AI policy
1. Purpose
This policy sets out how staff at Ardent IFA Limited may use artificial intelligence tools at work. The aim is to allow sensible productivity gains while protecting Ardent IFA Limited, its clients, staff, confidential information, personal data and systems.
AI tools can be helpful for drafting, summarising, researching, analysing and improving workflows, but they must be used with judgement. AI output is not automatically accurate, private, unbiased, secure or suitable for use without review.
2. Scope
This policy applies to all employees, directors, contractors, temporary workers and anyone else using AI tools for Company business. It applies whether the AI tool is accessed on a Company device, personal device, web browser, mobile app, Microsoft 365 integration, browser extension, API, plug-in or third-party platform.
The policy covers general AI assistants, generative AI, image/audio/video AI tools, transcription tools, coding assistants, meeting summarisation tools, AI plug-ins, AI features built into existing products and any automated agent that can process or act on Company information.
3. Core policy statement
- Use only approved tools. Staff must only use AI tools that have been approved and recorded in the AI Tool Register.
- Do not enter confidential or personal data without approval. Client data, staff data, candidate data, HR data, financial data, legal data, special category data and confidential business information must not be entered into an AI tool unless the tool and use case have been approved.
- Use business or enterprise accounts. Free personal AI accounts must not be used for Company, client or staff information unless the Company has explicitly approved the use case as low risk.
- Review AI output before use. Staff remain responsible for checking accuracy, tone, bias, completeness, copyright risk, security risk and suitability.
- Report incidents quickly. Any accidental sharing of confidential, personal or client information with an AI tool must be reported immediately to IT, the Data Protection Lead or senior management.
4. External sharing position
Ardent IFA Limited may share this policy with clients, suppliers, auditors or other third parties to show that it has internal handrails for AI use. Before external sharing, the document should be checked to ensure it does not disclose sensitive details about internal systems, suppliers, controls or incidents.
5. Paid and free AI services
For Company work, Ardent IFA Limited will prefer paid business or enterprise AI services with appropriate contractual terms, administration controls, access controls, data protection commitments, retention settings, audit options and controls over whether prompts or uploaded files are used to improve public models.
Free or consumer AI services must not be used for Company, client, staff or personal data unless a specific low-risk use case has been approved. Free tools may be suitable for public information, general ideas and non-sensitive drafting, but they normally provide less organisational control and should be treated as unapproved until reviewed.
Microsoft 365 integrated AI tools may be a preferred option for Microsoft 365 content where Ardent IFA Limited can rely on existing tenant controls, permissions and business accounts. This is not automatic approval. Licensing, permissions, data location, retention, auditability and the specific use case must still be reviewed.
6. Definitions
| Term | Meaning |
| AI tool | Any software feature or service that uses artificial intelligence to generate, analyse, summarise, classify, transform or act on information. |
| Generative AI | AI that creates new text, images, audio, video, code, documents or recommendations from prompts or uploaded content. |
| Company data | Any information created, received, stored or processed for Company business. |
| Personal data | Any information relating to an identified or identifiable living person. |
| Special category data | More sensitive personal data such as health information, biometric data, ethnicity, religious beliefs, political opinions or trade union membership. |
| Confidential information | Non-public Company, client, supplier, employee, commercial, technical, financial, legal or operational information. |
| Approved tool | An AI tool that has been reviewed, risk assessed and marked as approved in the AI Tool Register. |
7. Permitted uses
Where an AI tool is approved for the relevant use case, staff may use it for low-risk work such as:
- Drafting general wording, internal notes, agendas, checklists and non-confidential emails.
- Summarising public information or internal information that the tool is approved to process.
- Improving grammar, structure, accessibility or clarity of non-sensitive text.
- Creating first-draft ideas, templates, training materials or brainstorming notes.
- Analysing anonymised or synthetic data where there is no realistic route to identify an individual, client or confidential matter.
- Helping with technical research, provided any code, command, configuration or security recommendation is independently checked before use.
8. Prohibited uses
Staff must not use AI tools for the following unless there is written approval from the relevant senior manager and the AI Tool Register confirms that the tool and use case are approved:
- Uploading client contracts, HR files, payroll information, personnel notes, medical information, candidate records, grievance records or disciplinary records.
