Controlled policy
AI governance policy template for SMEs
A useful AI policy describes how the organisation makes and maintains decisions. It should point people to operational records and owners rather than copying broad principles that cannot be evidenced.
Prepared by EU AI Fit editorial team · Published 24 August 2026 · Source review 31 August 2026
Purpose, scope and principles
Define which employees, contractors, systems and uses the policy covers; how it relates to privacy, security and procurement; and the principles used when evidence or authority is uncertain.
Roles and decision rights
Name the governing body, accountable system owner, technical owner, privacy and security contributors, procurement responsibilities and the people authorised to approve, pause or retire AI use.
Required operating processes
Set requirements for discovery, inventory, exposure screening, role and classification review, supplier assurance, evidence, human oversight, training, monitoring, incidents and material-change reassessment.
- No operational use without a named owner
- Escalation for prohibited or high-impact signals
- Evidence and approval retention
- Change notification by suppliers and system teams
- Periodic management review
Control the document
Assign an owner, approver, version, effective date, review date and change history. Mark organisation-specific gaps before approval and retain the evidence that the policy is communicated and operating.
Recommended next step
Draft the policy from current inventory and governance facts, resolve every marked gap and approve it as a controlled document—not a generic download.
Run the free exposure checkRelated practical guides
Put the guidance into practice