ISO 42001 GOVERNANCE

Acceptable use policy for AI

Part of: Annex A.2: Policies Related to AI

Description

Policy defining permitted and prohibited uses of AI systems, including boundaries for autonomous decision-making and human involvement.

Implementation Guidance

Permitted and Prohibited Uses

Define explicit categories: approved use cases (content drafting, code assistance, data analysis), restricted use cases requiring approval (customer-facing decisions, HR screening), and prohibited uses (social scoring, unauthorized surveillance, weapons targeting).

Decision Boundaries

Specify thresholds for autonomous vs. human-assisted AI decisions based on impact level. High-impact decisions (credit, employment, healthcare) require human-in-the-loop. Document escalation paths when AI outputs fall outside acceptable confidence ranges.

Employee Guidance

Provide practical examples for each user role: what engineers can use AI for, what analysts should avoid, how managers should review AI-assisted recommendations. Include data handling rules for AI tool inputs.

Evidence Requirements

  • Acceptable use policy with use case classifications
  • Decision boundary matrix (autonomous vs. human-in-the-loop)
  • Employee acknowledgment records
  • Use case approval requests and decisions