Responsible AI resourceMenuHomeModel policyDecisionsResearch & approachGet support
Leadership guide/The policy review standard
Use four lenses to distinguish a statement of intent from a rule that can guide institutional practice.
Does the policy address the issue? Locate the relevant provision and linked procedure. A missing web page is not proof that an institution has no rule.
Can people apply the rule? Name the trigger, permitted or required action and any limits. Test a realistic exception.
Who owns the decision? Identify authority, review, escalation and the route to correction. A committee name alone may be insufficient.
What shows that it works? Look for current approvals, tested controls, prepared people and evidence from actual operation.
Both statements address privacy. Only the second begins to tell a person what is permitted and how permission is established.
A general statement“Users must protect confidential information when using AI.”
A more actionable provision“Protected institutional information may be used only in AI tools and use cases approved for that information. Approval must identify permitted data, access, retention, vendor reuse and incident responsibilities.”
The stronger clause still needs an actual approval process, named owners and evidence that the controls work. Text alone cannot establish implementation.
The model policy covers the twelve decision areas. The institution must supply local approvals and operational evidence. This crosswalk makes that distinction visible.
Policy testWhat should AI help your institution accomplish?
Implementation evidenceA purpose statement that explains the need in ordinary language. A baseline or reasoned comparison against current practice. Measures of benefit, error and effects on affected people.
Policy testWhat exactly does an approval authorize?
Implementation evidenceAn accessible list of approved uses and restrictions. Contract and technical review proportionate to the deployment. A named owner, review date and exit arrangement.
Policy testWhat information can enter which AI systems?
Implementation evidenceAn information-flow description covering inputs, retrieval, output and logs. Documented authority and relevant contractual and security controls. A tested incident route and an owner who can contain exposure.
Policy testWhen may AI assist, recommend or act?
Implementation evidenceA named reviewer with relevant expertise and authority. Records showing substantive review of representative difficult cases. A usable human reconsideration route and tested stop mechanism.
Policy testWhat must students learn to do, with and without AI?
Implementation evidenceClear assignment expectations available in advance. Assessment evidence of student reasoning or performance. A supported route for access barriers and accommodations.
Policy testHow should the institution handle concerns about AI-assisted work?
Implementation evidencePublished rules describing permitted assistance and disclosure. A documented evidence-based inquiry and response opportunity. A consistent review route and staff preparation for using it.
Policy testCan the people affected participate and obtain effective help?
Implementation evidenceTask-based accessibility and participation checks. An effective support and accommodation route. Documented response to material barriers or differential effects.
Policy testWhen should someone know AI is involved?
Implementation evidenceExamples of acceptable notices for different uses. A clear process for rights and permissions questions. Communications that accurately represent the human involvement.
Policy testWho recommends, who decides and who remains accountable?
Implementation evidenceA mandate with authority, deliverables and review dates. Named decision owners and approval routes. A record of resolved and escalated decisions.
Policy testWhat do people need to be able to do responsibly?
Implementation evidenceRole-specific capability expectations. Practice and feedback using relevant scenarios. Evidence of performance and a route for additional support.
Policy testWhat happens when an AI-supported service gets something wrong?
Implementation evidenceA visible reporting route with accountable triage. A response exercise covering more than a cybersecurity breach. A record of correction, communication and restart conditions.
Policy testWhat should trigger a new decision?
Implementation evidenceA current inventory with owners and review conditions. Documented review of outcomes, incidents and material changes. Explicit decisions to continue, change or retire uses.
Use findings with reasons and evidence locations. A numerical score cannot decide whether a consequential safeguard is adequate.
The provision and relevant procedure establish the arrangement. Identify the evidence and any operating verification still needed.
The intent is present, but authority, conditions, exceptions or the practical rule remain ambiguous.
State whether the provision was not found, the supporting material was unavailable or implementation has not been demonstrated.
This is a HumanSkills qualitative review standard. It is not a nationally normed score, certification or legal-compliance determination. Independent calibration remains necessary before comparative scoring is offered.
Risk and approval, AI security, vendor evidence, release testing, monitoring and incident response.