⚡ Quick Summary
Published by the Responsible AI Institute (RAI Institute), this June 2024 template supplies a fill-in-the-blank organizational AI Policy that organizations adapt to their own context; the document describes itself as the Institute's first draft version. It states its purpose as showing one interpretation of how global and regional guidance — explicitly the NIST AI Risk Management Framework (RMF) and ISO/IEC 42001 — can be operationalized through corporate policy, noting that an AI policy is a requirement of an AI management system under ISO/IEC 42001.
The template runs through fourteen sections containing bracketed placeholders: purpose and scope with example definitions of AI, AI model and AI system; AI principles built on seven trustworthiness characteristics; objectives and strategy; governance through a Steering Committee and an Operational Committee plus governance gates; data, risk, project, stakeholder, workforce and documentation management; regulatory compliance; and AI procurement. Its central mechanisms include the AI Impact Assessment in low-, medium- and high-touch versions, an AI Incident, Impact, and Risk (IIR) database, risk levels from minimal (1) to very high (4), and a Responsible Supplier Assessment. Appendix A lists policy documents and artifacts to link to the policy.
🧩 What’s Covered
The parts follow the document's own order.
- Introduction and disclaimer: explains why a standalone AI policy can centralize responsible AI strategy, advises customization and annual review, and states that the template "does not purport to, satisfy particular legal requirements in every jurisdiction."
- Purpose and Scope: placeholders for the policy's scope and audience, with example definitions of AI, AI model and AI system drawn from the NIST AI RMF and United States Executive Order No. 14110.
- AI Principles: seven trustworthiness characteristics — validity and reliability, safety, security and resiliency, accountability and transparency, explainability and interpretability, privacy-enhanced, and fairness with harmful bias managed — plus human oversight, beneficence, equity and ethics, and continual learning.
- AI Objectives and Strategy: a documented long-term AI strategy with key objectives and measures, and priority capabilities for bought, built and sold systems.
- Governance: executive owners or sponsors, a high-level Steering Committee and an Operational Committee with convening cadences and listed responsibilities, internal and external AI actor roles, communication and feedback channels, and governance gates that approve, pause or terminate life cycle progression.
- Data, Risk, Project, Stakeholder, Workforce and Documentation Management: twelve documented data items per data set; definitions of AI impact, incident and risk with risk tolerance thresholds; eight risk management components including three AI Impact Assessment levels; AI system life cycle stages; consultation, notification and reporting duties; DEI and training provisions; and documentation control.
- Regulatory Compliance and AI Procurement: compliance duties to monitor, map and be accountable for requirements, and procurement steps including the Responsible Supplier Assessment, absolute thresholds and terms of use.
- Appendix A: lists enterprise-level policy documents, enterprise artifacts such as the risk taxonomy, AI system inventory and IIR database, and system-level artifacts per AI system.
💡 Why it matters?
Organizations that need a documented AI policy — for instance to meet the AI management system requirement the template attributes to ISO/IEC 42001 — can start from drafted clauses instead of a blank page. Each provision is annotated with the ISO/IEC 42001 clause or NIST AI RMF statement it aligns with, which helps compliance and risk teams trace internal policy back to recognized expectations. The AI Impact Assessment, risk tolerance thresholds, governance gates and Responsible Supplier Assessment give concrete mechanisms for approving, monitoring and procuring AI systems. Legal sufficiency is left to the adopting organization.
❓ What’s Missing
The document is a template, so most substantive values remain bracketed placeholders: definitions, risk tolerances, prohibited use cases, objectives and metrics must all be supplied by the adopting organization. It states that it does not satisfy particular legal requirements in every jurisdiction and recommends independent legal advice. No completed example, worked case or cost estimate is provided, and the IIR database, risk taxonomy and inventories are referenced as artifacts to build rather than described in operational detail. Because this is a first draft version with feedback accepted only into July 2024, provisions may change.
👥 Best For
Policy owners and AI governance leads in organizations that need a starting draft mapped to ISO/IEC 42001 and the NIST AI RMF; compliance and legal teams reviewing AI policy clauses; risk, data and procurement functions introducing impact assessments, risk tolerances and supplier assessments; and advisers building client AI policies.
📄 Source Details
AI Policy Template, published by the Responsible AI Institute, June 2024, described in the document as the Institute's first draft version. 46 pages, English. No individual authors, ISBN, series or reference number are printed, and no URL appears in the extracted text; the closing "About Responsible AI Institute" page ends at "Where to connect with us:" with no address shown. The full text of all 46 pages was available, including cover, table of contents, the fourteen sections and Appendix A.