Most cooperatives and small utilities are already using AI tools, with or without a written policy. Without one, each employee decides what data is acceptable to enter, whether the output needs review, and whether anyone else needs to know. A short policy settles those questions in one place.
This article lays out a one-page structure, explains the reasoning behind each section, and notes what to confirm before adopting it. It is a starting framework. Have your counsel and your IT or security lead review it against your own obligations.
The Seven Sections
#
Section
What it settles
1
Scope
Which tools and uses are approved
2
Data that never goes in
Hard limits on what can be entered
3
Data that goes in only with approved tools
Conditional use
4
Review and sign-off
Who is accountable for output
5
Records
What is retained, and for how long
6
Prompt ownership
Who maintains recurring prompts
7
Reporting
What management and the board see
1. Scope
List the approved tools by name and the approved uses for each, such as drafting, data comparison, reconciliation support, and summarizing. State that anything not listed requires approval from a named person before use.
Naming the tools matters. A policy that says "approved AI tools" without identifying them leaves staff guessing, and they will tend to use whatever is already on their phone.
2. Data That Never Goes In
Set a short list of prohibited inputs and make it specific:
Member or customer personal information, including names tied to account or usage data
Social Security numbers and government identification
Bank account, payment card, and other financial account numbers
Information covered by a confidentiality agreement or nondisclosure clause
Login credentials and API keys
A list this short is easy to remember. If the work requires one of these items, the work is done outside the tool or the data is removed or anonymized first, with approval.
3. Data That Goes In Only With an Approved Tool
Some data is acceptable but not in every tool: unpublished financial statements, board materials, rate study work in progress, internal reconciliations. The policy should state that this category is entered only into tools approved for it.
What makes a tool approvable is something to settle with your IT or security lead and counsel. At a minimum, confirm in writing with each provider:
Whether inputs are retained, and for how long
Whether inputs are used to train models
Whether those answers apply to your specific plan
Those terms can differ between providers and between consumer and business plans, so an answer about one plan does not carry over to another. Check the plan you actually use.
Also ask your lender and your insurer whether they have expectations about AI use. If you borrow from RUS or from a private lender, or carry cyber coverage, a question may arise at renewal or in an examination. It is easier to answer with a policy already in place. For more on the data side, see Establishing an AI Security Policy.
4. Review and Sign-Off
State that every AI-assisted workpaper has a named preparer and a named reviewer, and that the reviewer's note records what was checked and what changed. "Reviewed" alone is not sufficient.
State also that AI output does not go into a filing, a rate application, or a board packet without human sign-off. The judgment on which explanation is true, materiality, and final approval stay with people, and the policy should say so directly.
5. Records
Refer to the support file described in What Auditors and Commission Staff Will Ask About AI-Assisted Work: the input as provided, the prompt with its version, the tool and model with the date, the original output, and the review note. Retain them under your existing records retention policy rather than creating a separate schedule.
If your records policy doesn't mention AI-assisted work, add a line there and reference it from this policy.
6. Prompt Ownership
Each recurring prompt has one owner, a version and date, a change log, and a known-answer test that is rerun at each quarter-end close and when the model version changes. For most utilities the working library is ten to fifteen prompts, so this is a manageable register. The mechanics are covered in Prompt Rot: Why AI Prompts Drift and How to Maintain a Prompt Library.
A prompt shared by several people and maintained by none eventually produces a result no one can explain.
7. Reporting
Provide the finance committee or board with a short annual summary: where AI is used, how many recurring prompts are in the register, and any errors caught in review and what was changed as a result. A half page is enough.
Reporting errors caught is useful. It shows that the review step is working, and it gives the board a basis for confidence that does not depend on assurances.
Adopting the Policy
Draft from the structure above and fill in your own tool list and prohibited data.
Have counsel and your IT or security lead review it.
Confirm provider terms in writing for the plans you use.
Name an owner for the policy itself and set an annual review date. Tools and terms change often enough that a policy not revisited in two years will be out of date.
Walk staff through it in one short session. A page people have read is worth more than a longer one they haven't.
What the Policy Doesn't Do
It doesn't replace professional judgment, and it doesn't make any output correct. It sets the limits on data, the expectation of review, and the records that show the review happened.
This article is general information and is not legal advice. Have your counsel review any policy before adopting it.
Written by
Russ Hissom, CPA
Principal, UtilityEducation.com · 35+ Years of Utility Accounting Experience
Russ Hissom, CPA is a principal of UtilityEducation.com, an online training platform offering certified continuing education courses in accounting, rates, construction accounting, financial analysis, management and artificial intelligence applications for utilities.
Learn more at UtilityEducation.com or contact Russ at [email protected].