On April 22, 2026, the Superior Court of Quebec set aside an arbitral award involving a claim of $1.225 million. The reason had nothing to do with the merits of the case. The arbitrator had drafted the reasons with the help of a generative AI tool, and counsel discovered that the cited references did not exist: one fabricated scholarly article and three fictitious decisions.
The problem was not the use of AI. Two things were missing: a written rule that says who verifies what before a text becomes an official document, plus a named owner to enforce it.
That is an AI governance policy. Not a document that bans products. A document that assigns responsibilities and makes what your company does with artificial intelligence verifiable.
What AI governance means in practice
I have already written about the definition of AI governance and the tightening framework, including in ISO 42001: What You Need to Know Before You Start. I will not repeat that in detail. What matters for what follows fits in one sentence: governing AI is not about controlling the technology. It is about deciding in advance who answers for what, which limits apply, and what happens when a system is wrong.
ISO/IEC 42001, published in December 2023, is the first international standard that frames an artificial intelligence management system. Like ISO 27001, it rests on a continuous improvement cycle and on an annex of controls: 38 controls across nine objectives, numbered A.2 to A.10.
Those nine objectives boil down to nine questions.
A.2 Policy
Do you have an approved policy?
A.3 Accountability
Who owns it?
A.4 Resources
Are your people competent and your systems documented?
A.5 Impacts
Did you assess impacts before deploying?
A.6 Lifecycle
Do you track your systems from acquisition to retirement?
A.7 Data
Do you know which data feeds them?
A.8 Informing people
Do you inform people who are affected?
A.9 Use
Do your teams use these tools for what they are meant for?
A.10 Suppliers
Are your suppliers governed?
The template below covers these nine dimensions in a single document and gives you the structure to produce the evidence that goes with them. It does not tick all 38 controls, and it is not a certification. It is the starting trail: the one that lets an auditor or a client see that someone sat down and decided, instead of hearing you explain verbally that “everyone is careful.”
An auditor does not stop at the document. They check that it fits your reality, that it was communicated, understood, and actually applied, and that it holds together with the rest of your management system. The entry door, though, is always the same: a last-revision date, an approver’s name with the authority to approve it, and proof that employees received it. A perfect policy nobody signed is worth less than an imperfect policy with fifty dated acknowledgements.
Three mistakes that make a policy useless
A product list instead of rules
The first is to build the policy around a list of allowed or banned products. An approved-tools list is useful. It tells you which account to use tomorrow morning. It cannot be the heart of the policy, because it goes stale as soon as a new tool appears. Core rules must address data, uses, and authorization levels. The tool list comes after, as an application of those rules, not as their foundation.
Principles without verifiable rules
The second is to write only principles. “The employee must exercise judgment” is not a rule. It is a wish. A rule can be verified: either the person validated the facts before sending the document to the client, or they did not.
One document for two audiences
The third is to draft a single document for two audiences. Management needs the full frame. The employee needs to know what to do on Tuesday morning. That is why section 8 of the template is written so it can be detached from the rest and signed as is.
The template
What follows is a starting point. Adapt it to your reality and have it reviewed by your legal counsel and by your privacy officer. Replace everything in brackets. Cut what does not apply to you: a company that only uses commercial tools can remove a large part of section 9. If you only use SaaS tools, I also detailed which ISO 42001 controls may not apply in ISO 42001: Your SMB Only Uses ChatGPT?.
A note for standard purists: this template groups in one document what a large organization would split into policy, directive, and procedure. In an SMB, that grouping is acceptable and often preferable. What matters is that the rules are approved, known, and applied, not that they are spread across three documents nobody reads.
Copy everything that follows.
Artificial intelligence governance policy
Organization: [Company name]
Version: 1.0
Effective date: [date]
Approved by: [name, title]
Next review: [date, maximum 12 months]
1. Purpose
This policy sets out how [Company name] governs the acquisition, use, monitoring, and retirement of artificial intelligence systems. It aims to enable use of these tools while protecting personal information, confidential information, the quality of work delivered to our clients, and people affected by our decisions.
2. Scope
This policy applies to all employees, contractors, interns, and directors of [Company name], without exception, including management.
It covers any system that generates content, analyzes information, produces a recommendation, or performs tasks based on an artificial intelligence model, whether purchased, cloud-based, embedded in existing software, or developed internally. This includes conversational assistants, AI features built into software you already use, browser extensions, meeting transcription and summary tools, online translators, and autonomous agents.
If you are not sure whether a tool is covered, assume that it is and ask the responsible person identified in section 4.
3. Definitions
- AI system: software that, from data, produces content, predictions, recommendations, or decisions.
- Generative AI: a system that produces text, images, code, audio, or video.
- Agent: an AI system that performs actions autonomously in another software or service.
- Automated decision: a decision about a person taken from automated processing, without human intervention.
- Hallucination: a result invented by an AI system, presented with the same confidence as an accurate result.
4. Roles and responsibilities
- [Name, title] is the AI governance owner. They approve this policy, decide exceptions, and report to [board of directors or management committee] at least once a year.