- Entering passwords, MFA codes, API keys, security tokens, private keys, recovery codes or admin credentials.
- Entering full customer, client, employee or candidate records into a free or personal AI account.
- Uploading confidential documents from SharePoint, OneDrive, Teams, email or local folders to an unapproved AI platform.
- Using AI to make final decisions about recruitment, dismissal, promotion, pay, disciplinary action, creditworthiness, vulnerability, eligibility or other significant decisions about people.
- Using AI output as legal, medical, financial, HR, tax, regulatory or cyber security advice without suitable professional review.
- Using AI to generate deceptive content, impersonate a person, fake evidence, bypass security controls, write malware, avoid detection or breach a third party system.
- Installing AI browser extensions, plug-ins, desktop apps, agents or connectors without IT approval.
- Connecting an AI tool to email, SharePoint, OneDrive, Teams, CRM, finance systems, HR systems or client systems without formal approval.
- Allowing AI agents to send emails, delete records, change permissions, purchase goods, update client systems or take other business actions without approved controls and human oversight.
9. Data classification rules
| Data type | Examples | AI rule |
| Public | Public website text, published marketing copy, public job adverts, public product information. | Usually acceptable in approved tools. Check copyright and accuracy. |
| Internal | Internal templates, process notes, general internal guidance with no personal, client or confidential data. | Acceptable only in approved business tools. Do not use personal accounts. |
| Confidential | Client documents, contracts, pricing, proposals, meeting notes, strategy documents, security configurations, non-public financial data. | Do not enter unless the tool and use case are specifically approved. |
| Personal data | Names, contact details, employment records, candidate details, notes about individuals, images, voice recordings, transcripts. | Do not enter unless approved and lawful basis, transparency, minimisation, retention and supplier checks are complete. |
| Special category or high-risk personal data | Health, disability, ethnicity, religious belief, political views, trade union membership, biometric data, criminal offence data. | Do not enter unless specifically approved by senior management and the Data Protection Lead, with DPIA consideration. |
| Credentials and secrets | Passwords, tokens, keys, certificates, recovery codes, API secrets, private keys. | Never enter. |
10. Personal data and UK GDPR controls
Where AI involves personal data, the Company must be able to show that processing is lawful, fair, transparent, necessary, proportionate and secure. Staff must apply data minimisation and only use the minimum information needed for the specific task.
Before personal data is processed by an AI tool, the business owner must check whether the use requires a data protection impact assessment, whether the privacy notice covers the processing, whether a suitable supplier contract is in place, where data is stored and processed, whether data may be used for training, how long it is retained and how individual rights can be respected.
Anonymisation must be real, not cosmetic. Replacing a name with initials is not enough if the person can still be identified from job title, dates, location, case details or surrounding context.
All regulated advice and recommendations remain subject to appropriate human review and are the responsibility of the authorised adviser. We maintain controls to ensure any use of AI is undertaken in accordance with FCA requirements, Consumer Duty obligations and applicable GDPR laws.
11. Security controls
- AI tools must use approved accounts, strong passwords and MFA where available.
- AI tools must not be granted access to Company systems unless the access is approved, documented and limited to the minimum required.
- Browser extensions and plug-ins must be treated as software suppliers and must not be installed without approval.
- Staff must not open suspicious links, files, scripts, macros or downloads generated or recommended by AI without normal security checks.
- AI-generated code, PowerShell, scripts, firewall rules, email rules, registry changes and configuration changes must be checked by a competent person before use.
- The Company should prefer tools with enterprise controls, auditability, data protection commitments, clear retention controls and the ability to prevent prompts and files being used to train public models.
12. Approval process for AI tools
- The requester completes a new entry in the AI Tool Register or asks IT/Data Protection Lead to create one.
- The business owner defines the intended use case, data categories, users and expected benefit.
- Due diligence is completed i.e security, access, authentication, integration, supplier risk and technical controls.
- The Data Protection Lead reviews personal data, special category data, lawful basis, DPIA need, privacy notice impact, retention and international transfer risk.
- Only work emails may be used for any agreed AI tool.
- Senior management approves, rejects or restricts the tool.
- The tool is marked as Approved, Approved with Restrictions, Pilot, Rejected or Retired in the AI Tool Register.
- Staff are informed of the approved use cases and any restrictions before use begins.
