Draft your personal and team AI policies

You will write both policies, test them on real cases and prepare them for review.

This is where the course comes together. Over seven modules you've audited your tools, checked work uses against the PDPA, run a swap test, written a content use note, set up a safe word plan, fact-checked claims and mapped your tasks. This project turns that work into two documents: a personal AI policy you follow, and a one-page team AI policy you can hand to colleagues.

Allow about fifty minutes. You'll write both policies, test them against real situations, fix what doesn't work, and send the team version to someone for review.

The brief

Your personal policy is five to eight rules, each one sentence, drawn from your module work. It covers the decisions from lesson 8.1, What goes in a personal AI policy: your tools, accounts and settings; what never goes in; what you always check, including your safe word routine; and the skills you keep doing by hand.

Your team policy fits on one page and uses the four sections from lesson 8.2, What goes in a team AI policy: approved tools and how to request a new one; data rules; review and disclosure; and incidents. Each section has at least one example from your team's real work. If you don't manage a team, write it for the team you work in, as a draft you could offer your manager.

Steps

Start by gathering your materials: the audit table from lesson 1.4, your PDPA checklist from lesson 2.4, your swap test decision from lesson 3.4, your content use note from lesson 4.4, your safe word plan from lesson 5.4, and your task map from lesson 7.4. Most of your rules are already sitting in these.

Write the personal policy first. Start from the draft you wrote in lesson 8.1 and add anything missing. Read it aloud. If any rule takes more than one breath to say, shorten it.

Then write the team policy. Use the four headings. Under each, write two or three rules and one example. Keep it to a page. Put the owner's name and the next review date at the top, from lesson 8.3, Getting a policy used, not filed.

Now test both policies on three real situations. Choose ones that are likely to happen. A good set covers three different risks. One involves a file with personal data, such as a client spreadsheet. One is a deepfake or impersonation request, such as a voice note from your "manager" asking for an urgent transfer. One is something you'd publish, such as an AI-generated image for a social post.

For each situation, read through your policies and ask: does a rule clearly tell me what to do? Write down the answer the policy gives. If the answer is unclear, or two rules seem to conflict, or no rule applies, mark it.

Finally, fix every rule that gave an unclear answer. Rewrite it, add an example, or add a missing rule. Then rerun that situation to check the fix works.

A worked example of testing

Daniel tested the clinic's team policy against three situations.

Situation one: a physiotherapist wants to upload a patient's scan report to an AI tool to explain it in simpler language for the patient. The data rules section said treatment notes go only into the clinic's approved system for tasks the data protection officer has signed off. Clear answer: not without sign-off. No fix needed.

Situation two: a receptionist gets a WhatsApp voice note from what sounds like the clinic owner, asking her to pay a new supplier's invoice today to a different bank account. The incidents section covered deepfake requests, but only mentioned calls and video calls. Unclear whether a voice note counted. Fix: Daniel changed the rule to "any request by call, voice note, message or video", and added the example.

Situation three: the marketing assistant wants to post an AI-generated photo of a smiling patient doing exercises. The review and disclosure section said content needed checking, but said nothing about images that look like real patients. Fix: he added "Don't publish AI images that look like real patients or staff. Use real photos with consent, or illustrations."

Two of his three tests found a gap. That's a normal result, and exactly why you test.

What done looks like

You've finished when you have a personal policy of five to eight one-sentence rules, and a one-page team policy with four sections, an example in each, and an owner and review date at the top. Both have been tested against three real situations, with the result of each test written down and every unclear rule fixed. And the team version has gone to at least one reviewer, such as your manager, a colleague, or your data protection officer, with a short note asking what they'd still not know how to handle.

Keep both documents somewhere you'll see them. Your personal policy might live in your phone's notes, and the team policy wherever your team keeps its working documents, not its archive.

The first rule you write is usually the easiest. Open your audit table from lesson 1.4 and start there.

Write your personal policy and a one-page team policy, test both on three real situations, and send the team version to one reviewer.

Course

Junxiong-WFG Organisation is an authorised representative of AIA Financial Advisers Private Limited (Reg. No. 201715016G).