Don't Start Your AI Policy With 40 Pages Nobody Will Read

Skip that. Start with a spreadsheet.
Make these 5 columns:
Tool name. Whatever staff are actually using. ChatGPT, Canva’s AI features, Pet Whisperer AI.
Department. Who’s using it. Marketing, membership, HR, doesn’t matter. If it touches your branch or the org chart, it goes on the list.
Data touched. This is the column that matters most. Member names? Financial info? Nothing at all, just brainstorming copy? Be specific here. “Some data” is not an acceptable answer.
Who approved it. Even if the answer is “no one yet,” write that down. It tells you where the gaps are.
Review date. Decide on a frequency. Set a date to check back as tools change and approvals expire.
That’s it. Just 5 columns on a shared spreadsheet, completed in a single afternoon.
Keep in mind, a registry only tracks what gets entered. It won’t catch a tool that someone starts using, doesn’t report and is never questioned on. That’s a different problem, and it needs a different solution like a manager asking directly or a periodic check of what’s actually installed. Something that doesn’t rely on people volunteering information.
But the registry, unlike a policy document, gives you one place to look when you need an answer fast. And it reveals the gaps once someone finally does ask.
Next post: what to do once you know what’s on the list. Some tools carry more risk than others and treating them all the same is a mistake.