An AI acceptable use policy for Mauritian employers: template and worked example
Most Mauritian firms have already had the conversation about whether staff should use ChatGPT, Copilot or Gemini at work. The case for writing the answer down has been made elsewhere, including in the founder’s earlier piece on ChatGPT for businesses in Mauritius, which sets out safe use cases and a one-page approach to rules. This article does not repeat that argument. It provides the formal, adoptable version: a policy your HR function can issue, your staff can sign, and an auditor or a client can read.
The policy below is written for an organisation with no dedicated compliance department. It is deliberately short. A policy that runs to twenty pages will not be read; one that fits on four will be. Where a clause rests on the Data Protection Act 2017 it is labelled Legal requirement. Where it reflects good practice rather than law it is labelled Best practice or Consultaix recommendation. The distinction matters, because a policy that overstates the law loses credibility with the people it governs.
One point before anything else. This is a template, not legal advice. Before adoption it should be reviewed by HR and, where the organisation has one or can retain one, by employment counsel, because a policy that staff sign becomes part of the employment relationship and its disciplinary consequences must sit correctly within Mauritian employment law and your existing staff handbook.
The eight clauses the policy needs
A workable AI acceptable use policy has eight parts. Each is explained briefly here; the template that follows renders them as headed sections with bracketed fields to complete.
1. Purpose and scope
State what the policy is for and who it binds. Scope should cover employees, contractors and interns, and should apply to any generative AI tool used for work purposes, whether on company or personal devices. The common gap is the personal phone: a policy that only covers company laptops leaves the most likely route for a data leak unaddressed. Best practice.
2. Approved tools and how tools get approved
List the tools staff may use, the account type (a business or enterprise plan rather than a free consumer account, where the vendor’s terms on training and retention are usually different), and the person who can approve additions. The approval route should be simple enough that people use it rather than bypassing it. A tool register kept by one named person is enough for most SMEs. Consultaix recommendation.
3. Data classification in three tiers
This is the clause that does most of the work. Staff need a simple test they can apply in the moment, and three tiers are about the limit of what people will remember.
The first tier is personal data. The Data Protection Act 2017 defines personal data as any information relating to a data subject, and a data subject as an identified or identifiable individual, whether by name, identification number, location data, an online identifier or other factors specific to that person (section 2). The Act separately defines special categories of personal data, which include racial or ethnic origin, political opinion, religious or philosophical beliefs, trade union membership, physical or mental health, sexual orientation and other categories listed in section 2, and imposes stricter conditions on their processing (section 29). Under section 31, a controller or processor must implement appropriate security and organisational measures to prevent unauthorised access to or disclosure of personal data. Pasting a customer’s or employee’s details into a tool whose terms you have not reviewed is a security question under that section. Legal requirement (the duty to secure personal data); Consultaix recommendation (treating the tier as a hard stop for unapproved tools).
The second tier is confidential business data: anything under a non-disclosure agreement, unpublished financials, pricing, contracts, board papers, source code, and client deliverables. The Act does not govern this tier; your client contracts and NDAs do. Best practice.
The third tier is general business information: material that is public or would cause no harm if disclosed. This is where most productive AI use sits.
4. Permitted and prohibited uses
Say what people may do (drafting, summarising, structuring, translating, brainstorming, code assistance) and what they may not (entering tier one or tier two data into unapproved tools; using AI output as the final word on legal, financial, HR, medical or regulatory matters without qualified review; generating content that misrepresents the company; using AI to make or recommend decisions about individuals without the safeguards in clause 5). Best practice, with the last item touching a Legal requirement, explained below.
5. Human review of AI output
Every AI output used for work must be reviewed by the person responsible for it, and that person remains accountable for it. Where AI is used in any process that produces a decision significantly affecting an individual, such as recruitment screening, credit or performance assessment, the Act’s provisions on automated individual decision making apply (section 38), and the person must be informed of the existence of automated decision making, the logic involved and its consequences at collection (section 23(2)(g)). A systematic evaluation of individuals based on automated processing that produces legal or similarly significant effects is one of the operations for which a data protection impact assessment is required before processing (section 34). For most SMEs the safe answer is that AI does not make decisions about people; it may prepare material for a human who does. Legal requirement where decisions about individuals are involved; Best practice elsewhere.
6. Disclosure and transparency
Set out when the use of AI must be disclosed: to clients, where a deliverable was substantially AI-generated and the contract or professional standard expects human authorship; to colleagues, where a document will be relied on; and to the public, where content might be mistaken for a human statement. The Act’s transparency duties in section 23 apply where personal data is collected; the wider disclosure norms here are Best practice.
