What should a company AI governance policy include?

Short answer

An AI governance policy should name the approved AI tools, define which data may and may not be used in them, require human review of AI output that affects customers or decisions, assign an accountable owner, and set a process for approving new tools and reporting incidents. NIST's voluntary AI Risk Management Framework is the most widely used reference for structuring it.

Start with a short acceptable-use policy

Most mid-size companies do not need a 40-page AI program on day one. They need a two-page policy every employee can read and follow, backed by a slightly longer internal standard that IT and leadership own.

The employee-facing policy should answer five questions in plain language: which tools are approved, what data is off limits, when a human must check the output, how to request a new tool, and who to call when something goes wrong.

The core sections

  • Scope: employees, contractors and any AI built into software you already license.
  • Approved tools: a named list, tied to company-managed accounts, not personal sign-ups.
  • Data classification: what is public, internal, confidential and regulated, and which classes each tool may handle, with examples employees will recognize.
  • Human oversight: which outputs require review before use, such as customer communications, contracts, code and regulated records.
  • Accountability: a named owner, usually a senior leader, with IT and legal support.
  • Vendor review: how a new AI tool is assessed for training-data use, retention and security before approval.
  • Incident handling: how to report data put into the wrong tool or a harmful output.

Use the NIST AI RMF as the backbone

NIST released the AI Risk Management Framework (AI RMF 1.0) on January 26, 2023, for voluntary use. It organizes AI risk work into four functions: Govern, Map, Measure and Manage. On July 26, 2024, NIST added NIST AI 600-1, a Generative AI Profile that addresses risks specific to generative AI. NIST notes the AI RMF is currently being revised, so build your policy around the four functions rather than around any one version's wording.

Mapping your policy to these functions gives you a recognized structure if a customer, auditor or investor asks how you manage AI risk.

Make it enforceable, not aspirational

A policy nobody can enforce is a liability. Tie it to technical controls: single sign-on for approved tools, blocking or monitoring unapproved AI sites where practical, sensitivity labels on confidential files, and a quarterly review of what is actually in use. Review the policy itself at least annually, because vendor terms and tools change quickly. Train new hires on it during onboarding, and keep a simple record of who has acknowledged it.

Common follow-up questions

Is the NIST AI RMF mandatory?

No. NIST describes the AI RMF as intended for voluntary use. Companies adopt it because it is a recognized, neutral structure that customers, auditors and boards understand, and because it scales from a small policy to a full program.

Who should own AI governance in a mid-size company?

A named senior leader should be accountable, often the COO, CFO or CIO, with IT running the technical controls and legal reviewing vendor terms. Committees help with input, but one person must own decisions and exceptions.

How often should an AI policy be updated?

Review it at least annually and whenever you approve a major new tool. AI vendors change plans, names and data terms frequently, so the approved-tool list and vendor review notes usually need updating more often than the policy text itself.

Need help with this?

LAN Service Group drafts AI acceptable-use policies and governance standards for small and mid-size businesses and implements the identity, labeling and monitoring controls that make them enforceable.

Talk to LAN Service Group (888) 281-7243

Sources