Sample template. A starting point to adapt to your organization — not legal advice, and not a finished or binding document. Review with your own counsel before you rely on it.
AI governance policy template
Updated
An AI governance policy sets the rules for how your organization adopts and uses AI: which tools are approved, what data may go into them, who is accountable, and how AI-assisted decisions are overseen. This template gives you a section outline you can adapt, structured to close the gaps that emerging standards — ISO/IEC 42001 and the NIST AI Risk Management Framework — are built around.
The point of the policy is to make the sanctioned path clear and fast, so people do not route sensitive data through ungoverned tools (shadow AI). Adapt each section to your context rather than adopting it verbatim; a policy that does not match how your teams actually work will be ignored, which is worse than having none.
Policy section outline
A workable AI governance policy covers the sections below. Keep it concrete — name the approved tools and the data rules — because vague policies do not change behavior. Pair it with a lightweight intake so new tools have an obvious front door rather than being adopted in the shadows.
| Section | What it should cover |
|---|---|
| Purpose & scope | Why the policy exists and which systems, teams, and uses it covers |
| Roles & accountability | Who owns AI risk, approves tools, and is accountable per system |
| Approved tools & intake | The sanctioned AI tool catalog and how to request a new one |
| Data handling | What data classes may/may not be entered into AI tools; no secrets or regulated data without controls |
| Human oversight | Where a human must review AI output before it is relied on |
| AI inventory | Requirement to record AI systems, models, data, and prompts (an AI-BOM) |
| Provenance & records | What must be logged so an AI-assisted decision can be reconstructed |
| Third-party & procurement | Diligence for vendors whose products embed AI |
| Prohibited uses | Uses that are never permitted (e.g., fully automated high-stakes decisions) |
| Review & exceptions | How the policy is reviewed and how exceptions are requested and recorded |
Aligning to ISO 42001 and the NIST AI RMF
Both leading AI frameworks assume you can enumerate and manage your AI. ISO/IEC 42001 frames AI management as a lifecycle over identified systems; the NIST AI RMF centers on mapping, measuring, and managing AI risk. The inventory and provenance sections of this policy are what make those requirements achievable — you cannot govern the lifecycle of a system you have not recorded.
Treat the policy as living. AI capability and your usage change quickly, so build in a regular review and a real exceptions process. A policy reviewed annually with a clear path to add tools stays relevant; one written once and frozen becomes the reason people work around it.
Frequently asked questions
What should an AI governance policy include?
Purpose and scope, roles and accountability, an approved-tools catalog with an intake process, data-handling rules, human-oversight requirements, an AI inventory (AI-BOM), provenance and record-keeping, third-party diligence, prohibited uses, and a review-and-exceptions process. The concrete sections — named tools and specific data rules — are what actually change behavior.
How does an AI governance policy relate to ISO 42001 and the NIST AI RMF?
Both frameworks assume you can enumerate and manage your AI systems. ISO 42001 manages AI as a lifecycle over identified systems; the NIST AI RMF maps, measures, and manages AI risk. A policy's inventory and provenance requirements are what make those achievable, since you cannot govern a system you have not recorded.
How do you stop shadow AI with a policy?
By making the sanctioned path faster than the unsanctioned one: a clear approved-tool catalog, a lightweight intake for new tools, and visibility into usage. A policy that only prohibits pushes usage underground; one that gives people an easy, approved way to adopt AI brings that usage into governance.