Policies & Standards¶
The rules people have to follow. Frameworks say how you govern; policies say what is and is not allowed, and standards say how to meet them.
| Template | Status | Purpose |
|---|---|---|
| Data Governance Policy | Ready | The mandatory rules for handling data. Where the framework explains how governance works, this policy states what people must and must not do, in… |
| Data Quality Standard | Ready | Defines what "good enough" data means in measurable terms — the dimensions, how they are measured, the thresholds that apply, and who acts when a… |
| Data Classification & Handling Policy | Ready | Defines the sensitivity tiers your data falls into and the handling rules for each — including the rules that decide what may be pasted into an AI tool. |
| Acceptable AI Use Policy | Ready | The staff-facing rules for using AI at work: what is encouraged, what needs approval, and what is never allowed. This is the most-read document in the… |
| AI Development & Deployment Standard | Ready | The engineering-facing requirements for building, testing, deploying, and operating AI systems — the technical controls that make the framework's… |
| Third-Party AI Risk Policy | Ready | How you assess, contract for, and monitor AI you did not build — including AI features that appear inside software you already licence. For most… |
Not sure where you stand?
Take the role-based assessment — answer questions relevant to your role and get a report showing which of these templates close your biggest gaps. Everything stays in your browser.