7. Incidents and escalation
Say what counts as an incident (personal data entered into an unapproved tool, a confidential document uploaded, an AI-generated error reaching a client), who to tell, and how fast. Section 25 of the Act requires a controller to notify the Data Protection Commissioner of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it, so the internal reporting line has to be quicker than that. Make it clear that early reporting is not a disciplinary matter in itself. Legal requirement for breach notification; Best practice for the internal route.
8. Ownership, review and training
Name the policy owner, the review cycle (annually, or on any material change in tools or law), and the training that accompanies it. A policy with no owner decays within a year. Section 31(6) of the Act requires controllers and processors to take reasonable steps to ensure their staff are aware of and comply with the relevant security measures, which is the legal anchor for the training clause. Legal requirement (staff awareness of security measures); Consultaix recommendation (the annual cycle and named owner).
The template
The text below is the policy itself. Bracketed fields are to be completed. Delete the clause labels before issuing to staff; they are there for the drafter.
[Company name] Acceptable Use Policy for Artificial Intelligence Tools
Version [1.0] | Effective date [date] | Owner [role] | Next review [date]
1. Purpose and scope
1.1 This policy sets out how [Company name] (“the Company”) permits the use of generative artificial intelligence tools (“AI tools”) in the course of work.
1.2 It applies to all employees, contractors, interns and any other person performing work for the Company (“staff”), on any device, whether provided by the Company or personally owned, where the use relates to Company business.
1.3 “AI tools” means any software that generates text, images, code, audio, video or recommendations from a prompt or from data supplied to it, including but not limited to [ChatGPT, Microsoft Copilot, Google Gemini, Claude], and any AI feature embedded in software the Company already uses.
1.4 This policy should be read with the Company’s [Information Security Policy], [Data Protection Policy], [Staff Handbook] and [Client Confidentiality obligations].
2. Approved tools
2.1 Staff may use only the AI tools listed in the Approved AI Tools Register maintained by [role], currently:
| Tool | Approved account type | Approved for data tiers | Notes |
|---|---|---|---|
| [Tool 1] | [Business / Enterprise plan] | [Tier 3 only / Tiers 2 and 3] | [e.g. training on inputs disabled] |
| [Tool 2] | [ ] | [ ] | [ ] |
2.2 Free consumer accounts are [not permitted for any work purpose / permitted for Tier 3 data only].
2.3 Staff who wish to use a tool not on the register must request approval from [role] by [email / form]. [Role] will assess the tool’s terms of service, data handling, retention and location of processing before approval, and will record the decision in the register within [10] working days.
2.4 Staff may not connect AI tools to Company systems, mailboxes, file stores or databases, or install browser extensions or plug-ins that do so, without written approval from [role].
3. Data classification
3.1 Before entering any information into an AI tool, staff must classify it under one of the following tiers.
Tier 1: Personal data. Any information relating to an identified or identifiable individual, including names, identification numbers, contact details, location data, online identifiers, images and voice, and any special categories of personal data as defined in the Data Protection Act 2017 (including health, ethnic origin, political opinion, religious belief, trade union membership and sexual orientation). Tier 1 data must not be entered into any AI tool unless [the tool is approved for Tier 1 in the register and the use has been recorded by [role]].
Tier 2: Confidential business data. Information the Company or its clients would not want disclosed, including material under non-disclosure agreements, client deliverables and files, unpublished financial information, pricing, contracts, board and management papers, personnel matters, source code and credentials. Tier 2 data may be entered only into tools approved for Tier 2 in the register.
Tier 3: General business information. Information that is public, or that would cause no harm to the Company, its clients or any individual if disclosed. Tier 3 data may be entered into any approved tool.
3.2 Where staff are unsure which tier applies, they must treat the information as the higher tier or ask [role].
3.3 Removing names does not by itself make data Tier 3. Information that could identify a person when combined with other information remains Tier 1.
4. Permitted and prohibited uses
4.1 Staff may use approved AI tools to draft, edit, summarise, structure, translate, brainstorm, research, and assist with code, spreadsheets and presentations, subject to the data rules in clause 3 and the review rules in clause 5.
4.2 Staff must not:
(a) enter Tier 1 or Tier 2 data into a tool not approved for that tier; (b) rely on AI output as the final word on legal, tax, financial, HR, medical, safety or regulatory matters without review by a qualified person; (c) use AI tools to make, or to recommend without human review, any decision that significantly affects an individual, including recruitment, promotion, discipline, credit or eligibility decisions; (d) present AI-generated content as the work of a named individual where the client, the regulator or a professional standard expects human authorship; (e) use AI tools to generate content that is defamatory, discriminatory, infringing of third-party rights, or that misrepresents the Company; (f) use AI tools to record, transcribe or analyse meetings or calls without the knowledge of the participants [and, where required, their consent]; (g) circumvent Company security controls or use AI tools on Company matters through accounts not linked to a Company identity.
