AI Governance Policy Builder
Build internal AI governance policies from scratch. Covers acceptable use, model selection, data handling, vendor contracts, compliance mapping, and board reporting.
When to Use
- Writing or reviewing internal AI acceptable use policies
- Establishing AI governance committees or review boards
- Mapping AI usage to regulatory frameworks (EU AI Act, NIST, ISO 42001)
- Evaluating vendor AI terms and liability clauses
- Preparing board-level AI governance reports
Governance Policy Framework
1. Acceptable Use Policy (AUP)
Every organization running AI needs a written AUP covering:
Permitted Uses
- List approved AI tools by department and function
- Define data classification tiers (public, internal, confidential, restricted)
- Map which data tiers can enter which AI systems
- Specify approved vendors vs. shadow AI (employees using personal ChatGPT accounts)
Prohibited Uses
- Customer PII in non-SOC2 models without anonymization
- Autonomous financial decisions above $[threshold] without human review
- HR screening/scoring without bias audit documentation
- Any use violating sector regulations (HIPAA, GDPR, SOX, PCI-DSS)
Shadow AI Detection
| Signal |
Risk Level |
Action |
| API calls to unknown AI endpoints |
HIGH |
Block + investigate |
| Browser extensions with AI features |
MEDIUM |
Audit + approve/deny |
| Personal accounts on company devices |
MEDIUM |
Policy reminder + monitor |
| Exported data to AI training sets |
CRITICAL |
Immediate review |
2. AI Model Selection & Procurement
Evaluation Scorecard (100 points)
| Criteria |
Weight |
What to Check |
| Data residency & sovereignty |
20 |
Where is data processed? Stored? Can you choose region? |
| Security certifications |
20 |
SOC2 Type II, ISO 27001, HIPAA BAA, FedRAMP |
| Model transparency |
15 |
Training data provenance, bias testing, version control |
| Contract terms |
15 |
Data usage rights, indemnification, SLA, exit clauses |
| Performance & cost |
15 |
Latency, accuracy benchmarks, token pricing, rate limits |
| Integration & support |
15 |
API stability, documentation quality, support SLA |
Minimum score for production deployment: 70/100
Red Flags (automatic disqualification):
- Vendor trains on your data without opt-out
- No data processing agreement (DPA) available
- Indemnification excluded for AI outputs
- No incident response SLA
3. Data Handling & Classification
AI Data Flow Audit Template
For each AI integration, document:
- Input data: What goes in? Classification tier? PII present?
- Processing: Where? Which model? Hosted or API? Region?
- Output data: What comes out? Stored where? Retention period?
- Training: Does vendor use your data for training? Opt-out confirmed?
- Logging: Are prompts/responses logged? Where? Who has access?
- Deletion: Can you request data deletion? Verified how?
Data Minimization Checklist
4. Regulatory Compliance Mapping
EU AI Act (effective Aug 2025, enforcement Feb 2025)
| Risk Category |
Examples |
Requirements |
| Unacceptable |
Social scoring, real-time biometric ID (most cases) |
Banned |
| High-risk |
HR screening, credit scoring, medical devices |
Conformity assessment, human oversight, transparency |
| Limited |
Chatbots, deepfakes |
Transparency obligations (disclose AI use) |
| Minimal |
Spam filters, game AI |
No requirements |
NIST AI RMF (Risk Management Framework)
- Map: Identify AI systems in use
- Measure: Quantify risks per system
- Manage: Implement controls proportional to risk
- Govern: Establish oversight structure and accountability
ISO 42001 (AI Management System)
- Useful for organizations wanting certified AI governance
- Aligns with ISO 27001 (already have it? Easier path)
- Covers: AI policy, risk assessment, objectives, competence, documentation
5. AI Governance Committee Structure
Recommended Composition
- Chair: CTO or Chief AI Officer
- Legal: 1 representative (contracts, compliance)
- Security: CISO or delegate (data protection, incident response)
- Business: 1-2 department heads (use case prioritization)
- Ethics: External advisor or designated internal role
- Finance: CFO delegate (budget, ROI tracking)
Meeting Cadence
