A complete, editable policy written for firms that use AI: CPA and accounting firms, law firms, insurance agencies, RIAs, healthcare practices and consultancies. Copy it, replace the bracketed fields, delete what does not apply, and have leadership sign it. It is the first control every regulator, carrier and client questionnaire asks about, and a gating control in the AboveBoard Standard.
A policy is only as good as the three decisions behind it. Make them first; the template fills in around them.
Everything in brackets is yours to replace. Clauses marked "optional" can be deleted. This template is provided for information; have counsel review the final version for your jurisdiction and industry.
Version [1.0] · Approved by [Managing Partner / Board / Executive Committee] on [date] · Owner: [Name, Title] · Next review: [date]
This policy sets out how [Firm Name] ("the Firm") and its people may use artificial intelligence tools, including generative AI, in the Firm's work. Its purpose is to let the Firm benefit from AI while protecting client confidentiality, the accuracy of our work, our professional and legal obligations, and the trust of our clients, regulators and insurers.
This policy applies to all partners, owners, employees, temporary staff, interns and contractors of the Firm ("Personnel"), on any device and any account, whenever they perform work for the Firm or handle Firm or client information. It covers AI features embedded in software the Firm already uses (for example, document, email, meeting, research, practice-management and [industry-specific system] tools) as well as standalone AI applications.
Personnel may use only Approved AI tools for Firm work. The Approved AI Tools Register (Schedule A) lists each tool, the account type, the permitted uses, the data classifications permitted, the owner and the date the vendor's terms were last reviewed. A tool is added only after the AI Owner has confirmed, in writing, that the vendor's terms prohibit training on the Firm's inputs, state retention and deletion periods, identify sub-processors, and provide confidentiality and security commitments appropriate to the data involved [and, for healthcare, that a business associate agreement is in place]. Personal, free or consumer accounts may not be used for Firm work. Requests for new tools go to the AI Owner using the [request form / email address].
Personnel must not:
Information is classified as follows for AI purposes: Public (may be used in any Approved AI tool); Internal (may be used in Approved AI tools on Firm accounts); Confidential and client information (may be used only in Approved AI tools expressly approved for that classification in Schedule A, and only as necessary for the engagement); Restricted ([Social Security numbers, tax return information, protected health information, account numbers, privileged material, material non-public information]: may not be entered into any AI tool unless Schedule A expressly permits it for that tool). Where a client's engagement terms, a privacy notice or applicable law require notice or consent before AI processing, the engagement leader obtains it before use and records it in the matter file. Prompts, outputs and AI-generated drafts are subject to the Firm's retention schedule; Personnel must not disable retention controls the Firm has configured.
A qualified person, named in the record, reviews and takes responsibility for all AI-assisted work product before it is delivered to a client, filed with a court or regulator, published, or placed in a permanent file. Review includes verifying every factual statement, citation, calculation and quotation against original sources; checking for confidentiality breaches, bias and completeness; and confirming the output reflects the Firm's professional judgment. [For legal work: no citation is filed unverified. For accounting work: AI output is not audit evidence and is not relied upon as such. For clinical work: an AI-drafted note is not part of the record until a clinician has reviewed and signed it.] The AI Owner or delegate samples AI-assisted work product at least [quarterly], records results, and tracks corrective actions. AI-assisted work product is identified as such in the Firm's [document management / matter / engagement] system.
The Firm discloses its use of AI to clients through [engagement letters / terms of business / statements of work] and a published AI statement, and honors client instructions that restrict AI use, which the engagement leader records in the matter file. Personnel disclose AI use to courts, regulators and professional bodies where their rules require it; the AI Owner maintains the list of such requirements. Where the Firm uses AI to communicate with clients or patients directly, or to record or transcribe conversations, the notice required by law and by this policy is given [and, where required, consent obtained] before use. Only [designated persons] may make statements about the Firm's AI capabilities in marketing, proposals, RFP responses or to the media, and every such statement is reviewed for accuracy and substantiation before publication.
Personnel report any actual or suspected AI incident immediately to [the AI Owner / the incident email / the hotline], without fear of retaliation for good-faith reports. The Firm's incident response plan applies, including its AI section, which covers containment, assessment, notification of affected clients and any regulator or insurer where required, correction of the record, and documentation. The AI Owner maintains a log of AI incidents and near-misses and reports it to [the partners / the board] at least quarterly.
