Approved tools
A short, current list of what staff may use for work, at which tier, and for what kind of information. Short enough that people can remember it; specific enough to be enforceable.
Access control
AI tools reached through your identity provider, with the same conditional access, device requirements and revocation as any other business application.
Identity
Every AI system and agent has a named identity — a person's or a service's — so actions are attributable, reviewable and revocable without disrupting anyone else.
Data boundaries
Explicit rules on what categories of information may go to which tools. Personal data, client confidential material and commercially sensitive pricing are the ones that need naming.
Audit logs
A record of what was used, by whom, against what data. Without this you cannot answer a client question, satisfy an auditor or scope an incident.
Retention
How long prompts, uploads and outputs are retained by the vendor and by you, aligned with your existing retention schedule rather than left to a default.
AI policy
Two pages that a member of staff will actually read, covering what is permitted, what is not, and what to do when they are unsure. Not a twelve-page document nobody opens.
Vendor assessment
A proportionate review of an AI vendor before adoption: data location, retention, training use, sub-processors, security posture and what happens to your data if you leave.
Model and data considerations
Where the model runs, whether your inputs contribute to training, what happens to embeddings and indexes of your documents, and whether the arrangement matches what you have told your own clients.
Human oversight
Named accountability for AI use, defined review points for consequential output, and a route for staff to raise concerns without it being treated as an admission of misuse.