13. AI Tool Register requirements
The Company must maintain an AI Tool Register. The register should include the tool name, supplier, owner, approved status, approved users, approved use cases, prohibited uses, data categories, personal data position, training/data-use settings, data location, retention, supplier contract status, DPIA status, risk rating, review date and decision history.
The register must be reviewed at least annually for active tools and whenever a supplier changes its terms, product features, data processing arrangements, security controls or pricing model.
14. Human review and accountability
AI is a support tool, not a replacement for professional judgement. Staff must review output before relying on it or sharing it. The person using the output remains responsible for the final work product.
- Check facts, figures, dates, names and references.
- Check tone, fairness, bias and potential discrimination.
- Check whether output includes invented sources, fake citations or unsupported claims.
- Check whether output contains confidential information that should not be shared.
- Check whether output might copy protected text, code, images or designs from elsewhere.
- Check technical output in a safe test environment before applying it to live systems.
15. Meeting notes, transcription and recordings
AI meeting transcription or summarisation must only be used where the tool is approved and participants are informed where required. Meeting recordings, transcripts and summaries may contain personal data and confidential information. They must be stored, shared and deleted in line with Company retention rules and any client instructions.
16. Client and third-party obligations
Where Company work is carried out for a client, staff must also follow any client contract, NDA, security policy, procurement rule or data processing instruction. Client information must not be placed into an AI system where this would breach a contract, NDA, client policy or data processing agreement.
17. Incidents and escalation
Staff must immediately report any actual or suspected AI-related incident, including accidental upload of confidential or personal data, use of an unapproved tool, unauthorised connector access, incorrect AI output used in a client matter, suspicious AI-generated link/file, or unexpected disclosure of information.
Reports should go to the Data Protection Lead or a director. Staff should not attempt to hide or delete evidence without advice. Rapid reporting helps the Company contain risk and decide whether any data protection notification is required.
18. Roles and responsibilities
| Role | Responsibilities |
| All staff | Follow this policy, use approved tools only, protect data, review outputs, report incidents. |
| Managers | Ensure team use is appropriate, approve business need, challenge risky use, support training. |
| IT (External: Genius) | Review technical security, integrations, access, MFA, logging, software approval and incident response. |
| Data Protection Lead | Review personal data, DPIA need, privacy notices, supplier terms, retention and individual rights. |
| Senior management | Approve risk appetite, high-risk use cases, budget and final acceptance of restricted AI tools. |
19. Training and awareness
Staff who use AI tools must receive suitable guidance on safe use, prompt discipline, data protection, cyber security, accuracy checking, bias, confidentiality and incident reporting. The Staff AI Usage Guide should be issued alongside this policy.
20. Monitoring and compliance
The Company may review AI usage records, tool approvals, licence assignments and system logs where lawful and proportionate. Breach of this policy may lead to removal of access, further training, disciplinary action or contractual action depending on severity.
21. Review
This policy must be reviewed every 12 months or sooner if there is a material change in AI law, ICO guidance, cyber security guidance, supplier terms, business use, client requirements or Company systems.
22. Quick staff rules
| Do | Do not |
| Use approved Company AI tools and accounts. | Use personal/free AI accounts for Company or client data. |
| Ask AI to help draft, summarise or improve low-risk content. | Paste client, HR, candidate, payroll, legal or confidential information into unapproved tools. |
| Anonymise properly and minimise data. | Assume replacing a name is enough to anonymise a person or client. |
| Check AI output before using it. | Trust AI output as automatically accurate, lawful or secure. |
| Report mistakes quickly. | Hide accidental uploads or unapproved AI use. |
Reference guidance
The policy has been prepared with reference to current UK guidance from the Information Commissioner’s Office, the National Cyber Security Centre and GOV.UK, including:
- ICO artificial intelligence guidance: https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/
- ICO guidance on AI and data protection: https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/guidance-on-ai-and-data-protection/
- NCSC AI and cyber security guidance: https://www.ncsc.gov.uk/guidance/ai-and-cyber-security-what-you-need-to-know
- NCSC guidelines for secure AI system development: https://www.ncsc.gov.uk/collection/guidelines-secure-ai-system-development
- GOV.UK AI Cyber Security Code of Practice: https://www.gov.uk/government/publications/ai-cyber-security-code-of-practice