- [Name, title] maintains the inventory of AI systems, approves any new use, and keeps risk assessments.
- [Name, title], privacy officer, is consulted before any use involving personal information.
- Each manager ensures that members of their team have read this policy and acknowledged it.
- Each employee remains responsible for the work they produce, regardless of the tool used to produce it.
5. Objectives
[Company name] sets the following objectives for the period [year]:
- Keep an up-to-date inventory of all AI systems in use, reviewed at least [quarterly]
- Train [100%] of covered staff before [date]
- Assess the risk of every new system before it goes live, without exception
- Record and handle [100%] of reported AI-related incidents
These objectives are reviewed annually together with the policy.
6. Inventory of AI systems
[Company name] keeps a written inventory of all AI systems in service. For each one, the inventory records the tool name, vendor, user department, intended use, type of data processed, internal owner, assigned risk level, and date of last review.
No system may go live without being listed. The inventory is reviewed at least [quarterly].
7. Risk and impact assessment
Before an AI system goes live, [Name, title] assesses and records the following: the nature of the data processed, the possible consequences of an incorrect result, the people who could be affected, the risk of discriminatory processing, and the degree of autonomy granted to the system.
Each system receives a risk level: low, medium, or high.
For the purposes of this policy, a system is automatically classified as high internal risk if it touches hiring, compensation, discipline, access to a service, credit decisions, a person’s health, or a person’s safety. This classification is internal. It does not determine the legal qualification of the system under applicable law.
A high internal-risk system requires written approval from [Name, title] before it goes live. If it processes personal information, a privacy impact assessment is completed before go-live when applicable law or our internal rules require it.
The assessment is redone if the use changes, or at least once a year for high-risk systems.
8. Acceptable use rules
This section is given to every employee and is the subject of the acknowledgement in section 16.
8.1 Authorized tools
Only the following tools are approved for professional use, and only from the enterprise account provided by [Company name]:
- [Tool 1, e.g. Microsoft 365 Copilot, enterprise account]
- [Tool 2]
- [Tool 3]
Using a free personal account for company work is prohibited, even if it is the same product. The contractual protections that cover us are tied to the enterprise account, not to the logo on the screen.
To request addition of a tool, write to [email address]. Do not install anything before you receive a reply.
8.2 Data: what may be entered, and where
| Type of information | Public tool, personal account | Approved tool, enterprise account |
|---|---|---|
| Information already public | Allowed | Allowed |
| Non-sensitive internal document | Prohibited | Allowed |
| Personal information (client, employee, candidate) | Prohibited | Allowed only if authorized in writing by [Name, title] and compatible with our legal and contractual obligations |
| Trade secret, source code, client contract | Prohibited | Allowed only if authorized in writing by [Name, title] and compatible with our legal and contractual obligations |
| Health, financial, or judicial data | Prohibited | Prohibited without written authorization from [Name, title] |
An internal authorization alone is not enough. Many of our client contracts forbid transmitting their information to a third party, including an AI vendor, without their consent. Check the contract before requesting authorization.
When in doubt, ask yourself this before pasting anything: does this information identify a person, reveal a competitive advantage of the company, belong to a client, or could it cause harm if it got out? If yes, stop and ask.
8.3 Prohibited uses
The following uses are prohibited at all times:
- Circumventing a security measure, access control, or confidentiality rule of the company or of a client
- Producing discriminatory, harassing, defamatory, or illegal content
- Generating content that imitates a real person, their voice, or their image, without their written consent
- Using an AI tool alone to take a decision that affects a person’s employment, hiring, compensation, discipline, or access to a service
- Uploading a client document into an unapproved tool, including to translate or summarize it
- Presenting AI-generated content as coming from a verified source without performing the verification described in section 8.4
8.4 Mandatory verification before use
This rule covers content produced by an AI tool at a person’s request. Actions executed by an agent approved under section 8.6 follow instead the limits defined at approval.
Content produced by an AI tool is a draft. It becomes a deliverable only after human verification.
Before sending to a client, publishing, filing in an official record, transmitting to a third party, or relying on AI-assisted content for an important decision, you must:
- Verify every fact, figure, citation, reference, statute, or name cited in a primary source, not in the tool that generated it
- Confirm that the content actually matches the request and the matter context
- Correct or remove anything you cannot confirm
An AI tool can invent a reference that looks entirely real. This verification is not a suggestion.
8.5 Human oversight
No decision that produces a legal effect or a significant effect on a person may be taken solely from automated processing. An identified human must review the decision and own it.
When an AI system is used in a process that affects a person, [Name, title] must be notified before deployment to assess the information and review obligations under Quebec’s Law 25, including its section 12.1.
8.6 Agents and automation
An agent that performs actions autonomously, such as sending an email, modifying a file, creating a record in a system, or triggering a payment, must be approved by [Name, title] before it goes live.
Each agent must have a named owner, a documented list of systems it can access, and a clear limit on actions it may execute without human validation.
9. Lifecycle of internally developed systems
This section applies if [Company name] designs, trains, fine-tunes, or integrates its own AI systems.
