The AI Action Plan's shift toward self-regulation creates an immediate gap: your organization needs a governance policy that addresses AI risk without waiting for federal rules. This template provides a working AI governance policy you can adapt to your risk profile, industry context, and existing GRC framework.
Purpose of the Template
This policy sets baseline governance for AI systems in your organization. It's designed for the current regulatory environment, where the AI Action Plan advocates for minimal federal interference with state-level AI laws unless they're "unduly restrictive to innovation." You're responsible for defining acceptable use, risk thresholds, and oversight mechanisms before a regulator does it for you.
The template addresses three core requirements:
- Risk classification, categorize AI systems by potential impact.
- Deployment controls, define approval gates and testing requirements.
- Monitoring obligations, specify ongoing oversight and incident response.
Customize this policy based on your industry's regulatory obligations, your organization's risk appetite, and the AI use cases you're enabling or restricting.
Prerequisites
Before implementing this policy, ensure you have:
- Executive sponsorship, AI governance requires cross-functional authority. Your Chief Risk Officer or Chief Information Officer should own this policy.
- Inventory capability, you need a method to identify and track AI systems in use across the organization, including shadow AI deployments.
- Existing policy framework, this AI policy should reference your data privacy, information security, and vendor management policies. If those don't exist, build them first.
- Legal review capacity, state-level AI laws vary significantly. Your legal team must validate that this policy doesn't conflict with jurisdiction-specific requirements in states where you operate.
The Template
POLICY TITLE: Artificial Intelligence Governance and Risk Management
POLICY OWNER: [Chief Risk Officer / Chief Information Officer]
EFFECTIVE DATE: [Date]
REVIEW CYCLE: Quarterly
1. PURPOSE AND SCOPE
This policy establishes governance requirements for artificial intelligence systems developed, procured, or deployed by [Organization Name]. It applies to all business units, technology teams, and third-party vendors processing data on behalf of the organization.
For purposes of this policy, an AI system is defined as any technology that uses machine learning, natural language processing, computer vision, or algorithmic decision-making to analyze data, generate predictions, or automate decisions.
2. RISK CLASSIFICATION
All AI systems must be classified into one of three risk tiers within 10 business days of identification:
HIGH RISK, AI systems that:
- Make or materially influence decisions affecting employment, credit, insurance, or legal rights
- Process [Sensitive Personal Data](/glossary/sensitive-personal-data) as defined in [Reference: Data Privacy Policy]
- Operate in regulated industries subject to model risk management requirements (financial services, healthcare)
- Automate decisions previously requiring human judgment in high-stakes contexts
MODERATE RISK, AI systems that:
- Support internal business processes without direct customer impact
- Analyze data to generate recommendations reviewed by humans before action
- Operate in customer-facing contexts with human override capability
LOW RISK, AI systems that:
- Perform narrow technical functions (spam filtering, search ranking, content recommendations)
- Operate in controlled environments with limited data access
- Generate outputs used solely for research or internal analysis
3. DEPLOYMENT CONTROLS
HIGH RISK systems require:
- Written risk assessment documenting model design, training data sources, bias testing results, and failure modes
- Approval from [Governance Committee / Chief Risk Officer] before production deployment
- Third-party validation of model performance and fairness metrics (if processing decisions affecting individuals)
- Documentation of human oversight mechanisms and override procedures
MODERATE RISK systems require:
- Self-assessment using the AI Risk Assessment Template [Appendix A]
- Department head approval
- Testing protocol demonstrating output accuracy and data handling compliance
LOW RISK systems require:
- Registration in the AI System Inventory
- Confirmation of data handling compliance with existing Information [Security Policy](/glossary/security-policy)
4. VENDOR AI SYSTEMS
Any third-party software, platform, or service that incorporates AI functionality must be evaluated under this policy before contract execution.
