Establish and improve your governance policies.
Get a set of AI governance policies in place and keep them improving as the work and the rules evolve.
Why your policy stack needs attention
An audit committee chair asks to see the AI Acceptable Use Policy, the data governance policy and the incident response plan. A customer contract requires AI policies before signing. An ISO 42001 readiness review surfaces what is missing. A near-miss incident exposes that the policy that should have applied does not actually exist.
An information security policy from 2019 that mentions AI in passing is not an AI policy stack. This journey is about going from there to a documented set of AI governance policies, each approved by the right authorities, published and maintained over time as the underlying rules and your organisation's AI use both change.
Draft each policy from templates with your context
You open the Template Library and select the policy you need to draft first, often the AI Acceptable Use Policy. You provide context about your organisation, covering sector, size, current AI use and risk appetite. Aicura assembles a draft from curated content blocks shaped by your context. The draft is a starting point that already reflects your situation, rather than a generic boilerplate.
Walk through the wording in your context
The side-by-side verification walks you through each section of the draft, showing the standard wording, your context and the proposed text together. You approve, edit or refine block by block. By the time you finish, the policy reflects your organisation rather than the template it started from.
Cycle through counsel review
Your General Counsel reviews the draft. Legal feedback comes back, you make the changes, and the policy gets signed off. Aicura keeps the version under control, so the trail of what was approved and by whom stays intact.
Publish across the organisation
The approved policy is published internally. Staff are notified through your existing communications channels. The policy is now in force. You then repeat the workflow for each of the six standard policy types Aicura covers, building out the stack over time.
Improve based on scanner guidance
Once a policy is published you upload the approved version back into Aicura. The scanner reviews the document and returns guidance on where it could be sharper or more specific to your AI use. You decide which suggestions to fold into the next version, draft the improvement, and run the same review cycle. Versions are kept, so the trail of what was in force when stays intact.
After the first set of policies is in place, the work shifts to maintenance. As the rules and your AI use change, Aicura surfaces notifications suggesting policies you may want to re-scan. You decide what to run. News and regulatory developments can trigger amendments. Versions are kept indefinitely, so the trail of what was in force when stays intact. The policy stack becomes a documented, signed, current set that your team can point to with confidence rather than a folder of files from various points in time.
Frequently asked questions
Do we need AI policies if we already have an information security policy?
In most cases, yes. An information security policy from 2019 that mentions AI in passing is not an AI policy stack, and the requests now arriving ask for more, whether that is an audit committee chair wanting the AI Acceptable Use Policy, a customer contract requiring AI policies before signing or an ISO 42001 readiness review surfacing what is missing. A near-miss incident is often what exposes that the policy that should have applied does not exist.
Does Aicura write our AI policies for us?
Aicura drafts each policy from curated content blocks shaped by context you provide about your sector, size, current AI use and risk appetite, so the starting point already reflects your situation rather than generic boilerplate. Review and sign-off stay with your organisation and its counsel. Aicura does not certify the result and does not give legal advice.
What happens to the policies after they are approved?
The work shifts to maintenance. As the rules and your AI use change, Aicura surfaces notifications suggesting policies you may want to re-scan, and you decide what to run. Versions are kept indefinitely, so the trail of what was in force when stays intact.
Start the work in Aicura
Aicura supports this work from the register that anchors it through to the documents and records it produces, with your people reviewing and approving everything along the way. It is guidance, not certification, audit or legal advice.