For each developed system, [Company name] documents the intended purpose and excluded uses, training data and its provenance, tests performed before go-live (accuracy, behavior on unexpected input, prompt-injection attempts), who approved production release, and criteria for retiring the system.
This documentation is retained for the life of the system and for [duration] after retirement.
10. Data
Data used to feed or train an AI system must have a known provenance and a verified right of use.
No personal information is used to train a model without a documented legal basis and written authorization from [Name, title].
Retention of data transmitted to an AI vendor must be known and recorded in the inventory.
11. Vendors and third parties
Before contracting with an AI vendor, [Name, title] verifies and keeps evidence of the following: whether the agreement excludes use of our data to train the vendor’s models, where data are hosted and retained, for how long, what incident-notification obligations apply, and whether the vendor’s contractual, organizational, and technical measures are compatible with the obligations that apply to us.
Use of a vendor that processes personal information on our behalf must be covered by a writing that sets out the applicable protection measures, as required by Law 25. A disclosure of personal information outside Quebec also requires a prior assessment, to be validated by [Name, title] or by legal counsel.
12. Transparency toward people
[Company name] applies the following principle: when a person could reasonably believe they are interacting with an employee while they are interacting with an AI system, they are clearly informed.
When a decision about them is based on automated processing, they are informed, may obtain the main factors that led to the decision, and may request review by a person.
AI-generated content published in the name of [Company name] is verified under section 8.4 before publication.
13. Competence and training
Every covered employee must complete AI-use training before using an approved tool, then an annual refresh. Training covers recognizing personal information, hallucinations, and the verification procedure in section 8.4.
Participation and understanding are recorded (signed acknowledgement, quiz result, or training register).
14. AI-related incidents
Report immediately to [Name, title or email address] any situation where:
- Confidential information or personal information was entered into an unapproved tool
- AI-generated content containing an error was sent to a client or published
- An AI system produced a discriminatory or inappropriate result
- An agent executed an unintended action
Reporting quickly does not trigger discipline. Failing to report does.
Each report is recorded in the AI incident register with the date, description, measures taken, and correction applied. The company assesses and records each confidentiality incident, then determines whether notice to the Commission d’accès à l’information and to the affected persons is required because a risk of serious injury exists.
15. Monitoring and improvement
[Name, title] presents to [board of directors or management committee], at least once a year, a report covering the state of the inventory, incidents that occurred and how they were handled, achievement of the objectives in section 5, gaps identified, and planned corrective actions with an owner and a deadline.
This policy is reviewed at least once a year, or earlier if a regulatory change, an incident, or the arrival of a new system warrants it.
Failure to comply with this policy may lead to disciplinary measures, up to termination, depending on severity and consequences for the company or its clients.
16. Acknowledgement
I have read and understood the artificial intelligence acceptable use rules of [Company name]. I commit to follow them and to report any incident covered by section 14.
Name: ______________________
Signature: ______________________
Date: ______________________
End of template.
In practice: adopt it in 30 days
Do not build all sixteen sections at once. Complexity is the enemy of security. Here is an order that works.
Week 1
List the AI tools actually in use, asking without threat. You will find ones you did not suspect. That list becomes your section 6.
Week 2
Name the owners in section 4 and fill the brackets in sections 1 to 8. One person per role, not a committee.
Have sections 8.2, 8.5, and 11 reviewed by your legal counsel. Those three expose you the most.
Week 3
Have the policy approved by the person with authority to approve it, keeping the trail (minutes, dated email).
Distribute section 8 to all staff with a thirty-minute meeting, then collect signed acknowledgements. Keep the acknowledgements in one folder.
Week 4
Complete sections 9 to 12 only for systems already in service. A non-applicable section is acceptable, provided the non-applicability is justified in writing.
After 30 days, you have an approved document, an inventory, a named owner, and dated acknowledgements.
What this template does not do
It does not make you ISO 42001 compliant. The standard also requires a context analysis, documented planning, internal audits, and a proper management review. The template gives you several elements of the governance system, not the full management system.
It does not replace a privacy impact assessment when one is required. The CAI expects one before deployment, not after a complaint.
If you sell to European clients, two dates changed this summer. The European Union’s digital omnibus regulation entered into force on July 27, 2026 and postpones to December 2, 2027 most high-risk system obligations that were due to apply on August 2, 2026. Transparency obligations, such as disclosing that a person is interacting with AI and labeling generated content, have applied since August 2, 2026. The AI literacy obligation was softened: it now requires taking measures to support team competence, without guaranteeing a precise level. The postponement gives you time. It does not give you a pass.
In short
A governance policy does not make an AI system infallible. It reduces the risk that it is wrong, then it names the person who was supposed to verify before the error left your company. That is a thin difference on paper and a huge one on the day an erroneous document reaches a client.
In the April matter, the award was set aside because the reasoning rested on invented sources. The question I have been asking clients since: if one of your deliverables from the last three months contained an invented reference, would you know which one?
Want to know where you stand on this? Let’s talk.