Write an AI policy your organisation will follow, in one working week.

Download the Australian or New Zealand edition and work through the five days below. By Friday you have a policy with a named owner, an approved tools register, a register of every AI use case and a fixed review date, and every clause carries the law it answers in your jurisdiction.

Both governments offer a free AI policy template, Australia's through the National AI Centre and New Zealand's through the Government Chief Digital Officer. Both stop at principles. The PolyGovern editions are editable Word documents with square-bracket placeholders, a legal reference line on every section, and four schedules that hold the registers and the staff acknowledgement.

Have two things ready on Monday morning: the list of AI tools your staff already use, and the name of the person who will own the policy. If you have no list yet, run the shadow AI discovery checklist first, because Day 2 is built on it. Section numbers below follow the Australian edition. The New Zealand edition adds a section 11, so its later sections run one higher.

Day 1 路 Sections 0 to 4

Choose the edition, set the scope and name the owner.

By the end of the day, section 0 carries an owner, an approver, a version and a next review date, and every role in section 4 has a person's name against it.

  1. 01

    Pick the edition. The skeleton is shared, so an organisation working in both countries can run the two side by side.

  2. 02

    Decide what this document replaces. The template is an enterprise AI governance policy with an acceptable use layer built in, and it carries procurement and employee usage rules as sections. If you already have a procurement policy or an HR usage policy, cross-reference it in section 20.

  3. 03

    In section 2, list who the policy covers (employees, contractors, volunteers and the board) and state that personal accounts are excluded.

  4. 04

    In section 3, tie each principle to the section that enforces it. Delete any principle you cannot tie to a control.

  5. 05

    In section 4, name the policy owner, the approver, the AI governance group, the compliance monitor, the use-case owners and the privacy officer.

Worked example 路 Principles without owners

A policy on public generative AI tools can sit beside an AI strategy for years while nobody holds enterprise-wide responsibility for AI and nobody can see where it is used across the organisation.

ASIC found a related gap at licensees, where some policies gave guiding principles without clear standards. Steps 04 and 05 are written against both problems.

Australian edition

Commonwealth agencies keep the clauses marked for the DTA policy for the responsible use of AI in government. It binds non-corporate Commonwealth entities. Other organisations delete those clauses. Accountable entities under the Financial Accountability Regime add their accountable persons to section 4.

Section 1 cites Corporations Act s 180, because ASIC treats director duties as technology neutral.

New Zealand edition

Public agencies keep the clauses marked for the Algorithm Charter, the Public Records Act 2005 and the Official Information Act 1982, and private organisations delete them. In section 4, agencies also name the responsible senior official the GCDO recommends.

Section 1 cites the directors' duties in ss 131 and 137 of the Companies Act 1993, and section 0 cites s 201 of the Privacy Act 2020 for the privacy officer.

Day 2 路 Sections 5 and 6, Schedules A to C

Register the AI already in use, then name the approved tools.

By the end of the day, Schedules A and B hold every approved tool and every current use case, each with an owner, and Schedule C is ready to screen new requests.

  1. 01

    Enter every AI use case on your discovery list in Schedule B, with an owner and a go-live date.

  2. 02

    Run each one through the Schedule C screening questions, which return normal, elevated or prohibited. Elevated uses need an impact assessment and a named owner before they continue.

  3. 03

    In section 6 and Schedule A, name the enterprise tools and tenancies staff may use. Prohibit everything else, personal accounts included, and write the path for requesting a new tool.

  4. 04

    Give each approved tool a data tier. Section 7 refers to these tiers on Day 3.

Staff who believe policy forbids AI at work keep using it anyway, and the request path in step 03 gives them a way in.

Worked example 路 Two approved lists

A tight list approves Copilot and Copilot Chat inside the organisation's own Office 365 tenancy and prohibits every other generative AI tool on its devices and for its business.

A list built on single-tenant tools can go further. It still bars personal AI accounts for work, and it lets staff upload confidential or internal data to the approved tools.

Australian edition

Schedule B follows the NAIC AI register template, and Schedule C uses the NAIC screening outcomes. Commonwealth agencies use Schedule B as the internal use-case register the DTA policy requires.

The OAIC expects due diligence on AI products to continue after purchase, so every Schedule A row carries a review date.

New Zealand edition

The GCDO recommends that each agency keep a register of AI use, and Schedule B is built to be that register. Public agencies add the Algorithm Charter risk matrix to Schedule C.

Section 5 cites the GCDO register recommendation for agencies and MBIE's inventory guidance for businesses.

Day 3 路 Sections 7, 8, 14 and 15

Write the rules for what goes in and what comes out.

