Free business checklist

A simple AI policy for your business.

Set clear rules for the tools your team uses, the information they share, and the work a person must review.

Three questions a business should answer before staff use AI

Decide seven things first.

A short written policy gives staff a safe starting point and someone to ask when a new situation comes up.

Tools and information

Choose what is allowed.

Approved tools. List the AI services and company accounts staff may use.

Private information. Name what staff must never paste into an outside AI service.

Company computers. Identify work that must stay on equipment your business controls.

People and review

Keep a person responsible.

Human review. Require a person to check customer-facing, financial, legal, hiring, or safety-related work.

Ownership. Name who approves new tools and answers staff questions.

Records and changes

Learn from real use.

Important records. Note which tool helped with work that affects customers or business decisions.

Problems and review date. Explain how staff report mistakes or accidental sharing, then review the policy on a regular date.

Copy this starting policy.

Replace the bracketed text, share the result with your team, and review it when your tools or work change.

[Business name]

AI use policy

Purpose
We use AI to assist our team. A person remains responsible for the work and the final decision.

Approved tools
Staff may use: [list approved services and company accounts]. Ask [policy owner] before using another AI tool for company work.

Information we do not share
Do not enter [customer records, passwords, payment details, confidential contracts, private employee information, or other restricted information] into an outside AI service.

Work that stays on company computers
Use our approved company computer or private service for: [list sensitive work].

Human review
A person must check AI-assisted work before it affects a customer, payment, contract, job applicant, employee, health, safety, or other important decision.

Records
For important work, note the AI tool used, the date, and the person who reviewed the result.

Problems
Report wrong, harmful, or accidentally shared information to [name or contact] as soon as possible. Do not hide the mistake.

Owner and review date
[Name or role] owns this policy. We will review it on [date] and whenever our tools or work change.

Practical starting point. Adapt this checklist to your business and local requirements. It is not legal advice or a claim of compliance.

A business owner reviewing how company AI work is handled

Start with one familiar job.

Choose a contained task, such as an internal summary or first draft. Name the owner, approved tool, review step, and information that stays private.

Further reading.

This practical checklist is informed by the voluntary NIST AI Risk Management Framework and NIST AI RMF Playbook. Those resources can be adapted to organizations of different sizes and needs.