Controlled policy

AI governance policy template for SMEs

A useful AI policy describes how the organisation makes and maintains decisions. It should point people to operational records and owners rather than copying broad principles that cannot be evidenced.

Prepared by EU AI Fit editorial team · Published 24 August 2026 · Source review 31 August 2026

Purpose, scope and principles

Define which employees, contractors, systems and uses the policy covers; how it relates to privacy, security and procurement; and the principles used when evidence or authority is uncertain.

Roles and decision rights

Name the governing body, accountable system owner, technical owner, privacy and security contributors, procurement responsibilities and the people authorised to approve, pause or retire AI use.

Required operating processes

Set requirements for discovery, inventory, exposure screening, role and classification review, supplier assurance, evidence, human oversight, training, monitoring, incidents and material-change reassessment.

  • No operational use without a named owner
  • Escalation for prohibited or high-impact signals
  • Evidence and approval retention
  • Change notification by suppliers and system teams
  • Periodic management review

Control the document

Assign an owner, approver, version, effective date, review date and change history. Mark organisation-specific gaps before approval and retain the evidence that the policy is communicated and operating.

Recommended next step

Draft the policy from current inventory and governance facts, resolve every marked gap and approve it as a controlled document—not a generic download.

Run the free exposure check

Related practical guides

Put the guidance into practice

Continue your EU AI Act review