By the end of the day, section 7 holds a tiered data table and section 8 sets the output review rule. Sections 14 and 15 cover security and records.

  1. 01

    In section 7, place each type of information in a tier: never entered, entered only in an approved tenancy, or permitted. Cover personal, sensitive, confidential, classified and client information, and intellectual property.

  2. 02

    In section 8, require a person to review any output before it is used, to check facts and citations, and to label material produced or edited by AI.

  3. 03

    In section 14, set access control and logging for the approved tools.

  4. 04

    In section 15, treat prompts, outputs and logs as business records and give them a retention period.

Worked example 路 Prompts as records

For a New Zealand council, prompts and chat histories are council information, discoverable under the Local Government Official Information and Meetings Act, and AI use leaves its recordkeeping obligations where they were. Section 15 applies the same logic to any organisation that keeps business records.

Australian edition

Section 7 follows the OAIC's recommendation that organisations do not enter personal information, and particularly sensitive information, into publicly available generative AI tools. Section 8 points HR teams to the Fair Work Commission's guidance note for documents lodged with the Commission.

An AI tool that generates or infers personal information is collecting it under APP 3, so section 7 cites APP 3 with APPs 6, 8 and 11 and the Notifiable Data Breaches scheme.

New Zealand edition

Section 7 carries the IPP 3A box. IPP 3A has been in force since 1 May 2026, so where an AI tool generates, infers or receives personal information from a third party, the register records how the individual is made aware or which exception applies. Health agencies use the variant for rule 12 of the Health Information Privacy Code 2020 on overseas transfer to an AI provider. Public agencies treat prompts, chat histories and outputs as official information and public records.

Section 7 applies the Privacy Commissioner's expectation that personal or confidential information goes into a tool only when the provider has confirmed it will not retain or disclose it.

Day 4 路 Sections 9 to 12

Set the rules for decisions about people.

By the end of the day, every decision about a person has a named human decision-maker and a channel for challenge. The privacy disclosure has an owner, and staff whose work AI changes have a consultation trigger.

  1. 01

    In section 9, bar AI from being the sole basis for a decision with legal or similarly significant effect, and name the person who decides and can overturn it.

  2. 02

    Add a contestability channel to section 9 that tells a person how to ask for a decision to be reviewed.

  3. 03

    In section 10, set bias testing before deployment and at fixed intervals after it.

  4. 04

    In section 11, state where customers learn about AI use: in the privacy policy, at the point of interaction, and through a label on any chatbot.

  5. 05

    In section 12, set the consultation trigger for AI that changes roles, hours, monitoring or skills.

Worked example 路 ASIC's licensee review

Of the 23 licensees ASIC reviewed, only 10 had policies referencing disclosure of AI use to affected consumers, and none appeared to have implemented specific contestability arrangements for AI. Steps 02 and 04 answer those two findings.

Australian edition

Section 9 carries the APP 1.7 readiness box. List the programs, the kinds of decisions and the kinds of personal information that must appear in the privacy policy by 10 December 2026, with a named owner and a target date. Health organisations use the variant for Ahpra's expectation that practitioners obtain consent before an AI scribe records and remain responsible for the clinical decision. Section 11 includes an AI transparency statement clause, mandatory for Commonwealth agencies under the DTA policy, and section 12 names the award consultation trigger for new technology with significant effects on employees.

APP 1.7 reaches programs that do a step substantially and directly related to the decision, so assisted decisions count, and it creates no right to contest.

New Zealand edition

This edition adds section 11, Te Tiriti o Waitangi and M膩ori data governance. It requires M膩ori data to be identified at screening, engagement with iwi or M膩ori advisers before go-live, onshore storage wherever possible, collective consent for collective data, and accuracy testing for M膩ori. The principles are attributed to Te Mana Raraunga, and the clause states that the organisation does not speak for M膩ori on how they apply. Public agencies add the Algorithm Charter commitments: a nominated point of contact, a channel for challenge, and publication of AI use. The workforce section cites the good faith duty in s 4 of the Employment Relations Act 2000.

Sections 9 and 10 cite the Human Rights Act 1993, and the M膩ori data governance page explains how to run the engagement section 11 requires.

Day 5 路 Sections 13 and 16 to 20, Schedule D

Connect vendors, incidents and review, then send it for sign-off.

By the end of the day, the policy has a vendor clause, an incident path tied to the breach rules, a training requirement and a fixed review date, and the draft is with the approver.

  1. 01

    In section 13, set the due diligence questions and contract terms for AI vendors: no training on your data, data location, breach notice, audit and exit.

