What an auditor, or Sekit's evidence engine, asks for.
AI policy
The written, leadership-approved document that sets out how the company develops, buys and uses artificial intelligence: principles, acceptable and prohibited uses, who is accountable, and how it connects to the company's other policies.
From the Sekit evidence catalog
In practice
Writing the AI policy means naming, in one leadership-approved document, what the company allows: buying a vendor copilot for drafting emails, say, but not pasting client data into a public chatbot. An auditor asks to see the document itself, checks it has an owner and a review date, and confirms it names prohibited practices specific to how this company uses AI, not a template downloaded wholesale. The common failure is a policy that reads like generic AI ethics language, naming no real tool, no real prohibited use, and no accountable person, so it fails the moment someone asks who signed it and when.
Common gaps
The AI policy is copied from a template and never edited to name the company's actual tools, so it reads as generic and unenforceable.
Leadership approved the policy once but no owner or review date is recorded, leaving nobody accountable when a new AI tool shows up.
The policy states principles but lists no prohibited uses, so staff pasting client data into a public chatbot breaks no written rule.
Questions your auditor will ask
Does the company have an approved AI policy, and who signed it?
The AI policy document names its approver and date, kept alongside the company's other leadership-approved policies.
What does the policy specifically prohibit?
It lists specific prohibited uses, such as pasting client data into a public chatbot, not only general principles.
Who is accountable if the AI policy is not followed?
The policy names an accountable owner responsible for enforcement and for updating it as AI use changes.
Where regulation demands it
GDPR Article 24.2 expects data protection commitments to sit inside an organization's policies, and ENS org.1 (Política de seguridad) asks for that same approved security policy in writing.
Related controls
Via the shared Sekit CSF topic, not the framework's own index.