What an auditor, or Sekit's evidence engine, asks for.
AI policy
The written, leadership-approved document that sets out how the company develops, buys and uses artificial intelligence: principles, acceptable and prohibited uses, who is accountable, and how it connects to the company's other policies.
From the Sekit evidence catalog
In practice
Reviewing the AI policy on schedule means more than a calendar reminder: when the company adopts a new AI vendor, changes how it uses customer data, or a relevant law takes effect, the policy gets reopened and reissued, not left stale for a year. An auditor checks the review log for dates, triggers and what changed in the document text, then asks how staff learned about the update. The common gap is a policy carrying a review date field that nobody has touched since it was first approved, even after the company added two new AI tools in the meantime.
Common gaps
The policy carries a review date field but the document text has not changed since it was first approved a year ago.
A new AI vendor was adopted and no one reopened the AI policy to check whether it still covers the new use.
Staff were never told the AI policy changed, so the update exists on paper but nobody works to the new version.
Questions your auditor will ask
How often is the AI policy reviewed?
On a defined schedule stated in the policy itself, and also whenever the company adopts a new AI tool or a relevant law changes.
How do staff learn the AI policy has changed?
The routine that communicates security policy updates company-wide also covers AI policy changes, with a record of who acknowledged it.
What triggers an out-of-cycle review?
A new AI vendor, a material change in AI use, or a legal change each trigger a review outside the normal schedule, logged with the trigger.
Where regulation demands it
GDPR Article 24.1 makes the controller responsible for keeping protective measures current, the same obligation behind reviewing the AI policy after a material change.
Related controls
Via the shared Sekit CSF topic, not the framework's own index.