5. Human review and accountability
5.1 The member of staff who uses an AI output remains responsible for its accuracy, appropriateness and compliance. Every AI output used for work must be reviewed by that person before use.
5.2 AI outputs must be fact-checked, particularly for figures, dates, citations, legal references and names. AI tools can produce plausible but incorrect statements.
5.3 Any AI output that relates to an individual, or that will inform a decision about an individual, must be reviewed and the decision taken by a named person. [The Company does not use AI tools to make automated decisions about individuals.] Where the Company proposes to introduce any such use, [role] must first assess whether a data protection impact assessment is required under the Data Protection Act 2017 and whether individuals must be informed.
5.4 AI-assisted work of a [client-facing / external / regulatory] nature must be reviewed by [a second person / the engagement lead] before release.
6. Disclosure and transparency
6.1 Staff must disclose the use of AI tools:
(a) to the engagement lead or line manager where a deliverable has been substantially generated by an AI tool; (b) to clients where the engagement letter, the client’s own policy, or applicable professional standards require it, or where the client has asked; (c) in any public-facing content where a reasonable reader could be misled into believing the content was created wholly by a person, [in the form: “Prepared with the assistance of AI tools and reviewed by [Company name]”].
6.2 Where the Company uses AI tools to interact with customers or the public (for example, a chatbot), the interface must state that the user is interacting with an automated system and provide a route to a person.
7. Incidents and escalation
7.1 An AI incident includes: Tier 1 or Tier 2 data entered into an unapproved tool; an AI-generated error reaching a client, regulator or the public; a suspected breach of this policy; or any AI output that raises a legal, safety or reputational concern.
7.2 Staff must report an AI incident to [role] [immediately / within 24 hours of becoming aware], by [channel].
7.3 [Role] will assess whether the incident involves a personal data breach and, where it does, will follow the Company’s [Data Protection Policy / breach procedure], including notification to the Data Protection Commissioner within the statutory period where required.
7.4 Prompt self-reporting of an incident will be taken into account in any subsequent review. Failure to report is itself a breach of this policy.
8. Ownership, review and training
8.1 This policy is owned by [role], who is responsible for maintaining the Approved AI Tools Register, handling approval requests, and coordinating incident response.
8.2 The policy will be reviewed [annually] and on any material change to approved tools, Company operations or applicable law.
8.3 All staff will complete [an induction briefing on this policy within [30] days of joining and an annual refresher]. Completion will be recorded by [HR].
8.4 Breaches of this policy may result in disciplinary action in accordance with the [Staff Handbook], up to and including [dismissal in cases of serious or repeated breach].
Acknowledgement
I confirm that I have read and understood the [Company name] Acceptable Use Policy for Artificial Intelligence Tools, version [1.0].
Name: [ ] | Signature: [ ] | Date: [ ]
Worked example: a 30-person professional-services firm
The following is illustrative. The firm, its staff and its choices are hypothetical, and are included only to show how three of the bracketed fields might be completed in practice.
The firm is an accounting and advisory practice in Ebène with 30 staff, four partners, no in-house IT function beyond a managed-service provider, and client files that routinely include payroll, personal identification and financial records. It had no AI policy; staff were using a mix of free ChatGPT accounts and the Copilot features that arrived with a Microsoft 365 upgrade.
Field completed: clause 2.1, the Approved AI Tools Register
The partners decided on two tools and set the register as follows.
| Tool | Approved account type | Approved for data tiers | Notes |
|---|---|---|---|
| Microsoft 365 Copilot | Firm’s business tenant only | Tiers 2 and 3 | Operates within the firm’s existing Microsoft 365 tenant; Tier 1 permitted only within the firm’s own documents already held in SharePoint, not pasted from external sources |
| ChatGPT | Team plan, firm-administered | Tier 3 only | Training on inputs disabled by administrator; free consumer accounts prohibited for work |
The reasoning was practical. Copilot processes client material that is already inside the firm’s Microsoft environment, so it was approved for confidential work subject to the existing security controls. ChatGPT was kept for general drafting and research on non-confidential material. Free accounts were prohibited outright because the firm could not administer them. Note that the tier permissions in this example reflect the firm’s own assessment of each vendor’s terms at the time; any firm adopting a register should review the current terms itself rather than copy this table.