- Monthly: Review new AI use cases, vendor changes, incidents
- Quarterly: Policy updates, compliance audit, budget review
- Annually: Full governance framework review, board report
Decision Authority
| Decision |
Authority Level |
| New AI tool (< $5K/year) |
Department head + security review |
| New AI tool (> $5K/year) |
Governance committee approval |
| Customer-facing AI |
Committee + legal + CEO sign-off |
| AI incident response |
Security lead (immediate) → Committee (48h review) |
6. Vendor Contract Checklist
Before signing any AI vendor contract, confirm:
7. Board Reporting Template
Quarterly AI Governance Report
AI GOVERNANCE REPORT — Q[X] [YEAR]
1. AI PORTFOLIO SUMMARY
- Active AI systems: [count]
- New deployments this quarter: [count]
- Retired/replaced: [count]
- Total AI spend: $[amount] (vs budget: $[amount])
2. RISK DASHBOARD
- High-risk systems: [count] — all compliant: [Y/N]
- Open incidents: [count] — resolved this quarter: [count]
- Shadow AI detections: [count] — remediated: [count]
- Compliance gaps: [list]
3. VALUE DELIVERED
- Hours saved: [estimate]
- Revenue attributed to AI: $[amount]
- Cost reduction: $[amount]
- Customer satisfaction impact: [metric]
4. KEY DECISIONS NEEDED
- [Decision 1: context + recommendation]
- [Decision 2: context + recommendation]
5. NEXT QUARTER PRIORITIES
- [Priority 1]
- [Priority 2]
8. Incident Response for AI Systems
AI-Specific Incident Categories
| Category |
Example |
Response Time |
| Data breach via AI |
Model leaks PII in output |
Immediate — invoke security IR plan |
| Hallucination causing harm |
Wrong medical/legal/financial advice acted on |
4h — document, notify affected parties |
| Bias detected |
Discriminatory output in hiring/lending |
24h — suspend system, audit, remediate |
| Prompt injection |
Attacker manipulates AI behavior |
Immediate — block vector, patch |
| Cost overrun |
Runaway API calls |
4h — rate limit, investigate, cap |
| Vendor incident |
Provider breach or outage |
Per vendor SLA — activate backup |
Post-Incident Review Template
- What happened (factual timeline)
- Impact (who/what affected, cost, duration)
- Root cause (not blame — systems thinking)
- Fixes applied (immediate + permanent)
- Policy/process changes needed
- Board notification required? (Y/N + rationale)
Cost of NOT Having AI Governance
| Company Size |
Annual Risk Without Governance |
| 15-50 employees |
$50K-$200K (shadow AI waste, compliance fines) |
| 50-200 employees |
$200K-$800K (data incidents, vendor lock-in, redundant tools) |
| 200-1000 employees |
$800K-$3M (regulatory penalties, IP exposure, audit failures) |
| 1000+ employees |
$3M-$15M+ (class action, regulatory enforcement, reputational damage) |
90-Day Implementation Roadmap
Month 1: Foundation
- Draft acceptable use policy
- Inventory all AI systems in use (including shadow AI)
- Classify data flowing through each system
- Identify governance committee members
Month 2: Controls
- Finalize and distribute AUP
- Implement vendor evaluation scorecard for new purchases
- Set up AI incident response procedures
- Begin regulatory compliance mapping
Month 3: Operationalize
- First governance committee meeting
- Deliver first board report
- Establish monitoring for shadow AI
- Schedule quarterly policy review cycle
Built by AfrexAI — AI operations infrastructure for mid-market companies.
Get the full industry-specific context pack for your sector ($47): https://afrexai-cto.github.io/context-packs/
Calculate your AI automation ROI: https://afrexai-cto.github.io/ai-revenue-calculator/
Set up your AI agent workforce in 5 minutes: https://afrexai-cto.github.io/agent-setup/
Need all 10 industry packs? $197 for the complete bundle: https://buy.stripe.com/aEUaGJ2Xd0rI6zKfZ7
1---2name: ai-governance-policy-builder3description: Build internal AI governance policies from scratch. Covers acceptable use, model selection, data handling, vendor contracts, compliance mapping, and board reporting.4---5
6# AI Governance Policy Builder
7
8Build internal AI governance policies from scratch. Covers acceptable use, model selection, data handling, vendor contracts, compliance mapping, and board reporting.
