Technology & Change Governance Policy Register
Governed register of all active policies — ratification status, version control, owner accountability, and per-initiative compliance signals.
7
Total Policies
5
Ratified
2
Draft / Pending
3
Non-Compliant Signals
10
Partial Compliance
Policy not yet ratified — AI Copilot Programme cannot advance to Established gate without ratification
Governance Champion role vacant — Developing gate criteria cannot be enforced without a named champion
AI Copilot Programme cannot advance without a ratified acceptable use policy
Responsible AI Use Policy
AI GovernanceEstablishes principles and controls for responsible AI use: fairness, explainability, human oversight, data governance, and robustness. Defines prohibited use cases and mandatory human-in-the-loop requirements for high-risk AI outputs.
Data Privacy & Protection Policy
Data PrivacyGoverns the collection, storage, processing, and deletion of personal data in compliance with applicable privacy regulations. Defines data classification tiers, retention schedules, and breach notification requirements.
Information Security Policy
SecurityEstablishes the information security framework including access controls, vulnerability management, incident response, and security review requirements for new technology deployments.
Technology & Change Governance Framework
Change GovernanceDefines the governance operating model for technology and change initiatives: decision rights, RACI requirements, lifecycle gate criteria, escalation paths, and the role of the Technology Governance Review Board.
Technology Risk Management Policy
Risk ManagementDefines the risk classification taxonomy (Low / Medium / High / Critical), standard controls per risk tier, risk assessment requirements at each lifecycle gate, and the risk appetite statement for technology investments.
Technology Lifecycle Management Policy
Technology LifecycleDefines standard lifecycle stages (Intake → Design → Build → Pre-Go-Live → Operate → Retire), required artefacts and sign-offs at each stage, and the criteria for advancing through lifecycle gates.
Acceptable Use Policy — Technology & AI Tools
Acceptable UseDefines acceptable and prohibited uses of technology tools, with specific provisions for AI-generated content: what can be published without review, what requires human sign-off, and what is prohibited entirely.