Policies, Procedures & Forms
AI Usage Policy Template
A generative AI acceptable-use policy template for employees: permitted use, confidential data input restrictions, output review, and accountability — aligned with the direction of ISO/IEC 42001.
- Format
- DOCX
- Size
- 15 KB
- Language
- Indonesian & English
- Price
- Free
Your data is handled in accordance with Indonesia's Personal Data Protection Law. We only send the document you requested and the occasional relevant GRC insight — no spam.
In short
An AI usage policy governs which artificial intelligence tools personnel may use, what data must never be entered into them, and how outputs are verified before use. Without a policy, usage still happens — only without agreed boundaries and without a reviewable trail.
What This Document Is For
A blanket ban on AI tools almost always fails: usage moves to personal devices, beyond monitoring and without records. What remains is not eliminated risk but invisible risk.
This policy takes a different position: name approved tools, draw a firm line around data that must never be entered, and require output verification before it informs a decision or leaves the organisation. The most important part is the prohibited data list — that is what keeps customer data out of third-party services with no lawful basis.
What's Inside
Standards & Regulations It Helps Satisfy
| Standard / Regulation | Clause / Article | What this document covers |
|---|---|---|
| ISO/IEC 27001:2022 | Control A.5.1 | Information security policy and its topic-specific subordinate policies. |
| ISO/IEC 27001:2022 | Control A.5.10 | Acceptable use of information and associated assets. |
| Law 27/2022 (PDP Law) | Lawful basis | Preventing third-party processing of personal data without a valid basis. |
This document helps satisfy the requirements above, but does not by itself make an organisation compliant. Compliance is judged on practice in operation, not on documents held.
Questions About This Document
Does this policy ban AI use?
No. The frame permits use under conditions: approved tools, restricted data, verified outputs. A blanket ban simply relocates usage somewhere invisible, which is the worse security outcome.
What about AI features inside software we already use?
That is the part most often missed. Automatic summarisation in a meeting or email tool can process data just as sensitive as a conversational assistant, yet never passes through an approval process because it is seen as part of an old tool. This policy covers it explicitly.
Is there a dedicated AI governance standard?
Yes: ISO/IEC 42001 covers artificial intelligence management systems. For most organisations starting out, a usage policy like this closes the largest risks; ISO 42001 becomes relevant when AI is a core part of the product or service you offer.
Need guidance, not just a template?
A template speeds up producing the document. What decides whether an audit passes is whether its contents genuinely reflect how your organisation works — and that is what we support.