Why finance needs its own AI policy
Generic IT and HR AI policies rarely address what a finance team actually carries: unpublished results, client and payment data, price-sensitive information, and the audit trail behind figures that reach the statutory accounts. This template is written for that reality. It is a starting point to adapt, not legal advice, so have your DPO or legal adviser review it before you adopt it.
Free editable download
Get the editable AI usage policy (Word and Google Docs)
Enter your work email and the editable template opens straight away, ready to drop your company name in and adapt. No cost, no obligation.
The template
Copy the ten sections below into your own document, replace the bracketed owners with real names, and trim anything that does not apply. Every clause is written to be read and followed by a finance team, not by a compliance department.
1.Purpose and scope
This policy governs how the finance team uses generative AI and AI assistants in its work. It applies to every member of the finance function, permanent or contract, and to any AI tool used for finance tasks, whether licensed by the company or accessed personally. Its purpose is to let the team use AI to work faster while protecting confidential data, the accuracy of reported numbers, and the company’s regulatory position.
2.Approved tools
Only tools on the approved list may be used for finance work. A tool is added to the list only after the policy owner has checked its data-handling terms (whether inputs are used for training), its security posture, and its fit for the task. Personal or free-tier accounts must not be used for any work involving company data unless that specific tier is named on the approved list. Requests to add a tool go to the policy owner, not around them.
3.Data rules: what may and may not be entered
Never enter the following into any general-purpose AI tool: client or employee personal data, bank or card details, unpublished financial results, anything price-sensitive or inside information, passwords or keys, and any data covered by a confidentiality clause. You may enter anonymised, aggregated, or already-public information, and you may work with sensitive data only inside an approved enterprise deployment that is contracted not to train on it. When in doubt, anonymise first or ask the policy owner.
4.Human review and accountability
AI output is a draft, never a decision. Every number, journal, commentary, or analysis produced with AI assistance must be reviewed by a named person before it is used, filed, or sent. That reviewer is accountable for the output exactly as if they had produced it by hand. AI must not be the final approver of any transaction, control, or published figure.
5.Confidentiality and UK GDPR
Personal data entered into an AI tool is processing under UK GDPR and needs a lawful basis, data minimisation, and a tool that does not train on the input. Client confidentiality and any contractual data clauses continue to apply in full when AI is involved. If a task would require personal or client-confidential data to be entered into a tool, it must use an approved enterprise deployment or the data must be anonymised first.
6.Prohibited uses
Do not use AI to fabricate figures, backfill missing evidence, or generate support for a conclusion that the underlying numbers do not support. Do not use AI to bypass a control, an approval, or a segregation-of-duties rule. Do not present AI-generated text or analysis as independently verified when it has not been reviewed. Do not use unapproved tools for finance work.
7.Record-keeping and auditability
Where AI materially shapes a deliverable that feeds the accounts or a board decision, keep enough of a record to explain how it was produced: the tool used, the human reviewer, and the source data. The goal is that an auditor or reviewer can trace any AI-assisted figure back to its evidence, the same standard applied to any other working paper.
8.Roles and responsibilities
The policy owner (typically the FD or financial controller) maintains the approved-tools list, the data rules, and this document. Approvers sign off requests for new tools and for higher-risk uses. Every team member is responsible for following the data rules, applying human review, and raising anything unclear rather than guessing. Breaches are handled under the normal disciplinary and data-incident processes.
9.Training and competence
No one is expected to work this out alone. The team receives structured training on using AI safely and effectively for finance tasks, and new joiners are briefed on this policy as part of onboarding. Competence with AI is treated as a professional skill to be developed deliberately, not assumed.
10.Review
This policy is reviewed at least every six months and whenever a significant new tool or model is approved. The policy owner is responsible for keeping it current as tools, vendor terms, and regulatory guidance evolve.
How to put it in place
A policy on a shared drive that no one has read changes nothing. Three steps make it real: adapt the template with your named owners and your approved-tools list; brief the whole team on it in one short session, with the data rules front and centre; and put a six-monthly review in the calendar so the approved-tools list stays current. The policy is the guardrail. The habit of using it comes from training the team on what safe, useful AI actually looks like in their day-to-day work.
Governance is one module of the course
Writing and running an AI policy like this is a hands-on lesson in our AI for Finance Leaders course (£99), alongside the risk-and-control framework it sits inside. Prefer it done with your own team? Our team training builds the policy around your actual tools and workflows.