Sections 4 & 4a of the template

Approved tools & how tools are approved

The heart of the whole policy. If you keep only one thing intact, keep this.

Home › Approved tools & how tools are approved

Staff may use AI for work only through tools your organisation has approved, and only through organisation-provided accounts. Everything else is off-limits by default. That starting point is deliberate.

What it is

A single, clear approval process that every tool goes through before it’s used for work. The approved list names each tool and what it’s approved for. Anything not on that list, including public consumer chatbots and anything reached through a personal login, isn’t approved and isn’t used. One point catches people out: a new AI feature that appears inside a product you already approve isn’t approved by default. It goes back through the same process before anyone uses it. (The policy template refers to this process as the approval gate.)

Governed exceptions (section 4a, optional). Include these only if you choose to permit named tools for single, tightly-defined purposes, with the same scrutiny applied and the exception written down rather than assumed.

Why it’s important

Without an approval process, rules like “no personal data into AI” or “a DPIA before deployment” can’t be enforced. With one, the important questions — what data the tool uses, your lawful basis for it, and what the supplier does with it — are answered before the tool is in daily use, not discovered afterwards. The DfE product safety standards and the ICO’s audit findings both point the same way: assess before you adopt.

A non-negotiable

Tool approval is a non-negotiable, and so is the rule that a new AI feature inside an existing product comes back through it. “We already use this supplier” isn’t the same as approval.

What you decide here

  • Which tools you approve, and the specific purpose each one is approved for.
  • Who approves additions, and how a member of staff requests one.
  • Whether you permit any governed exceptions (4a), and how they’re recorded.
  • How the approved list is published, and how staff know what’s blocked.

Assessing a particular product? The DPIA screening tool takes you through the questions your approval process should be asking.

Working on your AI policy?

Support with writing or refining it, and with training your staff, is exactly the work I do. And if the template or the screening tool has helped in your school or trust, I’d love to hear about it.