  2. 02

    In section 16, define an AI incident, the reporting path, how a system is taken offline and the manual fallback while it is down.

  3. 03

    In sections 17 and 18, set the training requirement and the consequences of a breach under your code of conduct.

  4. 04

    In section 19, fix an annual review and keep the five triggers for an earlier one: an incident reported to the approver, a change in law or regulator guidance, a new class of AI tool such as agentic AI, an audit finding, or a material change in strategy.

  5. 05

    Send the draft to your legal adviser, then to the approver, and allow 2 to 4 weeks for consultation and approval. Once it is approved, collect a Schedule D acknowledgement from every person in scope.

Worked example 路 Review dates

We examined published AI policies from councils, a university and the New Zealand government template while building this one, and none stated a fixed review interval. The NAIC template is the exception, with an annual review plus triggers.

ASIC asks licensees how they ensure staff adhere to their AI policies. The signed Schedule D and the training records from section 17 are evidence you can hand over.

Australian edition

Section 13 carries an APRA annex for regulated entities: the CPS 230 material service provider test for AI vendors that support critical operations, and the CPS 234 information security assessment. The CPS 230 guide walks through the vendor test.

Section 16 routes AI data exposure, such as prompt leakage or a vendor breach, into the Notifiable Data Breaches scheme.

New Zealand edition

The procurement section draws on MBIE's AI procurement appendix and cites IPP 12 for providers that hold data offshore.

The incident section uses the same offline and manual fallback pattern as the Australian edition, and links it to the notifiable privacy breach rules in Part 7 of the Privacy Act 2020.

Reference

The clause map.

Every section in both editions with the law it answers. Keep the legal reference lines when you edit, so a reviewer can trace each clause back to its source.

# Section Australian legal reference New Zealand legal reference
0Document controlAPP 1.2 practices, procedures and systemsPrivacy Act 2020 s 201 privacy officer
1Purpose and commitmentCorporations Act s 180; ASIC REP 798Companies Act 1993 ss 131, 137; IoD guidance
2Scope and definitionsPrivacy Act s 6; OAIC deployer definitionPrivacy Act 2020 s 7; Te Mana Raraunga definition of M膩ori data
3Principles, each tied to a controlAI Ethics Principles; NAIC Guidance for AI AdoptionPublic Service AI Framework principles; MBIE guidance
4Roles and accountabilityASIC REP 798; FAR; DTA accountable officialsGCDO responsible senior official
5AI use-case register and screening gateNAIC register and screening; DTA register and impact assessment thresholdsGCDO register; Algorithm Charter risk matrix; MBIE inventory
6Approved tools and accountsOAIC due diligenceGCDO approved enterprise tools clause
7Information rules for inputsAPP 3, 6, 8, 11; NDB schemeIPP 1, 5, 10, 11, 12; IPP 3A; HIPC rule 12
8Rules for outputsAPP 10; FWC guidance note for Commission documentsIPP 8; OIA and Public Records Act for public agencies
9Decisions about peopleAPP 1.7 to 1.9 readiness box; anti-discrimination Acts; AHPRAIPP 3A; Human Rights Act 1993; Algorithm Charter human oversight
10Fairness and biasAnti-discrimination Acts; OAIC periodic checksHuman Rights Act; BORA; OPC accuracy for M膩ori
NZ 11Te Tiriti and M膩ori data governanceNot in the AU editionTe Mana Raraunga principles; OPC engagement expectation
11Transparency to customers and the publicAPP 1 and 5; DTA transparency statementIPP 3; GCDO publish AI use; Fair Trading Act
12Workforce consultation and changeFair Work Act and award consultation terms; WHS dutyEmployment Relations Act s 4; Health and Safety at Work Act
13Procurement and vendorsOAIC Checklist 1; DTA model clauses; CPS 230 and 234MBIE procurement appendix; IPP 12
14SecurityAPP 11; CPS 234IPP 5; Framework security principle
15Records and retentionAPP 11.2IPP 9; Public Records Act; OIA and LGOIMA
16Incident managementNDB scheme; NAIC offline and fallback patternPrivacy Act 2020 Part 7
17Training and competenceOAIC training content; DTA training requirementGCDO and MBIE skills guidance
18Non-complianceCode of conduct; whistleblower protectionsCode of Conduct for the Public Sector; Protected Disclosures Act
19Review and continuous improvementNAIC annual plus triggers; ISO/IEC 42001 A.2Algorithm Charter review precedent; ISO/IEC 42001 A.2
20Related documentsAPP 1 practicesGCDO related-policy list
A to DSchedules: approved tools register, use-case register, screening questionnaire, staff acknowledgementNAIC register; DTA registerGCDO register; MBIE inventory

Pick the edition for your jurisdiction.

