Why does a small office need a written AI policy?
Because your people are probably using AI already, with or without your knowledge, and because the questions come from outside: a counterparty asks how you handle their documents, an insurer asks about controls, a family member asks who can see what. A one-page policy lets you answer in a minute. Without it, every answer is improvised.
You do not need to adopt a framework to write one, but public frameworks give you a vocabulary. The NIST AI Risk Management Framework 1.0 (January 26, 2023) is voluntary and organized around Govern, Map, Measure and Manage. NIST followed it with a Generative AI Profile, NIST-AI-600-1, on July 26, 2024, to help organizations identify risks specific to generative AI. ISO/IEC 42001, introduced in December 2023, is a certifiable standard for an AI management system. A small office does not need certification, but its themes (risk assessment, oversight of third-party tools, continuous improvement) overlap with the questions below.
If an SEC-registered adviser sits inside or beside your office, the SEC Division of Examinations' fiscal year 2026 examination priorities say it will review the accuracy of firms' statements about their AI capabilities and whether they have policies and procedures to monitor and supervise their use of AI. Many single family offices are not registered, so whether that applies to you is a question for counsel.
What are the ten questions to answer before staff use AI?
Write one or two sentences for each. If you cannot answer one, that is the first item on your list.
- Which data classes exist, and which may reach an AI tool? Sort your records into red, amber and green (table below). The rest of the policy hangs on this.
- Which tools and which plans are approved? Name the product and the plan tier. A tool on a free personal account is a different decision from the same tool on a business plan.
- What happens to what staff type? Find out from the provider's current terms how long inputs are kept, who can access them, and whether they may be used to train models. Record the date you checked.
- Who approves a new tool or a new use? One named person, a short request, a quick answer. Without this, staff approve for themselves.
- What do the vendor's terms and security documents say? Ask for the data processing terms and any security attestation, and have counsel review anything that touches red data.
- What do we owe clients, family members and counterparties? Check nondisclosure agreements, side letters, investor documents and engagement terms for limits on outside tools or on sharing information with third parties.
- What counts as an incident, and what happens next? Define it, for example red data entered into an unapproved tool. Say who is told, how fast, and who decides whether anyone outside is notified.
- How are staff trained? A short session at onboarding and a refresher each quarter beat a long document nobody opens.
- What do we log? Keep a list of approved tools, approval decisions, incidents and policy changes. Decide whether to keep prompts at all, since a log can itself hold sensitive data.
- When do we review? Quarterly is a sensible start while tools and terms change quickly. Put the date in the calendar and name the owner.
What do red, amber and green data look like in a family office?
Your counsel and your own obligations decide where the lines fall. Treat this as a starting point, and move an item up a level when in doubt.
| Level | Examples | Rule |
|---|---|---|
| Green | Public filings, published articles and reports, your office's public biography, generic templates with no names, invented scenarios. | Allowed in an approved tool. A person still checks the output. |
| Amber | Internal drafts and agendas, general correspondence, summaries of deals with names removed, staff scheduling, internal process notes. | Approved business-plan tools only, names removed where possible, retention settings checked, a person reviews every output. |
| Red | Account numbers, tax identification numbers, passwords and keys, privileged legal advice, family medical or children's details, identity and onboarding documents, deal materials under a nondisclosure agreement. | Not entered into any AI tool unless a named person approves in writing and counsel has reviewed the tool's terms. |
What does a one-page AI policy for a small office look like?
Copy this skeleton, fill the brackets, and cut anything that does not apply. It is a starting draft for you and your counsel, not a finished legal document.
AI use policy for [Office name]
Owner: [name]. Version date: [date]. Next review: [date].
- Purpose. This page says how our people may use AI tools while keeping family, client and counterparty information private.
- Scope. Everyone who works for or with [Office name], on any device used for our work.
- Approved tools. [Tool, plan, who may use it]. Anything not listed is not approved.
- Data rules. Green: allowed. Amber: approved tools only, names removed where possible, a person reviews the output. Red: never entered into an AI tool unless [name] approves in writing.
- Human review. A person checks every AI output before it is sent, filed or relied on. AI does not send messages or move money.
- New tools or uses. Ask [name]. Answer within [number] working days.
- Incidents. Tell [name] right away. We record what happened, what data was involved and what we did.
- Training. Every new team member before first use, and everyone each quarter.
- Records. [Name] keeps the approved tool list, approvals, incidents and policy versions.
- Review. Every quarter, or sooner if a tool's terms change.
Acknowledged by: [name, date].
Who should I ask, and what is this guide not?
This is a planning guide, not legal advice. Questions 3, 5 and 6 belong with counsel. Question 7 belongs with counsel and your IT or security provider. Your insurance broker can tell you whether your cyber or professional policies address AI tools. Your principal, or whoever runs operations, should own the page itself.
If you are the principal and have not used the tools yourself yet, start with the first 30 days for a principal, then write the policy. For an organization-wide view of the same decisions, read AI governance for non-technical CEOs, and for a standing home for them without a full-time hire, the center of excellence blueprint. If you want help setting this up, see executive AI coaching or fractional CAIO engagements.
Sources
- NIST, Artificial Intelligence Risk Management Framework (AI RMF 1.0). Released January 26, 2023 for voluntary use. NIST released the Generative AI Profile, NIST-AI-600-1, on July 26, 2024.
- KPMG Switzerland, ISO/IEC 42001:2023 (checked October 1, 2026). Describes ISO/IEC 42001, introduced in December 2023, as an international standard for AI management systems that can be certified.
- SEC Division of Examinations, Fiscal Year 2026 Examination Priorities. For advisers and broker-dealers, the Division said it would review the accuracy of statements about AI capabilities and whether policies and procedures monitor and supervise AI use.