Free template for lenders
AI Acceptable Use Policy Template for Lenders
A short, readable AI acceptable use policy you can copy, fill in, and put in front of your team this week. It states what is allowed, what needs approval, what is prohibited, and who decides. It is written for mortgage lenders, banks, and credit unions, and it works whether your AI came from a vendor or a browser tab.
How to Use This Template
Copy the template below into a document, replace everything in brackets, and have your leadership sign off. Then share it with every employee, not just the technology team, because AI use shows up in marketing, operations, and the loan office as much as in IT.
A policy is one part of a working governance framework. If you have not yet inventoried your AI or tiered your use cases by risk, start with the full framework guide and come back to this template with your tiers in hand.
Copy and customize
The Template.
Copy this text, then replace everything in [brackets].
[ORGANIZATION NAME]
Acceptable Use of Artificial Intelligence Policy
Purpose
This policy defines how employees, contractors, and vendors may use
artificial intelligence tools on behalf of [ORGANIZATION NAME]. It
applies to all AI tools, including AI features inside systems we
already own.
What Is Allowed
- Using approved AI tools for drafting, summarization, research,
and internal productivity
- Using AI to prepare first drafts that a person reviews before use
- Asking the AI Governance Lead questions about appropriate use
What Requires Approval
- Any customer-facing use of AI, including chat, email, and marketing
- Any new AI tool, vendor feature, or use case before first use
- Any use involving customer, borrower, or employee data
What Is Prohibited
- Entering confidential, customer, or borrower data into AI tools
that are not approved for that data
- Letting AI make or materially influence a credit, pricing, or
employment decision without documented human review
- Disabling, bypassing, or skipping required reviews
- Presenting AI output as verified fact without checking it
Data Rules
- Know the data classification before you use a tool
- Use only approved tools for confidential data
- Follow the data handling standards in [LINK TO STANDARDS]
Human Review
- A named human reviews AI output before it reaches a customer,
a regulator, or the public
- The reviewer is accountable for the final content, not the tool
Disclosure
- Follow the disclosure standards for customer-facing AI in
[LINK TO DISCLOSURE STANDARDS]
Who Decides
- The AI Governance Lead, [NAME], owns this policy and approves
use cases
- Moderate and high risk use cases require the AI review committee
- Report concerns or incidents to [CONTACT EMAIL]
Review
- This policy is reviewed at least annually and after any
significant AI, vendor, or regulatory change
Version [X.X] | Effective [DATE] | Owner [NAME, TITLE]Customization notes
Make It Yours.
Match It to Your Risk Tiers
The template's three lists (allowed, approval required, prohibited) map to low, moderate, and high risk use cases. If you have already tiered your AI inventory, align the language so staff see one consistent set of rules.
Name Real People
Replace every bracket with a name, not a department. A policy that says the AI Governance Lead decides works only when someone actually holds that title and answers for it.
Keep It Readable
This template fits on two pages on purpose. If staff cannot read it in ten minutes, they will not follow it. Attach your detailed standards and procedures as separate living documents.
Cover the AI You Already Own
Remember that AI features inside your LOS, CRM, and servicing platforms fall under this policy too. Your vendors' AI is your AI in the eyes of an examiner.
Next step
Want a Policy Built for Your Organization?
I help lenders turn this template into governance that holds up: an AI inventory, risk tiers, approval paths, vendor oversight, and board reporting, sized to your organization and your exam calendar. Bring your current state to a discovery call and we can talk through where to start.
