GASP AICF

Search controls and profiles

Search by control ID, name, domain or profile

AIG-001 AI Policy

Tier 1+AIProviderDeployerGPAI Model ProviderManaged Service Provider

Description

A documented AI policy states the organisation's principles, risk appetite and governance structure for developing and using AI systems. The risk appetite statement covers safety, fairness, privacy, reliability and regulatory compliance and expresses the level of AI risk the organisation accepts in measurable terms. The policy addresses prohibited uses, accountability and alignment with applicable law, is reviewed and approved at defined intervals and is communicated to all relevant personnel.

Rationale

Establishes the foundational direction and accountability structure for all AI activity in the organisation.

Applicability (9 profiles)

SaaS AI Providerstablerequiredcore
Enterprise AI Deployerstablerequiredcore
GPAI Model Providerstablerequiredcore
High-Risk Provider (EU)stablerequiredcore
Public Body Deployer (EU)stablerequiredcore
DORA ICT Provider (EU)stablerequiredcore
NIS2 Cloud Provider (EU)stablerequiredcore

Framework Mappings (15)

GRC-01Governance Program Policy and Procedurespartial
GRC-12Ethics Committeeinformative
EU-AI-Art.17.1Quality Management System — Establishment and Documentationinformative
A.2.2AI policyfull
A.2.3Alignment with other organizational policiespartial
A.2.4Review of the AI policyfull
A.9.3Objectives for responsible use of AI systeminformative
GV-1.1-001Legal and Regulatory AI Requirements | GV-1.1-001full
GV-1.3-006Risk Management Activity Level Determination | GV-1.3-006partial
GOVERN 1.1Legal and Regulatory AI Requirementsfull
GOVERN 1.2Trustworthy AI Characteristics Integrationfull
GOVERN 1.4Transparent Risk Management Policiesfull
GOVERN 4.1Safety-First Organisational Culturepartial
MAP 1.3Organisational Mission and AI Goalspartial
MAP 1.5Organisational Risk Tolerancefull

Evidence (3)

policydocumentmanual

AI governance policy or charter defining the organisation's principles, accountability structure, prohibited uses, and risk appetite for AI systems, reviewed and approved within the last 12 months.

Example: AI Governance Policy v2.1 (Confluence), approved by CTO on 2025-10-01, covering prohibited use cases, executive accountability matrix, and annual review obligation

Test: Request the AI governance policy. Verify: (1) a named executive is designated as sponsor, (2) prohibited AI use cases are enumerated, (3) accountability for AI risk decisions is assigned to specific roles, (4) a review cadence is stated, (5) the most recent approval date is within the last 12 months, (6) policy has been formally communicated to relevant personnel (distribution record or training completion report).

recorddocumentmanual

Annual AI policy review record demonstrating the policy was assessed against current AI activity, applicable law, and organisational changes, with sign-off by the accountable executive.

Example: AI Policy Annual Review Record 2025 (SharePoint), signed by CTO, confirming no material changes required with rationale documented

Test: Request the most recent AI policy review record. Verify: (1) review date is within the last 12 months, (2) the review considered changes to AI systems in production, (3) any required amendments were actioned, (4) sign-off by the named executive sponsor is present.

policydocumentmanual

AI risk tolerance statement or risk appetite declaration documenting the types and levels of AI risk the organisation is willing to accept, covering safety, fairness, privacy, reliability, and regulatory compliance dimensions.

Example: AI Risk Appetite Statement v1.0 (Confluence), approved by Risk Committee 2025-09-30, specifying quantified thresholds for acceptable error rates, bias metrics, and prohibited risk categories

Test: Request the AI risk tolerance or risk appetite document. Verify: (1) risk dimensions include at minimum safety, fairness, privacy, and regulatory compliance, (2) tolerance levels are expressed in measurable terms (not only qualitative), (3) approval by an appropriate governance body is evidenced, (4) review date is within the last 12 months, (5) a mechanism connecting tolerance statements to AI governance objectives is documented.

Questions (3)

boolean

Does your organisation have a documented AI governance policy or charter?

The policy should be formally approved by an executive sponsor, enumerate prohibited AI use cases, assign accountability for AI risk decisions, and specify a review cadence. Absence of a policy is a foundational gap that downstream controls cannot compensate for.

multi

Which of the following topics does your AI governance policy cover?

Prohibited or restricted AI use casesNamed executive sponsor or accountable ownerAccountability structure for AI risk decisionsAlignment with applicable laws and regulationsAnnual or more frequent review obligationCommunication requirements to relevant personnelNone of the above

A mature policy covers all six areas. Policies limited to high-level principles without accountability assignments or prohibited use lists provide weak governance foundations for enterprise buyers.

boolean

Has your organisation documented its AI risk tolerance, the types and levels of AI risk it is willing to accept?

Risk tolerance is the decision rule that determines when AI risks require treatment. Without it, risk management decisions are inconsistent and cannot be audited. Look for explicit statements covering safety, fairness, privacy, reliability, and regulatory compliance.