Free private markets document template

AI Policy Template for LPs

Create a private markets AI policy covering permitted uses, confidential data, human review, vendors, model risk, records and incident response.

01

Purpose

This policy governs responsible artificial intelligence use by Pension Investment Office effective October 1, 2027.

02

Scope

Covered users are trustees, employees, consultants, contractors and service providers. Covered activities include manager research, document review, data extraction, monitoring, operations, reporting and communications.

03

Core principles

Use AI to augment accountable professionals. Apply confidentiality, accuracy, transparency, proportionality, security and human judgment to every material use.

04

Permitted uses

Permitted uses include summarization, draft generation, document classification, controlled extraction, coding support and internal search, subject to approved tools and appropriate review.

05

Prohibited uses

autonomous investment approval, unsupervised valuation, fabricated citations, uploading restricted data to unapproved tools and impersonation

06

Confidential data

Use only approved enterprise tools with contractual privacy, tenant isolation and no training on institutional data

07

Human oversight

A qualified employee verifies material facts, calculations, sources and recommendations before use

08

Vendor diligence

Security, privacy, model documentation, data location, subcontractors, resilience and exit rights

09

Model risk

Test accuracy, hallucination, bias, drift, explainability and reproducibility before production use

10

Security

SSO, role-based access, logging, retention limits, data-loss prevention and incident monitoring

11

Records & disclosure

Retain material prompts, outputs, sources, reviewer and final disposition for decision-relevant uses

12

Incident response

Stop affected use, preserve evidence, notify Security and Legal, assess impact and remediate

13

Governance

AI Governance Committee with Investments, Operations, Legal, Risk and Information Security

14

Training

Training is Required before access and refreshed annually. Users must understand approved tools, prohibited data, verification and incident reporting.