Project controls & finance

AI Governance for Projects: A One-Page Policy Template

AI governance for projects made practical: a one-page policy template covering approved uses, data, sign-off and logging, plus a failure-mode register.

8 min read
Dark blue cover with a policy document and the words AI governance for projects

Most project teams are already using AI, whether or not anyone has told them they may. A scheduler pastes a task list into a chatbot to tidy the wording; a project manager asks a tool to summarise a long email chain; an analyst lets an assistant draft the monthly commentary. None of this is unreasonable, but without a policy nobody can say which data was shared, who checked the output or what the report would have said without the tool.

AI governance for projects does not need a committee or a fifty-page standard. It needs a one-page policy that people actually read, a short list of the ways AI fails and a log that makes work reviewable. This guide provides a template you can adapt, builds on the GUARD framework from AI in project controls, and includes a failure-mode risk register.

Why AI governance for projects fits on one page

Long policies are not read, and unread policies are not followed. A one-page policy forces choices, and those choices are the substance of governance. It should answer six questions:

  1. Which tools may be used, and for what data?
  2. Which tasks may AI do, assist or never do?
  3. What must be checked before an output is used?
  4. Who signs off?
  5. What gets recorded?
  6. What happens when something goes wrong?

Everything else, such as legal detail or technical standards, can sit in an appendix owned by your information security, legal or data protection specialists. This template is a starting point for a conversation with them, not a substitute for their advice. Nothing in this article is legal or compliance advice, and the thresholds, timescales and data classes shown are examples to adapt, not recommendations for any particular organisation or jurisdiction.

A reminder of GUARD

The GUARD framework in our earlier post has five parts: Grant permission deliberately, Use documented inputs, Assess outputs against a baseline, Review by a named person and Disclose in the report. The template below turns each into policy wording.

The one-page policy template

Adapt the wording, thresholds and tool names to your organisation. Items in capitals are fields to complete, and every timescale and classification below is an example value.

1. Purpose and scope

This policy applies to all use of AI tools in the PROJECT NAME team, including chat assistants, copilots and any feature embedded in project software. It exists so that AI speeds up our work without weakening accuracy, confidentiality or accountability.

2. Approved tools (Grant)

  • Only tools on the approved register may be used for project work. The register lists each tool, its owner, the data classes it may process and the date of last review.
  • Personal accounts and unapproved tools must not be used for project information.
  • To request a tool, contact NAMED ROLE.

3. Data rules (Use)

Data classExamplesMay be entered into approved AI tools?
PublicPublished standards, public tender noticesYes
InternalMeeting agendas, generic templates, anonymised schedulesYes, in approved tools only
ConfidentialCost rates, contract terms, supplier pricing, unreleased forecastsOnly in tools approved for this class
RestrictedPersonal data, security information, legally privileged materialNo

When unsure, treat the data as one class higher and ask.

4. Approved uses (Use and Assess)

LevelMeaningExamples
AI may draftA person must review and edit before useMeeting notes, first-draft status commentary, risk wording, agendas
AI may assistA person does the work and uses AI as a second pair of eyesChecking a schedule narrative for gaps, suggesting questions for an estimator
AI must not decideDecisions and sign-offs stay with named peopleBaseline changes, forecast approval, contract positions, safety decisions

5. Human sign-off (Review)

  • Every AI-assisted output that informs a decision has a named reviewer.
  • The reviewer checks numbers against source systems, not against the AI's own explanation.
  • Reviewers confirm that no confidential data left approved tools.
  • The reviewer is accountable for the output, whatever tool helped produce it.

6. Logging and disclosure (Disclose)

  • Keep a simple AI use log: date, tool, purpose, data class, reviewer and outcome.
  • Reports that include AI-assisted content say so in a line, for example "Commentary drafted with AI assistance and reviewed by NAME."
  • Forecast and risk outputs state the method and compare against a simple conventional baseline.

7. Incidents and review

  • Report suspected data exposure or material errors to NAMED ROLE within one working day (example timescale).
  • The policy is reviewed every six months (example interval) and whenever tools or regulations change.

That is the page. The following sections explain how to make it work.

A worked example: one log entry

This example uses fictional details. A project controls analyst uses an approved assistant to draft the monthly commentary from an anonymised extract of the cost report.

FieldEntry
DateMonth-end
ToolApproved assistant, internal data class
PurposeDraft commentary on cost variance for the sponsor pack
InputAnonymised variance table, no supplier names or rates
Check against baselineCompared draft statements with the CPI-based forecast: draft claimed variance was "minor"; the source shows CPI of 0.88
OutcomeDraft edited; sentence about "minor variance" removed; range added
ReviewerControls lead

The entry took two minutes to write. It shows that the tool saved drafting time, that the baseline comparison caught a misleading phrase and that a named person reviewed the result. If a board asks later how a statement reached the pack, the log answers it.

AI failure modes and a risk register

Governance is easier when you name how AI fails. The register below lists common failure modes in project settings, with a control for each. Scores are illustrative; rate likelihood and impact for your own context.

