Mist rising off still water at the edge of a dense treeline

Business practice

AI use policy.

Answer the question your insurer, your auditor, and your largest client are all starting to ask, in one document your team has actually signed.

The renewal form asks whether your firm has a written AI acceptable use policy. There is no box for "we are working on it."

The question arrived without warning and it is now on cyber renewals, professional liability applications, client security reviews, and the due diligence packet in any transaction. It is a yes or no field. Firms that answer no do not fail immediately, they simply move into a category with more questions, higher scrutiny, and occasionally a different premium.

Within a few weeks the answer is yes, and it holds up when someone reads past the first page. Tools are tiered, data classes are defined, every member of staff has acknowledged the document in writing, and you can hand the whole thing to an underwriter or a client without a covering explanation. The anxiety attached to that question is gone, permanently.

The approach

Tier, classify, sign.

Tier.

Tools land in one of three tiers: sanctioned, permitted with conditions, and prohibited. A policy that bans everything gets ignored within a month, and an ignored policy is worse than none because it proves the rule is optional.

Classify.

The real question is never which tool. It is which data. Client identifying information, financial records, health information, privileged material, and internal working documents each get an explicit rule, written in language a new hire understands on the first read.

Sign.

A policy nobody acknowledged is a draft. Every member of staff signs, the acknowledgements are filed, and the document enters onboarding so the next hire signs it in their first week without anyone remembering to ask.

Mist rising off still water at the edge of a dense treeline

Recognise this

The question is already in your inbox.

  • A renewal application or client questionnaire asked about AI use and you answered carefully.
  • You have a policy template saved somewhere that nobody has finished or circulated.
  • Your professional body has issued guidance and you have not mapped your firm against it.
  • Staff ask which tools are allowed and get a different answer depending on who they ask.
  • A client has started including AI terms in their engagement letters.

The work

Four parts, and none of them optional.

The written policy

Scope, definitions, permitted and prohibited uses, review obligations, and what happens when the rule is broken. Written for your firm and your obligations, not a template with a name swapped in. Short enough that people finish it.

Tool tiering

A named list of the tools your firm sanctions, the ones permitted under conditions, and the ones that are not to be used with client information. The list has an owner and a date, because a tiering that is never revisited becomes wrong within two quarters.

Acknowledgement and rollout

A signature page, a filing process, and a working session with the team so the document is understood rather than merely distributed. Adoption is the deliverable. A signed page from someone who did not read it protects nobody.

The review cadence

A named owner and a scheduled review, so the policy stays accurate as tools change. This is the part that turns a document into governance, and it is the part almost every firm leaves out.

Questions

Asked before, answered plainly.

Answer the question properly.

Book a first call