# AI governance starter pack

Operational guidance only. Adapt this pack to your business and obtain legal, privacy, security, or sector advice where needed.

## AI use register

| Field | Entry |
| --- | --- |
| Use case and purpose | |
| Operational owner | |
| Reviewer and approver | |
| Tool, model, and integrations | |
| Data used and prohibited data | |
| People affected and destination | |
| Risk tier and human decision | |
| Limitations and test evidence | |
| Fallback and incident contact | |
| Approval, last change, next review | |

## Acceptable-use policy starter

1. Use only approved AI tools and business accounts.
2. Keep personal, sensitive, confidential, client, credential, and privileged information out of AI tools unless the use is specifically approved with suitable controls.
3. A named person verifies material facts, sources, promises, and customer-facing outputs.
4. Public-facing AI is identified where required, with a route to a person.
5. Owners record approvals, material changes, tests, limitations, incidents, and reviews.
6. Stop and escalate unexpected disclosure, harmful output, significant inaccuracy, access failure, or out-of-scope use.
7. A material vendor, model, prompt, integration, data, audience, or purpose change triggers reassessment.
8. HR, credit, health, legal, safety, and rights-affecting decisions require specialist review.

## Approval record

- Purpose and success measure:
- Tool and account:
- Allowed and prohibited data:
- Risk tier and specialist input:
- Tests and known failures:
- Human decision and review coverage:
- Disclosure and fallback:
- Monitoring and incident route:
- Approver and date:
- Next review date:
