Getting a policy used, not filed

You will be able to plan a rollout that makes the policy part of daily work.

Most workplaces have a folder of policies nobody has opened since the day they were uploaded. Staff signed something on their first day saying they'd read them. Ask anyone what the IT policy says about USB drives and you'll get a blank look. An AI policy that ends up in that folder will protect nobody.

Daniel, from lesson 8.2, What goes in a team AI policy, has his draft. Now he needs it to change what the clinic's front desk and physiotherapists actually do on a busy Monday. This lesson covers how to get a policy used rather than filed.

One page, with your team's own examples

Length is the first thing that decides whether a policy gets read. A one-page policy can be read in two minutes and remembered. A ten-page one gets skimmed once and forgotten.

If your draft is longer than a page, cut it. Keep the four sections from lesson 8.2 and, under each, the rules people actually need. Move anything rarely needed, such as how to evaluate a new vendor in detail, into a separate note the policy owner keeps.

Then check that every example comes from your team's real work. "Do not input personal data into unapproved tools" is correct and forgettable. "Don't paste the patient feedback spreadsheet into your own ChatGPT" is something a receptionist will remember the next time she's about to do exactly that. Daniel went through his draft and replaced every generic example with one from the clinic.

Walk through it together

Sending the policy by email is the fastest way to make sure nobody reads it. Walk through it in a team meeting instead.

Daniel booked fifteen minutes at the start of the clinic's monthly staff meeting. He put the page on screen and spent a couple of minutes on each section, talking mostly about the examples. Then he stopped and asked a simple question: what would you still not know how to handle?

The questions that come back are the most useful part of the rollout. At the clinic, a physiotherapist asked whether she could use an AI app on her own phone to transcribe her notes after a session, and a receptionist wanted to know whether a patient's message in Malay could go into the approved assistant for translation. Daniel's page answered neither question.

Write every question down. Some you can answer on the spot, and the answer can go into the policy. Some you'll need to take away. Those gaps are much better found in a meeting than in the middle of a real incident.

Name an owner and a review date

A policy without an owner goes out of date quietly. AI tools change their features and their terms often, as lesson 1.2, Personal, business and enterprise accounts are not the same, pointed out, while new tools keep arriving and the team's own work shifts. Within a year, a policy nobody looks after will describe tools people no longer use and say nothing about the ones they do.

So the policy needs a policy owner: a named person who answers questions about it, approves new tools, and updates it. Daniel took the job at the clinic. Put the owner's name at the top of the policy, so people know who to ask.

It also needs a review date. A fixed date, written on the policy, works better than "regularly". Pick one a few months out for the first review, since the first version will have the most gaps, and then a regular interval after that. Put the date in the owner's calendar. At each review, check the approved tools list against what people actually use, reread the providers' current terms, and fold in the questions people have asked since the last version.

Check with the people who know the law

Before the policy is final, show it to your data protection officer, or to your legal or compliance team if you have one.

This course gives you working knowledge of the PDPA and the risks around AI, but it isn't legal advice, and your organisation may have obligations or contracts you don't know about. The data protection officer can check that the data rules match the organisation's PDPA obligations and its existing policies. Legal can check that the disclosure and client confidentiality rules match what's in client contracts.

At a small business, the data protection officer might be the owner, or the person who does the admin, and that works perfectly well. The point is that someone with responsibility for personal data has read it and agreed.

Daniel showed his draft to the clinic's data protection officer, one of the owners, before the staff meeting. She added a line about the clinic's patient management software, which already had an AI feature switched on that Daniel hadn't known about.

Before your own rollout, you'll need four things decided: when the team walkthrough happens, who owns the policy, who reviews it before it's final, and when it next gets looked at.

Write a rollout plan with the meeting date, the owner, the reviewer and the next review date.

Course

Junxiong-WFG Organisation is an authorised representative of AIA Financial Advisers Private Limited (Reg. No. 201715016G).