Policies: what the organisation decided once
The organisation-scope record register: the Art. 4 literacy programme, the Art. 17 policy pack, the retention policy, the programme steps that produce a policy, and the six policy documents you write and approve.
Policies (under Do the work) is the register of what the organisation has decided once, for every system — as opposed to the per-system obligations on the register next door. Each row is an organisation-scope record with its version, owner, approval, and next review.
What is on it
- The EU AI Act's organisation-scope records — the Art. 4 AI-literacy programme, the Art. 17 quality-management policy pack, the Art. 26(6) log-retention policy — with the review that keeps each one current (the AI-literacy review, the QMS review, the log-retention check).
- Programme steps that produce a policy — an ISO/IEC 42001 AI policy, an ISO/IEC 27001 information-security policy, a GDPR record: any step of organisation scope from a programme you run. The row opens the step's drawer, where the record is drafted, submitted and approved. See Steps: Aria drafts, a person approves, then it counts.
- The organisation-level documents the document register rolls up — the QMS manual, the Statement of Applicability, the record of processing activities, the supplier assessment, the GPAI copyright policy, the authorised-representative mandate.
Filter by status or search by title or article; sort by any column. A row's status is its record's status — not started, in progress, approved — and its next review is the date the schedule says.
The six policy documents
Six of the rows are policy documents you write in your own words, each with a clause outline: the AI governance policy, the roles, responsibilities and RACI record, the record-retention and documentation-control policy, the GPAI copyright compliance policy, the authorised representative mandate and the value-chain written agreement. They open on Documents as an editor with one rich-text field per clause and a count of clauses written.
Two rules carry weight there. The suggested content beside each clause is guidance, never prefilled text — a policy somebody approved without writing is worse than an empty one. And an approved policy is not edited in place: approving it issues it into the Issued archive exactly as it stands, and a change reopens it as a new version, with the approved one staying readable. Approval needs the approver permission.
Why a separate register
Per-system obligations answer "is this system in order?". Policies answer "does the organisation have a position?" — the thing an auditor reads first, and the thing that satisfies a clause in three frameworks at once when it is written well. A record here is filed once and credited everywhere it applies.