All Personnel complete AI awareness training within [30 days] of joining and at least annually thereafter. Personnel who review AI-assisted work product complete reviewer training. [Partners / board members] complete AI governance training annually. All Personnel sign the acknowledgment in Schedule B on joining, on each material revision of this policy, and at least annually. Training completion and acknowledgments are recorded by [HR / the AI Owner].
The Firm may monitor use of Firm systems and accounts, including AI tools, to the extent permitted by law, and may use technical controls to restrict unapproved tools. The AI Owner reviews the Approved AI Tools Register and vendor terms at least [twice a year] and monitors vendors for changes in terms, models, security notices and outages. Changes to prompts, templates and automated workflows that affect client work are approved, tested and logged.
Breaches of this policy are handled under the Firm's disciplinary procedures and may result in withdrawal of AI tool access, disciplinary action up to and including termination, and, for contractors, termination of engagement. Personnel who report their own good-faith mistakes promptly will have that fact taken into account.
The AI Owner reviews this policy at least annually and whenever a new tool, law, professional guidance, client requirement or incident warrants it, and maintains a version history recording each change, its date and its approver. [The partners / the board] approve each revision.
Tool · Vendor · Account type (enterprise / business) · Permitted uses · Permitted data classifications · Owner · Terms reviewed on · Training-on-data prohibited (Y/N) · Retention period · BAA or DPA on file (Y/N) · Notes.
See below.
I confirm that I have received and read the [Firm Name] Artificial Intelligence Acceptable Use Policy, version [1.0], dated [date], and that I have completed the AI training required for my role.
I understand that: I may use only Approved AI tools, on Firm-managed accounts, for Firm work; I may not enter Restricted information into any AI tool, or client or confidential information into any tool not approved for it; I am responsible for verifying any AI-assisted work product I deliver, file or place in a record; I must give any notice or obtain any consent the policy requires before using AI to record, transcribe or communicate with clients or patients; I must report AI incidents immediately; and breaches may result in loss of access and disciplinary action.
I agree to comply with the policy and with any revisions communicated to me.
Name: ____________________ Role: ____________________ Signature: ____________________ Date: ____________
Adopted, approved with a date and acknowledged by staff, this policy takes you to level 3 on G1 (written AI policy) and, with the records, on W3 (staff acknowledgment). Sections 7, 8 and 9 create the written requirements that D1 (data classification), O1 (human review before client-facing output) and T1 (engagement terms address AI) are scored on; sections 4, 5, 10 and 9 support G2 (named owner), D2 (approved tools), O3 (AI in the incident plan) and T6 (staff communications guidance). Two of those, G1 and O1, are gating controls: no firm is listed in the registry at any level with a zero on them.
A policy proves that rules exist. Evidence proves they operate. The reviewer will ask for the approval date, the acknowledgment records, Schedule A with the vendor-terms review dates, a sample review sign-off and the training completion report. The 40-point checklist lists the evidence for every control; the Standard shows all four levels.
Start from what is actually in use: inventory the tools, decide which are approved, and write the one rule about client data that matters most. Then fill in a template that covers purpose, scope, definitions, roles, approved and prohibited uses, data rules, human review, disclosure, incidents, training, monitoring, enforcement and review cadence. Have leadership approve it with a date, collect signed acknowledgments, and put a review date in the calendar. A first version takes an afternoon.
Purpose and scope; definitions; who is accountable; the approved-tool list and how tools get added; prohibited uses; what client, personal and confidential data may and may not be entered; the human-review requirement before AI output reaches a client, court, regulator or file; disclosure to clients and others; how to report an AI incident; training and acknowledgment requirements; monitoring; consequences of breach; and how often the policy is reviewed.
Yes. The template on this page is a complete AI acceptable-use policy written for professional-services firms, with an acknowledgment form and notes for customizing it by industry. Copy it, replace the bracketed fields, and delete what does not apply.
Because staff are already using generative AI and will not tell you unless you ask: 57% of employees say they hide their AI use from their employer, and 66% rely on AI output without checking it (KPMG / Univ. of Melbourne, Apr 2025). A written policy is also the first thing every regulator, insurer and client questionnaire asks for, and it is a gating control in the AboveBoard Standard: no firm is listed at any level without one.
Adopted, approved and acknowledged, it satisfies G1 (written AI policy) and W3 (staff acknowledgment), and it establishes the written requirements behind D1 (data classification), O1 (human review before client-facing output) and T1 (engagement terms address AI). It also supports G2, D2, O3 and T6. The policy alone does not prove those controls operate; the evidence does.