Governance starter

An AI acceptable-use policy your people can follow.

A useful policy says which tool, which account, which data, which workflow, and which reviewer. It also gives staff a fast path to propose something new.

Published by PrivateStride · Last updated August 11, 2026

Before drafting

Write the operating decisions first.

A policy cannot repair an unknown data flow or an unusable approved tool.

Start with the AI inventory, information classes, intended workflows, system diagrams, vendor review, risk assessment, and professional-review requirements. Involve the firm’s Qualified Individual, legal and privacy advisers, IT provider, engagement leaders, records owner, and people responsible for training.

Keep the employee-facing policy short. Put changing details such as approved product names, settings, owners, and workflows in a controlled AI register that can be updated without rewriting the entire policy.

Start by mapping likely shadow AI use

Policy structure

Eight sections that answer the daily questions.

The sample language is intentionally general. Replace it with decisions your authorized reviewers have approved.

Policy section

1. Purpose and scope

State why the policy exists, who it covers, and which AI systems count. Include stand-alone chatbots, meeting tools, browser extensions, embedded software features, APIs, models running locally, and AI used by contractors when they handle firm work.

Starter language: This policy governs the use of AI systems for firm business by personnel and contractors. AI may support work only when the service, account, data, and workflow are approved under this policy.

Policy section

2. Approved systems

Maintain a controlled list with the exact product, account or workspace, permitted data classes, approved workflows, owner, settings, and approval date. A familiar vendor name is not enough.

Starter language: Users may use only the systems and account types listed in the firm’s AI register. Personal accounts and unlisted AI features may not be used for firm work.

Policy section

3. Data rules

Translate the firm’s information classification into simple AI instructions. State what may enter each approved environment and what always requires specific review.

Starter language: Client, taxpayer, employee, credential, and other restricted information may enter an AI system only when the written register expressly permits that data class and workflow.

Policy section

4. Human responsibility

Make clear that AI output is a draft. Assign review for facts, calculations, sources, tax positions, confidential information, bias, tone, and records treatment before reliance or delivery.

Starter language: The responsible professional must verify AI-assisted work to the same standard as other work. AI does not approve a conclusion, sign a deliverable, or replace professional judgment.

Policy section

5. Prohibited uses

Name uses the firm will not allow, such as entering restricted data into an unapproved system, exposing credentials, hiding AI use from a required reviewer, auto-sending unreviewed output, or delegating a decision that must remain with a professional.

Starter language: Users may not bypass access controls, connect an unapproved plug-in, disable required logging, or represent unverified AI output as established fact.

Policy section

6. Records and reporting

Explain which prompts, inputs, outputs, approvals, corrections, and incidents become firm records. Give staff a nonpunitive path to report a mistake or unapproved use quickly.

Starter language: Report accidental disclosure, suspicious output, unexpected system behavior, or unapproved use immediately through the firm’s security process. Prompt reporting supports containment and review.

Policy section

7. New uses and exceptions

Provide a short intake form and name the decision owner. Require the purpose, data, service, flow, professional reviewer, expected value, and proposed test. Time-box exceptions and document conditions.

Starter language: A new AI use requires approval before production data is used. Material changes to the provider, model, integration, purpose, or data path trigger review again.

Policy section

8. Training and enforcement

Train with real firm scenarios and verify understanding. Apply existing employment and professional policies consistently. Review the AI policy on a defined schedule and after significant changes or incidents.

Starter language: Users receive role-based instruction before access and periodic refreshers. The firm reviews this policy and AI register at least annually and when material changes occur.

AI register

Keep the changing facts next to the policy.

One row per approved workflow gives users, administrators, reviewers, and auditors a common record.

Register fieldWhat to recordWhy it matters
Service and accountExact product, edition, workspace, owner, and administratorsPrevents a brand-level approval from spreading to other products
Workflow and purposeTask, engagement context, users, input, output, and intended useGives reviewers the facts behind the approval
Permitted dataAllowed classes, explicit exclusions, masking, and test-data rulesLets staff decide before they upload
ControlsAccess, MFA, retention, logging, training, review, and records handlingConnects the policy to the deployed system
ApprovalBusiness, legal, privacy, security, tax, and records decisions as applicableShows who accepted which conditions and limitations
LifecycleApproval date, review date, changes, incidents, suspension, and exitKeeps a once-correct decision from silently going stale

Launch checklist

Train on choices people will face this week.

Use examples from tax, audit, advisory, administration, and client service. Include a safe response when a user is uncertain: stop, preserve the information, and ask the named owner before proceeding.

See how PrivateStride builds adoption habits
  1. Approve the system inventory and AI register.
  2. Reconcile the policy with the WISP and records rules.
  3. Verify access, logging, retention, and support paths.
  4. Train each role using realistic, approved examples.
  5. Test the new-use request and incident-reporting paths.
  6. Measure questions, exceptions, corrections, and adoption.
  7. Review after significant changes and on schedule.
Review the technical controls behind the policy

Supporting frameworks

Use the policy as one layer of the program.

Governance, data mapping, risk assessment, technical controls, testing, incident response, and leadership reporting need to agree with the written rule.

Primary sources: NIST’s voluntary AI Risk Management Framework and Generative AI Profile offer governance and risk-management considerations. The FTC’s Safeguards Rule guide describes information-security program elements for covered financial institutions. The IRS maintains the Section 7216 Information Center. See our claims methodology for how we separate measured observations from projections.

Keep reading

Turn the policy into a working system.

These guides cover the decisions that sit next to this one.

ChatGPT and client data

Define the product, data, purpose, and review behind each policy decision.

Read the guide

Safeguards Rule and AI

Connect the AI register to the written security program.

Read the guide

IRC Section 7216 and AI

Bring tax return information questions into workflow approval.

Read the guide

Capacity & AI risk assessment

Map the risk before you choose the tool.

In 30 minutes, we identify your highest-value workflows, likely shadow-AI exposure, and the controls a private AI program would need. The findings are yours to keep.

Book your audit 30 min · No preparation · Confidential