Failure modeWhat it looks like in a projectIllustrative ratingControl
FabricationA plausible but invented fact, such as a clause, a standard or a precedentHighVerify every factual claim against source; require citations to documents provided
Arithmetic and logic slipsA wrong total or a mis-stated indexHighRecalculate in the controlled model; never accept a calculation unseen
Data leakageConfidential rates or contract terms pasted into an unapproved toolMediumApproved register; data classes; training; tool restrictions
Stale or incomplete inputsA summary based on last month's data or a partial extractMediumRecord the data date and source; compare with the system of record
Overconfidence and false precisionAn output states a single date or cost with no rangeMediumRequire ranges and stated assumptions
Bias toward the promptThe answer mirrors the leading questionMediumAsk neutral questions; ask for counter-arguments
Automation complacencyReviewers stop checking after several good resultsMediumSpot checks; rotate reviewers; keep the log
Unclear accountabilityNobody owns an AI-assisted forecastMediumNamed reviewer on every output
Inconsistent use across the teamDifferent practices and unequal qualityLow to mediumOne-page policy; short training; shared prompt library

Review the register when something goes wrong, and add new failure modes as you discover them.

Making the policy stick

  • Keep it to one page. If it grows, move detail to an appendix.
  • Train people with real examples, including the errors your own team has caught.
  • Make the safe path the easy path. Provide approved tools and ready-made prompts so people are not tempted to improvise.
  • Review the log regularly. Look for patterns: which tasks, which errors and which reviewers.
  • Treat reported errors as learning. If people fear blame, they will stop reporting.

Prompting standards belong in governance

Good governance includes good practice in how people ask. Standard prompts that restrict the model to provided evidence, request uncertainty to be stated and require output in a fixed format cut many failure modes at source. Optimize All's free courses Prompt Engineering Foundations and Advanced Prompt Engineering cover this in depth. For ten practical prompts with built-in checks, see AI prompts for project managers.

How this connects to forecasts and dashboards

Two areas deserve particular care. Forecasts are decision inputs, so the policy requires a conventional baseline comparison and a named reviewer; the principles in schedule risk analysis on ranges and stated assumptions apply to any AI-assisted forecast. Dashboards are read quickly and trusted widely, so every number on them should be traceable; see our one-page KPI dashboard guide.

Tools that help / Learn it properly

PCI AI (opens in a new tab) describes its PCL-AI, PFL-AI and PML-AI exams as fully online and scenario-based, with AI governed throughout; its site holds the official detail. The policy template in this article is our own and is not drawn from PCI AI's materials. Our PCI AI partner page summarises the three credentials, and the PML-AI certification guide and PCL-AI certification guide show where governance fits. For practice in applying these ideas, Optimize All's free course Project Controls with AI is a natural companion.

Frequently asked questions

Do small teams need an AI policy?

Yes, although it can be very short. The risks of data leakage and unchecked outputs do not depend on team size, and a one-page policy takes little time to follow.

Who should own the policy?

A named senior person such as the head of the PMO or controls lead, working with information security, legal and data protection specialists. Ownership matters more than the title.

Does the policy need to name specific tools?

It should refer to an approved register that names tools, since tools change quickly. The policy text can stay stable while the register is updated.

No. It is a practical starting point and not legal or compliance advice. Have your legal, security and data protection advisers review the final policy against your obligations, which differ by jurisdiction, sector and contract.


Optimize All is the official marketing partner of PCI AI and Certuvo.

All articles

Blog

Related articles

  • Dark blue cover with a chat prompt and the words AI prompts for project managers

    Project controls & finance

    AI Prompts for Project Managers: Ten You Can Verify

    Ten practical AI prompts for project managers, each with a built-in way to verify the output, plus prompt anatomy and what never to paste into a tool.

    Optimize All Editorial7 min read

  • Dark blue cover with dashboard tiles and the words Project controls KPIs on one page

    Project controls & finance

    Project Controls KPIs: Building a One-Page Dashboard

    Choose the project controls KPIs that matter: leading versus lagging measures, CPI and SPI, forecast accuracy, change-order rate and float on one page.

    Optimize All Editorial8 min read

  • Dark blue cover with a probability curve and the words Schedule risk analysis P50 and P80

    Project controls & finance

    Schedule Risk Analysis: Reading P50 and P80 Dates

    Schedule risk analysis explained in plain terms: three-point estimates, what P50 and P80 dates mean, how a simulation works and how to act on the result.

    Optimize All Editorial8 min read

  • Navy cover reading PML-AI Certification with the subtitle The AI-era Project Management Leader credential

    Project controls & finance

    PML-AI Certification: The AI-Era Project Leader Guide

    The PML-AI certification explained: governance, planning, execution, agile and hybrid delivery, AI-enabled project management, exam facts and who it suits.

    Optimize All Editorial8 min read

  • Dark blue cover with horizontal schedule bars and the words Project controls and finance

    Project controls & finance

    AI in Project Controls: Governed Forecasting and Risk

    How to use AI in project controls responsibly: use cases, a governance framework, a worked forecast and the checks before AI output reaches a board.

    Optimize All Editorial6 min read

Ready to grow?

Get a free, no-obligation marketing audit from a senior strategist — or book a 30-minute call.