9
10## When to Use
11- Writing or reviewing internal AI acceptable use policies
12- Establishing AI governance committees or review boards
13- Mapping AI usage to regulatory frameworks (EU AI Act, NIST, ISO 42001)
14- Evaluating vendor AI terms and liability clauses
15- Preparing board-level AI governance reports
16
17## Governance Policy Framework
18
19### 1. Acceptable Use Policy (AUP)
20
21Every organization running AI needs a written AUP covering:
22
23**Permitted Uses**
24- List approved AI tools by department and function
25- Define data classification tiers (public, internal, confidential, restricted)
26- Map which data tiers can enter which AI systems
27- Specify approved vendors vs. shadow AI (employees using personal ChatGPT accounts)
28
29**Prohibited Uses**
30- Customer PII in non-SOC2 models without anonymization
31- Autonomous financial decisions above $[threshold] without human review
32- HR screening/scoring without bias audit documentation
33- Any use violating sector regulations (HIPAA, GDPR, SOX, PCI-DSS)
34
35**Shadow AI Detection**
36| Signal | Risk Level | Action |
37|--------|-----------|--------|
38| API calls to unknown AI endpoints | HIGH | Block + investigate |
39| Browser extensions with AI features | MEDIUM | Audit + approve/deny |
40| Personal accounts on company devices | MEDIUM | Policy reminder + monitor |
41| Exported data to AI training sets | CRITICAL | Immediate review |
42
43### 2. AI Model Selection & Procurement
44
45**Evaluation Scorecard (100 points)**
46
47| Criteria | Weight | What to Check |
48|----------|--------|---------------|
49| Data residency & sovereignty | 20 | Where is data processed? Stored? Can you choose region? |
50| Security certifications | 20 | SOC2 Type II, ISO 27001, HIPAA BAA, FedRAMP |
51| Model transparency | 15 | Training data provenance, bias testing, version control |
52| Contract terms | 15 | Data usage rights, indemnification, SLA, exit clauses |
53| Performance & cost | 15 | Latency, accuracy benchmarks, token pricing, rate limits |
54| Integration & support | 15 | API stability, documentation quality, support SLA |
55
56**Minimum score for production deployment: 70/100**
57
58**Red Flags (automatic disqualification):**
59- Vendor trains on your data without opt-out
60- No data processing agreement (DPA) available
61- Indemnification excluded for AI outputs
62- No incident response SLA
63
64### 3. Data Handling & Classification
65
66**AI Data Flow Audit Template**
67
68For each AI integration, document:
691. **Input data**: What goes in? Classification tier? PII present?
702. **Processing**: Where? Which model? Hosted or API? Region?
713. **Output data**: What comes out? Stored where? Retention period?
724. **Training**: Does vendor use your data for training? Opt-out confirmed?
735. **Logging**: Are prompts/responses logged? Where? Who has access?
746. **Deletion**: Can you request data deletion? Verified how?
75
76**Data Minimization Checklist**
77- [ ] Only send minimum necessary data to AI systems
78- [ ] Strip PII before processing where possible
79- [ ] Use synthetic data for testing and development
80- [ ] Implement input sanitization for prompt injection prevention
81- [ ] Audit output for data leakage (model regurgitating training data)
82
83### 4. Regulatory Compliance Mapping
84
85**EU AI Act (effective Aug 2025, enforcement Feb 2025)**
86
87| Risk Category | Examples | Requirements |
88|--------------|----------|-------------|
89| Unacceptable | Social scoring, real-time biometric ID (most cases) | Banned |
90| High-risk | HR screening, credit scoring, medical devices | Conformity assessment, human oversight, transparency |
91| Limited | Chatbots, deepfakes | Transparency obligations (disclose AI use) |
92| Minimal | Spam filters, game AI | No requirements |
93
94**NIST AI RMF (Risk Management Framework)**
95- Map: Identify AI systems in use
96- Measure: Quantify risks per system
97- Manage: Implement controls proportional to risk
98- Govern: Establish oversight structure and accountability
99
100**ISO 42001 (AI Management System)**
101- Useful for organizations wanting certified AI governance
102- Aligns with ISO 27001 (already have it? Easier path)
103- Covers: AI policy, risk assessment, objectives, competence, documentation
104
105### 5. AI Governance Committee Structure
106
107**Recommended Composition**
108- Chair: CTO or Chief AI Officer
109- Legal: 1 representative (contracts, compliance)
110- Security: CISO or delegate (data protection, incident response)
111- Business: 1-2 department heads (use case prioritization)
112- Ethics: External advisor or designated internal role
113- Finance: CFO delegate (budget, ROI tracking)
114
115**Meeting Cadence**
116- Monthly: Review new AI use cases, vendor changes, incidents
117- Quarterly: Policy updates, compliance audit, budget review
118- Annually: Full governance framework review, board report
