounded in what real InfoSec and compliance teams need to know — and how to get there faster.Expect helpful walkthroughs, product tips, and practical insights.

Read more industry insights by Lucy Murphy

Popular ISO 42001 queries, answered!

What is an AI governance policy?

An AI governance policy is the top-level document, approved by senior management, that states why your organisation uses AI, which systems and people it covers, who is accountable, what uses are permitted or prohibited, and how risk, data, human oversight, incidents and review are handled. Under ISO/IEC 42001 clause 5.2 it is a mandatory requirement, and detailed procedures sit beneath it.

What is the difference between an AI governance policy and an AI acceptable use policy?

The governance policy is the board-level statement of principles, scope, accountability and commitments, addressed to staff, customers, regulators and auditors. The acceptable use policy is operational guidance for staff: which tools are approved, what data may be entered, and what to do when output is wrong. Keep them separate, because the acceptable use rules change far more often than the governance commitments.

Does ISO 42001 require an AI policy?

Yes. Clause 5.2 of ISO/IEC 42001:2023 requires top management to establish an AI policy that is appropriate to the organisation's purpose, provides a framework for AI objectives, and commits to meeting applicable requirements and to continual improvement. Annex A objective A.2 adds controls for the policy itself, its alignment with other policies and its scheduled review.

What should an AI governance policy include?

At minimum: purpose and principles, scope covering built, bought and shadow AI, named roles and accountability, acceptable and prohibited uses, a commitment to risk and impact assessment, human oversight requirements, rules on data, privacy and intellectual property, third-party AI due diligence, incident and concern reporting, training and attestation, and a review cadence with version control and an approving authority.

How often should an AI governance policy be reviewed?

Review it at least annually, and sooner when a trigger occurs: a new high-impact AI use case, a significant AI incident, a regulatory change such as an EU AI Act obligation coming into force, or a supplier changing its model or terms. Record every review, including those that result in no change, because the review record itself is audit evidence under ISO 42001.

Your ISO 42001 Compliance Newsletter

Stay ahead with the latest expert insights, news, and updates on compliance.
Decorative