An AI policy your audit committee can sign.
A starting-point policy and risk-appetite statement, written to survive a committee review.
How to use this template
Somewhere in your company, AI is already touching a number that will end up in front of your board. The question your audit committee will eventually ask is simple: who approved that, and under what policy?
This template gives you the policy. It adapts the structure of COSO’s 2026 guidance, Achieving Effective Internal Control Over Generative AI, and COSO’s Enterprise Risk Management framework into a document a public-company audit committee can review, mark up, and sign. Part A is the policy. Part B is the risk-appetite statement. Part C is the sign-off page, with the questions your committee should ask before anyone signs.
Three rules before you touch it:
- Every [bracketed] item is yours to fill. Names, thresholds, systems, tiers. A policy with someone else’s placeholders still in it will not survive a committee review, and it shouldn’t.
- This is education, not legal or audit advice. Have counsel review it against your jurisdiction and disclosure obligations, and walk it past your external auditor before you rely on it for anything touching financial reporting.
- Shorter beats longer. Strike any section that doesn’t apply to how your company actually uses AI. A committee signs what it understands.
What’s inside
[Company] Generative AI Use and Governance Policy
Twelve sections covering purpose, scope, shadow AI, governance and named ownership, acceptable use, use-case inventory and tiering, control requirements, ICFR reliance, third-party and vendor requirements, monitoring, incident response, training, and policy review.
Risk-Appetite Statement
A committee-ready statement mapped to the tiers in Section 5 — no appetite, low, moderate, higher — with the responses drawn from COSO’s ERM framework: accept, avoid, pursue, reduce, share.
Before the committee signs
The six questions a well-run audit committee should put to management before signing, plus the approval block for the chair, CFO, and the executive accountable for AI risk.
When management can answer all six without reaching for a binder, the policy is ready to sign.
What this template doesn’t do
A template gets you a document. It doesn’t tier your actual use cases, design the controls behind Section 6, set thresholds your auditor will accept, or build the bench of people who can review AI output without leaning on the tool. That work is judgment work, and it’s specific to your company.
If your company is heading toward an audit, a raise, or a sale and this document raised questions you can’t yet answer, that conversation is what I do.
Contact me. chantal@chantalschutz.com — for fractional CFO engagements, board and audit-committee advisory, and AI-governance reviews.
The CFO-governance cluster
This template sits alongside two companion pieces in the library — the three now form a coherent starting kit for finance leaders being asked to govern AI:
- AI in the close: a control checklist — the working control points around any AI touching month-end, forecast, or reporting.
- The industrial-tech CFO — the primer on why the AI era is pulling the finance seat back toward atoms.