Kali Foundation / AI Policy & Governance
Book a Conversation

AI capability portfolio · Governance

A policy that gets used,
not just filed.

We build a board-endorsed AI use policy for your organisation, grounded in the Privacy Act 2020 and MBIE's Responsible AI Guidance — plus a lightweight governance structure so it stays a living document, not a PDF nobody opens again.

Board-Endorsed AI Policy ReviewCycle NamedOwner EscalationPath

The policy is the document. The structure underneath it is what keeps it real.

The problem

Most organisations have no AI policy — or one nobody actually adopted.

Staff are already using AI tools day to day. Without a policy grounded in privacy law and endorsed by the board, that use happens without any shared understanding of what's appropriate, what's risky, or who's accountable if something goes wrong.

No formal endorsement

A policy someone drafted once but the board never actually signed off carries no real authority when it's tested.

Privacy risk sits unaddressed

Without a clear read on the Privacy Act 2020, it's easy to put client or beneficiary information somewhere it shouldn't go.

Nobody owns it after it's written

A policy with no review cycle and no named owner quietly goes out of date the moment it's filed.

What's included

A policy, and the structure that keeps it alive.

PART ONE — THE POLICY

1

A board-endorsed AI use policy

Written for your organisation specifically, grounded in the Privacy Act 2020 and MBIE's Responsible AI Guidance, and taken through your board for formal sign-off.

2

A plain-English staff summary

A short version staff can actually read and follow, alongside the full policy document.

PART TWO — THE GOVERNANCE STRUCTURE

3

A review cycle

A fixed point each year (or more often) where the policy is checked against how AI is actually being used.

4

Ownership and escalation

A named person responsible for the policy, and a clear path for raising a concern before it becomes a problem.

How it works

From current state to endorsed policy

01

Current-state review

A short look at how AI is already being used across your organisation, and where the gaps and risks actually sit.

02

Draft the policy

A policy written for your organisation's actual size, risk profile and way of working — not a generic template.

03

Board consultation & endorsement

We take the draft through your board, answer questions directly, and get it formally signed off.

04

Set up the structure & embed

Review cycle, ownership and escalation path are set up alongside the policy — and briefed to staff.

Who it's for

Any organisation without a real policy yet

Charity Trustees

Boards who know they need a policy but haven't had the time or the template to get one endorsed.

Community Trusts

Organisations handling sensitive beneficiary information who need privacy risk addressed properly.

Schools & Kura

Boards of Trustees needing a policy that covers staff, students and third-party data appropriately.

Social Enterprises

Growing organisations that need governance to catch up with how staff are already working.

Let's talk

Get your AI policy endorsed

We'll talk through your current state and what a right-sized policy looks like for your board.