Procurement teams must:
- Identify AI capabilities in vendor solutions during the RFP process
- Classify vendor AI systems using the risk tier framework in Section 2
- Require vendors to provide model documentation, training data descriptions, and bias testing results for HIGH RISK systems
- Include contractual rights to audit AI system performance and request model changes
5. ONGOING MONITORING
System owners must:
- Conduct quarterly reviews of HIGH RISK system performance, documenting output accuracy, bias metrics, and incidents
- Report material changes to model design, training data, or deployment context to [Policy Owner] within 5 business days
- Maintain logs of AI-generated decisions sufficient to support regulatory inquiries or litigation holds
6. INCIDENT RESPONSE
An AI incident is defined as:
- Systematic bias producing discriminatory outcomes
- Material inaccuracy in model outputs causing business or customer harm
- Unauthorized access to model training data or intellectual property
- Regulatory inquiry or enforcement action related to AI system operation
AI incidents must be reported to [[Information Security Incident](/glossary/information-security-incident) Response team] within 24 hours of identification. The [Incident Response Structure](/glossary/incident-response-structure) defined in [Reference: Incident Response Policy] applies to AI incidents.
7. TRAINING AND AWARENESS
Employees developing, deploying, or managing AI systems must complete AI Ethics and Risk training within 30 days of policy effective date and annually thereafter.
8. POLICY EXCEPTIONS
Requests for Approved Exceptions to this policy must be submitted to [Policy Owner] in writing, documenting business justification and compensating controls. Exceptions require written approval and are valid for a maximum of 12 months.
9. ENFORCEMENT
Violations of this policy may result in disciplinary action up to and including termination. Material violations must be reported to the [Audit Committee / Board Risk Committee] within 10 business days.
How to Customize It
Section 2 (Risk Classification): Adjust the risk tier definitions based on your industry. If you're in financial services, reference model risk management requirements from SR 11-7. If you're in healthcare, align HIGH RISK criteria with HIPAA's definition of treatment decisions.
Section 3 (Deployment Controls): The "third-party validation" requirement for HIGH RISK systems is intentionally strict. If your organization lacks budget for external model audits, replace this with internal peer review by a team that didn't develop the model. Document the reviewer's qualifications.
Section 4 (Vendor AI Systems): If your procurement team doesn't have AI expertise, add a requirement to consult with [IT Risk / Data Science team] during vendor evaluation. Consider adding vendor attestations about data center locations and supply chain transparency.
Section 6 (Incident Response): Define severity levels that map to your existing Information Security Incident severity framework. A Severity Level 1 AI incident (systematic bias affecting protected classes) should trigger the same executive notification as a data breach.
Training requirement: If annual training isn't realistic, make it event-driven: required before an employee can deploy a HIGH RISK system or before procurement can execute a contract with embedded AI.
Validation Steps
After customizing the template, validate it through these steps:
Legal review, confirm the policy doesn't conflict with state AI laws in jurisdictions where you operate. The AI Action Plan advocates for minimal federal interference unless state laws are "unduly restrictive to innovation," but that doesn't prevent states from enforcing existing laws.
Control mapping, document how this policy maps to your Compliance Program. If you're subject to GDPR, map Section 3's risk assessment requirement to Article 35 (Data Protection Impact Assessment). If you're in financial services, map Section 5's monitoring requirements to your existing model validation controls.
Inventory pilot, before rolling out the policy, run a pilot inventory exercise with one business unit. Identify 10-15 AI systems and classify them using Section 2's framework. If more than 80% land in a single risk tier, your tier definitions are too broad.
Incident scenario test, walk through a hypothetical AI incident with your Information Security team. Confirm the reporting timeline in Section 6 integrates with your existing incident response workflow. If your current process can't accommodate AI-specific incidents, update the Incident Response Structure before finalizing this policy.
Quarterly review checkpoint, schedule the first policy review 90 days after effective date. The AI Action Plan's focus on "opening the sandboxes" for rapid deployment means you'll need to adjust governance controls as use cases evolve faster than traditional technology.
This policy won't prevent every AI risk, but it establishes the governance baseline you need while federal rules remain undefined. Treat it as a living document and update it quarterly as your AI portfolio matures.





