|
AI Governance Framework · ISO/IEC 42001:2023 Aligned
Large Language Model Acceptable Use Policy & Assessment HandbookA complete, adoptable governance pack for UK local authorities: how staff may safely use generative AI, how to assess a specific use case, and how every rule maps to formal ISO controls. Balances innovation with security — moving from flat prohibition to proactive risk management. {{ m.k }} {{ m.v }} Three deliverables in this pack
Deliverable 1
LLM Acceptable Use PolicyThe council-wide standard for how staff and members may use generative AI text tools — the boundaries, the data rules, and where accountability always sits. 1PurposeThis council recognises that Artificial Intelligence, particularly Large Language Models (LLMs), presents substantial opportunities to improve operational efficiency, accelerate administrative processes, and enhance public services for residents. From summarising complex consultation reports to drafting communications, generative AI can serve as a highly effective assistant. However, adoption introduces serious novel compliance, legal, security and ethical risks. Uncontrolled use of public AI tools can lead to accidental data breaches, violations of UK GDPR, dissemination of inaccurate information ("hallucinations"), and compromise of internal ICT networks. This policy establishes a clear, supportive framework that empowers staff to use LLMs safely while safeguarding personal data, maintaining accountability and protecting council systems — aligned with the ISO/IEC 42001 AI Management System standard. 2ScopeThis policy applies to all individuals who access council systems, networks, or perform duties on behalf of the Local Authority: Who it applies to
Technologies covered
3Approved Use CasesStaff are actively encouraged to explore LLMs for low-risk administrative and creative tasks — where the output does not directly affect individuals' legal rights or eligibility for public services. {{ a.t }}
{{ a.d }}
✔ Practical example — approved
A policy officer uses Microsoft Copilot to summarise a 200-page national report published by the Department for Levelling Up, Housing & Communities. Because the input is a publicly available document, this is an excellent, safe use case that saves hours of administrative labour. 4Prohibited Use CasesTo prevent severe legal breaches and uphold public trust, these uses are completely barred from public, un-sandboxed LLMs. No AI system may replace statutory human decision-making or handle sensitive individual data. {{ p.t }}
{{ p.d }}
✘ Practical example — prohibited
A benefits officer inputs a resident's medical letter and financial statements into ChatGPT, asking "Does this applicant qualify for an extraordinary discretionary housing payment?" This is a critical violation — it uploads Special Category Data and delegates a statutory assessment to an uncontrolled public AI. 5Data Handling — The Traffic-Light ModelBefore inputting any character into an LLM prompt box, staff must evaluate the classification of the data using this model. 6Human AccountabilityUnder no circumstances does an AI system displace the professional, ethical or legal responsibilities of a council officer. The council operates an absolute principle of Human-in-the-Loop. {{ a.t }}
{{ a.d }}
7Accuracy & HallucinationsLLMs operate on probabilistic text prediction, not empirical truth. They lack semantic understanding and are prone to hallucination — the convincing generation of facts, citations, dates and statutory references that do not exist.
8Security Requirements{{ s.t }}
{{ s.d }}
9Copyright & IP
10Transparency
Standard disclosure template
"This document was compiled with the assistance of automated generative AI tools. The final output was comprehensively reviewed, verified, and approved by a qualified council officer." 11Roles & Responsibilities{{ r.t }}
{{ r.d }}
12Monitoring & ComplianceThe council reserves the right to log, monitor and audit web traffic and data transferred across its corporate network. Automated tools are deployed to detect the transmission of personal-data patterns — such as National Insurance numbers or credit-card forms — into known external AI endpoints. Policy breaches
Intentional upload of personal or special-category data into public, non-secure LLMs will be treated as an information-security incident. Serious or repeated breaches may lead to revocation of ICT access privileges and formal disciplinary action, up to and including dismissal. Section 13 · Quick reference
LLM Acceptable Use — Executive Summary✔ The DOs
✘ The DON'Ts
GREEN
Public info — safe in any tool. AMBER
Internal — secured accounts only. RED
STOP — forbidden in public systems.
Deliverable 2
Use Assessment HandbookA practical companion to the policy. A simple, self-guided method for any employee to evaluate a specific AI use case, identify compliance requirements, and stay aligned with ISO/IEC 42001 and UK GDPR — no technical knowledge required. 1Quick Decision TreeFollow this logical path before executing any task using an LLM.
STEP {{ s.n }}
{{ s.q }}
{{ b.cond }}
{{ b.verdict }}
2Traffic-Light Assessment Matrix3Risk Assessment Form (Pro-forma)If your use case falls into the Amber tier or is a new operational workflow, complete this template and submit it to your Line Manager before commencing use. On screen: type into the fields, then save as PDF. {{ f.label }} {{ f.hint }} Data classification (tick one)
Green — Public
Amber — Internal
Red — Confidential
Human review protocol Manager sign-off / date 420 Practical Local-Government ExamplesAn operational dictionary for standard council scenarios. 5Daily AI Usage ChecklistPrint this page and keep it visible at your workstation as a daily compliance reminder. {{ g.title }}
If in doubt, do not paste — contact Information Governance immediately.
6Manager Assessment GuideAs a manager, you are the foundational firewall for AI governance. When a report submits a use-case proposal, evaluate it systematically. Critical questions to ask
{{ q.t }}
{{ q.d }}
Halt & escalate to IG / DPO if…
Approval guidance
You may approve at team level if the task is strictly administrative, deals exclusively with public or non-sensitive corporate data, and the employee confirms they will manually review 100% of the output before use. Record all approvals via email confirmation logs for auditability.
Deliverable 3
ISO/IEC 42001 Mapping AppendixFor internal auditors, compliance officers and external assessors — this appendix maps every section of the policy and handbook directly to the formal control areas of ISO/IEC 42001:2023 (Artificial Intelligence Management System). |