119
120**Decision Authority**
121| Decision | Authority Level |
122|----------|----------------|
123| New AI tool (< $5K/year) | Department head + security review |
124| New AI tool (> $5K/year) | Governance committee approval |
125| Customer-facing AI | Committee + legal + CEO sign-off |
126| AI incident response | Security lead (immediate) → Committee (48h review) |
127
128### 6. Vendor Contract Checklist
129
130Before signing any AI vendor contract, confirm:
131
132- [ ] Data processing agreement (DPA) signed
133- [ ] Your data is NOT used for model training (or explicit opt-out confirmed)
134- [ ] Data residency requirements met (specify regions)
135- [ ] Indemnification clause covers AI-generated output liability
136- [ ] SLA includes uptime, latency, and support response time
137- [ ] Exit clause: data export format, deletion timeline, transition support
138- [ ] Security certifications current and verified (not expired)
139- [ ] Incident notification timeline specified (72h or less)
140- [ ] Subprocessor list provided with change notification rights
141- [ ] Insurance coverage for AI-specific risks confirmed
142- [ ] Price lock or cap on increases for contract duration
143- [ ] Right to audit (or audit report access)
144
145### 7. Board Reporting Template
146
147**Quarterly AI Governance Report**
148
149```
150AI GOVERNANCE REPORT — Q[X] [YEAR]
151
1521. AI PORTFOLIO SUMMARY
153 - Active AI systems: [count]
154 - New deployments this quarter: [count]
155 - Retired/replaced: [count]
156 - Total AI spend: $[amount] (vs budget: $[amount])
157
1582. RISK DASHBOARD
159 - High-risk systems: [count] — all compliant: [Y/N]
160 - Open incidents: [count] — resolved this quarter: [count]
161 - Shadow AI detections: [count] — remediated: [count]
162 - Compliance gaps: [list]
163
1643. VALUE DELIVERED
165 - Hours saved: [estimate]
166 - Revenue attributed to AI: $[amount]
167 - Cost reduction: $[amount]
168 - Customer satisfaction impact: [metric]
169
1704. KEY DECISIONS NEEDED
171 - [Decision 1: context + recommendation]
172 - [Decision 2: context + recommendation]
173
1745. NEXT QUARTER PRIORITIES
175 - [Priority 1]
176 - [Priority 2]
177```
178
179### 8. Incident Response for AI Systems
180
181**AI-Specific Incident Categories**
182
183| Category | Example | Response Time |
184|----------|---------|---------------|
185| Data breach via AI | Model leaks PII in output | Immediate — invoke security IR plan |
186| Hallucination causing harm | Wrong medical/legal/financial advice acted on | 4h — document, notify affected parties |
187| Bias detected | Discriminatory output in hiring/lending | 24h — suspend system, audit, remediate |
188| Prompt injection | Attacker manipulates AI behavior | Immediate — block vector, patch |
189| Cost overrun | Runaway API calls | 4h — rate limit, investigate, cap |
190| Vendor incident | Provider breach or outage | Per vendor SLA — activate backup |
191
192**Post-Incident Review Template**
1931. What happened (factual timeline)
1942. Impact (who/what affected, cost, duration)
1953. Root cause (not blame — systems thinking)
1964. Fixes applied (immediate + permanent)
1975. Policy/process changes needed
1986. Board notification required? (Y/N + rationale)
199
200## Cost of NOT Having AI Governance
201
202| Company Size | Annual Risk Without Governance |
203|-------------|-------------------------------|
204| 15-50 employees | $50K-$200K (shadow AI waste, compliance fines) |
205| 50-200 employees | $200K-$800K (data incidents, vendor lock-in, redundant tools) |
206| 200-1000 employees | $800K-$3M (regulatory penalties, IP exposure, audit failures) |
207| 1000+ employees | $3M-$15M+ (class action, regulatory enforcement, reputational damage) |
208
209## 90-Day Implementation Roadmap
210
211**Month 1: Foundation**
212- Draft acceptable use policy
213- Inventory all AI systems in use (including shadow AI)
214- Classify data flowing through each system
215- Identify governance committee members
216
217**Month 2: Controls**
218- Finalize and distribute AUP
219- Implement vendor evaluation scorecard for new purchases
220- Set up AI incident response procedures
221- Begin regulatory compliance mapping
222
223**Month 3: Operationalize**
224- First governance committee meeting
225- Deliver first board report
226- Establish monitoring for shadow AI
227- Schedule quarterly policy review cycle
228
229---
230
231*Built by AfrexAI — AI operations infrastructure for mid-market companies.*
232
233Get the full industry-specific context pack for your sector ($47): https://afrexai-cto.github.io/context-packs/
234
235Calculate your AI automation ROI: https://afrexai-cto.github.io/ai-revenue-calculator/
236
237Set up your AI agent workforce in 5 minutes: https://afrexai-cto.github.io/agent-setup/
238
239Need all 10 industry packs? $197 for the complete bundle: https://buy.stripe.com/aEUaGJ2Xd0rI6zKfZ7