Complete one section per AI system or adapt this document as an organisation-wide protocol covering all systems. Legal review is recommended for sections covering intellectual property, privacy, and data residency obligations.
1. Data Inventory
| Data Type | Source | Contains Personal Information? | Sensitivity Level | Retention Period |
| [e.g. Employee timesheets] | [e.g. HRIS system] | Yes | Sensitive | [e.g. 7 years] |
| | | | | |
| | | | | |
2. Data Provenance & Quality
Training data source and provenance assessment
[Describe where the model's training data came from, whether it has been assessed for bias or quality issues, and any known provenance gaps.]
Ongoing data quality assurance measures
[Describe how input data quality is monitored — e.g. automated validation rules; manual spot-checking; vendor-provided data quality reports.]
3. Privacy Controls
- All personal information processed by AI systems is governed by [Organisation Name]'s Privacy Policy and the Privacy Act 1988.
- Personal information is not input into AI systems with third-party cloud processing without Privacy Impact Assessment approval.
- Generative AI systems must not be used with client or employee personal data unless approved by the Privacy Officer.
4. Intellectual Property Controls
IP rules for generative AI use
[Define what types of content (client proposals, confidential designs, proprietary cost data) must not be submitted to generative AI systems. Reference any approved tools and their data handling terms.]
5. Cybersecurity Measures
- All AI API integrations are protected by [authentication method — OAuth 2.0 / API key management / other].
- Access to AI systems is role-based and reviewed quarterly.
- Prompt injection testing is conducted on all publicly-facing or high-risk Generative AI deployments before go-live.
- AI system security events are logged and monitored within the organisation's SIEM or equivalent.