Skip to content

Responsible AI resourceMenuHomeModel policyDecisionsResearch & approachGet support

Leadership guide/The policy review standard

The policy review standard

A policy should
survive a real situation.

Use four lenses to distinguish a statement of intent from a rule that can guide institutional practice.

Download the review standard↓

Coverage

Does the policy address the issue? Locate the relevant provision and linked procedure. A missing web page is not proof that an institution has no rule.

Clarity

Can people apply the rule? Name the trigger, permitted or required action and any limits. Test a realistic exception.

Accountability

Who owns the decision? Identify authority, review, escalation and the route to correction. A committee name alone may be insufficient.

Implementation

What shows that it works? Look for current approvals, tested controls, prepared people and evidence from actual operation.

A worked exampleFrom a broad intention
to a usable rule.

Both statements address privacy. Only the second begins to tell a person what is permitted and how permission is established.

A general statement“Users must protect confidential information when using AI.”

A more actionable provision“Protected institutional information may be used only in AI tools and use cases approved for that information. Approval must identify permitted data, access, retention, vendor reuse and incident responsibilities.”

The stronger clause still needs an actual approval process, named owners and evidence that the controls work. Text alone cannot establish implementation.

Apply the standard to our modelShow the provision.
Then show the practice.

The model policy covers the twelve decision areas. The institution must supply local approvals and operational evidence. This crosswalk makes that distinction visible.

Purpose & institutional value

§1 §7 §10 §11

Policy testWhat should AI help your institution accomplish?

Implementation evidenceA purpose statement that explains the need in ordinary language. A baseline or reasoned comparison against current practice. Measures of benefit, error and effects on affected people.

Tools, use cases & vendors

§4 §5 §9 §12

Policy testWhat exactly does an approval authorize?

Implementation evidenceAn accessible list of approved uses and restrictions. Contract and technical review proportionate to the deployment. A named owner, review date and exit arrangement.

Data privacy & security

§5 §9 §11

Policy testWhat information can enter which AI systems?

Implementation evidenceAn information-flow description covering inputs, retrieval, output and logs. Documented authority and relevant contractual and security controls. A tested incident route and an owner who can contain exposure.

Human judgment & automated action

§6 §9 §11

Policy testWhen may AI assist, recommend or act?

Implementation evidenceA named reviewer with relevant expertise and authority. Records showing substantive review of representative difficult cases. A usable human reconsideration route and tested stop mechanism.

Teaching, learning & assessment

§7 §8 §10

Policy testWhat must students learn to do, with and without AI?

Implementation evidenceClear assignment expectations available in advance. Assessment evidence of student reasoning or performance. A supported route for access barriers and accommodations.

Academic integrity & authorship

§7 §8 §10

Policy testHow should the institution handle concerns about AI-assisted work?

Implementation evidencePublished rules describing permitted assistance and disclosure. A documented evidence-based inquiry and response opportunity. A consistent review route and staff preparation for using it.

Access, accessibility & equitable treatment

§6 §7 §10

Policy testCan the people affected participate and obtain effective help?

Implementation evidenceTask-based accessibility and participation checks. An effective support and accommodation route. Documented response to material barriers or differential effects.

Notice, disclosure & intellectual property

§5 §8 §10

Policy testWhen should someone know AI is involved?

Implementation evidenceExamples of acceptable notices for different uses. A clear process for rights and permissions questions. Communications that accurately represent the human involvement.

Governance & institutional authority

§3 §4 §12

Policy testWho recommends, who decides and who remains accountable?

Implementation evidenceA mandate with authority, deliverables and review dates. Named decision owners and approval routes. A record of resolved and escalated decisions.

Human capability & workforce relevance

§7 §10 §12

Policy testWhat do people need to be able to do responsibly?

Implementation evidenceRole-specific capability expectations. Practice and feedback using relevant scenarios. Evidence of performance and a route for additional support.

Incidents, concerns & remedies

§6 §9 §11

Policy testWhat happens when an AI-supported service gets something wrong?

Implementation evidenceA visible reporting route with accountable triage. A response exercise covering more than a cybersecurity breach. A record of correction, communication and restart conditions.

Monitoring & policy renewal

§4 §11 §12

Policy testWhat should trigger a new decision?

Implementation evidenceA current inventory with owners and review conditions. Documented review of outcomes, incidents and material changes. Explicit decisions to continue, change or retire uses.

A finding you can act onName what remains
to be resolved.

Use findings with reasons and evidence locations. A numerical score cannot decide whether a consequential safeguard is adequate.

Clear in the reviewed material

The provision and relevant procedure establish the arrangement. Identify the evidence and any operating verification still needed.

A decision is needed

The intent is present, but authority, conditions, exceptions or the practical rule remain ambiguous.

Evidence is missing

State whether the provision was not found, the supporting material was unavailable or implementation has not been demonstrated.

This is a HumanSkills qualitative review standard. It is not a nationally normed score, certification or legal-compliance determination. Independent calibration remains necessary before comparative scoring is offered.

Put the arrangements into practice.

Risk and approval, AI security, vendor evidence, release testing, monitoring and incident response.

Open operations and assurance→Download the guide→