Each download is an editable Word document of about twenty sections and four schedules, with square-bracket placeholders. Replace the placeholders, delete the clauses that do not apply, keep the legal reference lines, and have your legal adviser review the result before approval.

Free download 路 Word document

Australian edition.

APP 1.7 readiness box, APRA annex, award consultation trigger, Commonwealth agency clauses, health variant.

Free download 路 Word document

New Zealand edition.

IPP 3A box, Te Tiriti and M膩ori data governance section, public records clauses, Algorithm Charter commitments, health variant.

Thirty-minute call

Policy review against your register.

A senior consultant walks through your current AI policy, or the template as you have filled it in, against the use cases you run. See the Australian or New Zealand AI policy development service.

Download the Australian edition

Tell us who you are and the Word document will download straight away.

By submitting you consent to PolyGovern contacting you about the checklist. No spam; unsubscribe any time.

Download the New Zealand edition

Tell us who you are and the Word document will download straight away.

By submitting you consent to PolyGovern contacting you about the checklist. No spam; unsubscribe any time.

Questions the template gets asked.

Is a written AI policy required by law in Australia or New Zealand?

Neither country has an AI statute. New Zealand relies on existing law with no standalone AI Act, and Australia has not legislated mandatory guardrails for high-risk AI. The obligation to have a policy comes from the laws that already apply: privacy, anti-discrimination, employment, consumer protection, director duties and sector rules. The OAIC expects organisations to establish policies and procedures for AI use, and the Privacy Commissioner in New Zealand expects privacy policies to govern AI tools. For Australian non-corporate Commonwealth entities, the Digital Transformation Agency's AI policy is mandatory.

What is the APP 1.7 obligation and when does it start?

From 10 December 2026, an Australian organisation that has arranged for a computer program to make, or do something substantially and directly related to making, a decision that could reasonably be expected to significantly affect an individual's rights or interests, using personal information, must say so in its privacy policy. The policy must list the kinds of personal information used, the kinds of decisions made solely by the program, and the kinds of decisions where the program performs a related step. It is a transparency obligation and creates no right to contest a decision or to receive an explanation.

What is IPP 3A and does my AI policy need to cover it?

IPP 3A has applied under the Privacy Act 2020 since 1 May 2026. Where an agency collects personal information from someone other than the individual concerned, it must take reasonable steps to make the individual aware of specified matters. An AI tool that infers or generates information about a person, or that receives it from a vendor, is collecting indirectly. A New Zealand AI policy that permits that kind of use needs to say how the individual is made aware, or which exception applies.

How is this template different from the free NAIC and GCDO templates?

Australia's National AI Centre and New Zealand's Government Chief Digital Officer each offer a free AI policy template, and both are sound principle-level starting points. Neither maps clauses to statute, names approved tools, sets a fixed review interval with triggers, includes an AI register and screening gate inside the policy, or covers the APP 1.7 and IPP 3A obligations. The New Zealand official template does not go beyond a Treaty statement on M膩ori data. PolyGovern's editions add each of those.

What did ASIC find when it reviewed AI policies at financial services licensees?

ASIC reviewed 624 AI use cases across 23 AFS and credit licensees. Only 12 of the 23 had AI policies that referenced fairness or related concepts, and only 10 had policies referencing disclosure of AI use to affected consumers. Some policies set out guiding principles without clear standards, and no licensee appeared to have implemented specific contestability arrangements for AI.

Which policy types does the template cover?

The template is an enterprise AI governance policy with an acceptable-use layer built in. It covers the governance structure, the register and screening gate, information rules for inputs and outputs, decisions about people, procurement, security, records, incidents, training and review. Procurement and employee-usage rules sit inside it as sections. Organisations that already have a procurement policy or an HR usage policy can cross-reference those instead.

Does the template cover the public sector?

Yes. Clauses marked for Commonwealth agencies follow the structure of the DTA policy for the responsible use of AI in government. Clauses marked for New Zealand public agencies cover the Algorithm Charter for Aotearoa New Zealand, the Public Records Act 2005, the Official Information Act 1982 and the GCDO recommendation to publish agency AI use online. Delete the marked clauses if they do not apply.

How often should the policy be reviewed?

The template fixes an annual review and adds triggers for an out-of-cycle review: an incident reported to the approver, a change in law or regulator guidance, adoption of a new class of AI tool such as agentic AI, an audit finding, or a material change in strategy. None of the published AI policies we examined while building the template stated a fixed review interval, apart from the NAIC template, which sets an annual review plus triggers.

Get in Touch