AI Governance Policy and Controls

Prepared for: Northbank Trust Company (illustrative) — an independently owned Trust Company, 32 staff, Jersey.
Prepared by: Change AI Consortium

This document is one of two linked deliverables. The named opportunities, priorities and 30-day plan sit in a companion document: read the sample AI Implementation Roadmap.

1. AI use policy

Northbank Trust Company — AI Use Policy (illustrative)

1. Purpose. This policy sets out how Northbank Trust Company uses AI tools, so that every member of staff knows what is allowed, what is not, and who to ask.

2. Scope. Covers any AI tool used in the course of work, whether provided by the firm or brought by an individual. Personal AI accounts may not be used for firm business.

3. What AI may be used for. Drafting support on internal, non-client-data material only: policy drafts, internal correspondence templates, report formatting. Every output is reviewed by a named person before it is used or sent.

4. What AI may not be used for. Any client data, any matter covered by legal professional privilege, or any regulated decision, until the board records a specific, minuted decision to open that use, with named controls in place.

5. Approved tools. Only tools on the approved list, held by the Head of Risk and Compliance, may be used. Requests to add a tool go through that role.

6. Ownership. The Head of Risk and Compliance owns this policy, reviews it quarterly, and reports on its use to the board monthly.

7. Breach. A breach of this policy is reported to the Head of Risk and Compliance the same day it is noticed. This is a learning process, not a disciplinary trap, for the first year of use.

2. Controls supporting delivery

Controls in place from day one