Here's a pattern that shows up in nearly every organization I've consulted for over the past two years: employees are already using ChatGPT, Copilot, or similar tools to draft emails, summarize documents, and write code — often without any policy in place, and often without IT's knowledge. The tools arrived faster than the governance did. If your organization doesn't have a generative AI policy yet, here's the checklist I use with clients to build one.

1. Classify What Data Can (and Can't) Go Into an AI Tool

This is the single highest-risk gap. Free-tier consumer AI tools may use submitted data for further model training unless the account is on an enterprise or opted-out plan. Your policy needs a clear, simple rule — not a legal essay — that staff can actually follow: what categories of data (customer PII, financial records, source code, legal contracts) are never to be pasted into a public AI tool.

2. Decide Which Tools Are Approved

"No generative AI" policies rarely survive contact with reality — staff use these tools anyway, just without visibility. A more realistic approach is to approve a defined set of enterprise-grade tools (with appropriate data protection terms) and explicitly prohibit consumer/free-tier equivalents for work use.

3. Require Human Review for Consequential Output

Anything AI-generated that becomes external-facing — client communications, contracts, financial analysis, code shipped to production — should require documented human review before use. This isn't just a quality control step; under ISO/IEC 42001 principles, it's the human-oversight control that regulators and auditors increasingly expect to see.

4. Address Intellectual Property and Attribution

Clarify ownership of AI-assisted work product, and set expectations around disclosing AI involvement where relevant — particularly in client-facing consulting, creative, or reporting work.

Practical Tip

Don't launch a generative AI policy without training to go with it. A policy document that sits unread in a shared drive changes nothing — a 60–90 minute workshop walking staff through real examples changes behavior.

5. Set an Incident Response Path

Define what happens if sensitive data is accidentally submitted to an AI tool, or if AI-generated content contains an error that reaches a client. Staff need to know who to notify and what the escalation path looks like — the same way they would for any other data incident.

6. Review and Update Regularly

Generative AI tooling changes quickly — new models, new enterprise features, new risks. A policy reviewed once and never revisited will be outdated within a year. Build a review cadence into the policy itself.

"Practical workshops on prompt engineering, Microsoft Copilot integration, and safe, productive Artificial Intelligence (AI) adoption for corporate teams."

Frequently Asked Questions

Should we just ban ChatGPT at work?

Blanket bans rarely work — staff tend to use these tools anyway through personal devices or accounts, just without any visibility or control. A better approach is approving enterprise-grade tools with proper data protections and clearly restricting what can and can't be shared with them.

Does this policy need to tie into ISO 42001 or ISO 27001?

Ideally, yes. A generative AI usage policy is one of the first concrete deliverables organizations produce when starting an ISO/IEC 42001 AI Management System, and it should align with your existing ISO 27001 data classification rules if you have them.

How often should the policy be reviewed?

At minimum annually, but given how quickly generative AI tooling evolves, a semi-annual review is a safer cadence for most organizations.

TA
Tillandran Achuthan ISO/IEC 27001 & 42001 Lead Auditor, ESG Lead Implementer, and HRDCorp-accredited Artificial Intelligence (AI) trainer based in Kuala Lumpur, Malaysia.

Need this implemented, not just explained?

Tillandran advises organizations across Malaysia on Artificial Intelligence (AI) governance, ISO 27001 & 42001 implementation, cybersecurity, and ESG reporting — book a consultation to discuss your specific situation.