Field completed: clause 3.1, Tier 1 examples
Because most staff handle personal data daily, the firm added practice-specific examples under Tier 1 so that classification became obvious rather than abstract:
“Tier 1 includes, without limitation: client payroll files; National Identity Card numbers and passport details; employee records of clients; Tax Account Numbers of individuals; bank account details of individuals; medical certificates; and any document naming a client’s staff. A client trial balance with no individual names is Tier 2. A published annual report is Tier 3.”
Field completed: clause 5.4, second-person review
The firm set the second-review threshold at any deliverable going to a client or to the Mauritius Revenue Authority: “AI-assisted work forming part of any client deliverable, tax filing or regulatory submission must be reviewed by the engagement manager before release, and the reviewer must confirm that all figures and legal references have been verified against source.” Internal memos and first drafts were exempt, which kept the rule proportionate.
The three fields took the partners roughly one meeting to settle. The remaining fields were mostly names and dates. The policy was then sent to HR and to the firm’s external employment lawyer for a short review of clause 8.4 against the staff handbook before issue.
How the policy maps to ISO/IEC 42001
ISO/IEC 42001:2023 is the international standard for an AI management system. It is voluntary, and certification is a choice rather than an obligation. Most Mauritian SMEs will not seek certification and do not need to. The value of the standard for a small organisation is that it describes, in general terms, what a coherent approach to AI looks like, and an acceptable use policy is one of the earliest pieces of that approach.
In general terms, the standard expects an organisation to have an AI policy set by leadership, defined roles and responsibilities, a way of identifying and assessing AI risks and impacts, controls over the AI systems it uses (including those supplied by third parties), competence and awareness among staff, a way of handling incidents, and a cycle of monitoring and improvement. The template above touches each of these: the purpose clause and ownership clause give the policy a sponsor and an owner; the approved-tools register is a lightweight form of inventory and supplier control; the data classification and human-review clauses are risk controls; the incidents clause provides the reporting route; and the training and annual-review clause supplies the competence and improvement elements.
This mapping is deliberately general. The standard’s detailed control set is in its annexes, and a policy alone does not constitute a management system. An organisation that later decides to pursue certification would build on the policy rather than replace it. For most firms the honest position is that the policy is the first substantive artefact on the road to ISO/IEC 42001, and a perfectly adequate stopping point for years.
Adopting the policy
Four steps are enough. Complete the bracketed fields, with the register and the Tier 1 examples given the most thought. Have HR check clause 8 against the staff handbook and, where possible, have employment counsel confirm the disciplinary wording. Brief staff in a single session rather than by email, and collect signed acknowledgements. Put the review date in someone’s calendar.
The policy will be imperfect on day one. That is acceptable. A short, adopted policy that staff have read is worth more than a comprehensive one that is still in draft.
Where Consultaix fits
Consultaix helps organisations turn a policy on paper into behaviour in practice through its AI Training and Change Management programme, which covers staff briefings, tool-specific guidance and the review rhythm that keeps a policy alive. Where an organisation wants the policy to sit within a broader framework informed by ISO/IEC 42001 and the Data Protection Act 2017, the AI Governance Advisory service provides that structure. Both can begin with the AI Readiness Assessment, which locates governance alongside strategy, data, capability and execution on the Consultaix AI Adoption Ladder.
Sources
- The Data Protection Act 2017 (Act No. 20 of 2017), Republic of Mauritius, 2017: https://www.fscmauritius.org/media/105843/the-data-protection-act-2017.pdf
- Automated Individual Decision Making, Data Protection Office, Mauritius: https://dataprotection.govmu.org/Pages/Data%20Subjects/Automated-Individual-decision-making.aspx
- Data Protection Impact Assessment and High Risk Operations, Data Protection Office, Mauritius: https://dataprotection.govmu.org/Pages/Home%20-%20Pages/Document%20%26%20Forms/Data-Protection-Impact-Assessment-and-High-Risk-Operations.aspx
- ISO/IEC 42001:2023, Information technology, Artificial intelligence, Management system, ISO, 2023: https://www.iso.org/standard/42001
- ChatGPT for Businesses in Mauritius: Safe Use Cases, Policies, and Practical Workflows, Faaleh M. Sookye, faaleh.com: https://faaleh.com/insights/chatgpt-for-businesses-mauritius
- The Minimum Viable AI Governance Framework for SMEs, Faaleh M. Sookye, faaleh.com: https://faaleh.com/insights/minimum-viable-ai-governance-framework-for-smes