ChatGPT AI policy checklist for NZ businesses
Use this checklist before encouraging staff to use ChatGPT, ChatGPT Team, ChatGPT Enterprise, or similar AI assistants for business work.
1. Name approved tools and accounts
Decide which AI accounts may be used for work, who owns them, who pays for them, and whether staff may use personal accounts. If business data is involved, unmanaged personal accounts should usually be avoided.
2. Define prohibited information
List the information staff must not enter unless the business has explicitly approved the workflow: customer data, staff records, finance information, legal wording, passwords, contracts, health information, complaints, unpublished strategy, and confidential supplier or partner details.
3. Define approved use cases
Start with low-risk use cases: rewriting internal notes, creating agendas, drafting process outlines, summarising public information, preparing first-pass checklists, or explaining concepts. Keep customer-facing promises, pricing, legal wording, staff decisions, and public claims out of casual use.
4. Set human review gates
A person should review anything that goes to a customer, changes a record, affects pricing or scope, influences staff, creates public copy, or becomes a business decision. For a more detailed approval model, use the AI Approval Gates for Business Automation guide.
5. Require source checking
AI output can sound confident when source material is weak. Require staff to check facts, figures, names, dates, URLs, product details, policies, and claims against approved sources.
6. Keep a lightweight exception log
Record prompts or use cases that felt risky, produced wrong answers, exposed unclear permissions, or needed manager approval. Those exceptions show whether the business needs an AI risk register or a workflow assessment.