Policy & Governance
Acceptable AI Use and Prohibited Practices Policy
What this control does
Define organisational rules for acceptable AI use, prohibited practices and escalation.
How to implement
Set out which AI uses are allowed, restricted or prohibited within the organization and how personnel should obtain advice. Assign a policy owner and connect the policy to procurement, development and deployment approvals. Describe escalation and enforcement actions for unapproved use. Give staff examples relevant to their work and keep the policy aligned with the current prohibition screening. A policy supports the linked restrictions but does not replace technical controls, monitoring or legal assessment.
Suggested timing and triggers
At initial approval; after material regulatory or use changes; periodic review, with an annual cycle as a suggested starting point.
Evidence examples
Approved acceptable-use policy and version history Role-specific communications and acknowledgements Links to use-case approvals and screening records Records of exceptions, enforcement and corrective actions
How to check this control
Choose a policy restriction and trace it to an approval check or operational safeguard. Ask a relevant user how to obtain advice. Check that a recent policy change reached the affected teams.