AI Governance & Responsible Use

Artificial Intelligence Policy

How VisionOne uses artificial intelligence safely, lawfully, and ethically — with human judgment, privacy, and our customers, employees, and insurance partners protected at every step.

Version 1.0 · Effective June 25, 2026
~15 min read
30 sections
Human-Reviewed
Every AI Output
NIST & ISO 42001
Aligned Frameworks
Never
Customer Data in Public AI
This Artificial Intelligence Policy applies to all VisionOne employees, contractors, temporary workers, vendors, and anyone using AI tools for VisionOne business. It is owned by Executive Leadership and the Compliance Officer. VisionOne uses AI to improve productivity, service quality, and operations — but only when use is lawful, secure, accurate, reviewed by a human, and consistent with our privacy, cybersecurity, employment, customer-service, insurance, and contractual obligations. This policy aligns with the NIST AI Risk Management Framework, NIST’s Generative AI Profile, ISO/IEC 42001, and the NAIC Model Bulletin on the Use of AI by insurers.

Human Oversight

A qualified person reviews and owns every AI-assisted decision. AI supports judgment — it never replaces it.

Privacy & Confidentiality

We never put customer, employee, claims, or carrier data into unapproved or public AI tools.

Accuracy & Verification

AI output is checked against primary sources before anyone relies on it.

Fairness & Non-Discrimination

We test high-risk AI for bias and prohibit unfair or discriminatory outcomes.

Security

Approved tools, company accounts, and IT/security review before AI touches our systems.

Transparency

We disclose AI use where the law, regulators, carriers, or customers expect it.

1
Purpose

VisionOne uses artificial intelligence to improve productivity, service quality, communication, research, documentation, training, and business operations. AI must be used safely, legally, ethically, and in a way that protects customers, employees, confidential information, insurance partners, and the company.

This policy sets the rules for using AI at VisionOne. It is based on current AI risk-management guidance, including the NIST AI Risk Management Framework and NIST’s Generative AI Profile, which identify risks such as inaccurate outputs, privacy exposure, cybersecurity threats, bias, and misuse of AI-generated content.

VisionOne will also align its AI governance program with recognized management-system practices such as ISO/IEC 42001, which provides requirements and guidance for establishing, implementing, maintaining, and improving an AI management system.

2
Core Policy Statement

VisionOne allows the use of approved AI tools only when the use is lawful, secure, accurate, reviewed by a human, and consistent with insurance, privacy, cybersecurity, employment, customer-service, and contractual obligations.

AI may assist work. AI may not replace human judgment in decisions involving customers, employees, insurance eligibility, claims, pricing, underwriting, hiring, discipline, legal obligations, financial commitments, or any other high-impact decision.
3
Definitions

Artificial Intelligence / AI

Software or systems that generate, analyze, classify, predict, recommend, summarize, automate, or support decisions using machine learning, generative AI, large language models, automated decision tools, or similar technology.

Generative AI

AI that creates text, images, audio, video, code, summaries, recommendations, or other content.

Approved AI Tool

An AI system reviewed and approved by VisionOne leadership, compliance, IT/security, or another authorized owner.

Confidential Information

Any nonpublic company, customer, employee, carrier, financial, legal, operational, technical, or business information.

Personal Information

Any information that identifies or can reasonably identify a person, including name, address, phone number, email, date of birth, Social Security number, driver’s license number, financial information, health information, insurance information, account information, claims information, or similar data.

High-Risk AI Use

Any AI use that affects legal rights, insurance eligibility, underwriting, claims, pricing, employment, customer access to services, financial outcomes, compliance obligations, safety, or sensitive personal information.

4
Approved & Prohibited AI Use

Approved Uses

Employees may use approved AI tools for:

  • Drafting internal documents, outlines, checklists, templates, and training materials
  • Summarizing non-confidential information
  • Improving grammar, tone, clarity, or formatting
  • Creating internal brainstorming materials
  • Supporting research, provided sources are verified
  • Drafting customer communications, provided a qualified employee reviews and approves before use
  • Creating internal procedures, workflows, FAQs, and productivity tools
  • Assisting with code, formulas, spreadsheets, or data analysis, provided output is tested and verified
  • Translating or simplifying language, provided the result is reviewed for accuracy

Prohibited Uses

Employees may not use AI to:

  • Enter customer or employee personal information, insurance policy data, claims data, financial data, health data, passwords, API keys, carrier login credentials, or confidential company information into unapproved AI tools
  • Make final decisions about insurance eligibility, pricing, underwriting, coverage, claims, employment, discipline, termination, compensation, promotions, or customer access to services
  • Give legal, tax, medical, financial, or insurance coverage advice without human expert review
  • Represent AI-generated content as verified fact without checking it
  • Create fake documents, signatures, customer records, reviews, evidence, images, audio, or misleading communications
  • Bypass security controls, access restrictions, privacy rules, carrier rules, or company approval processes
  • Upload contracts, carrier manuals, customer documents, claim documents, employee records, or proprietary files into public AI tools unless specifically approved
  • Discriminate, profile, manipulate, harass, surveil, or unfairly target customers, employees, applicants, or vendors
  • Use AI-generated content that infringes copyrights, trademarks, licenses, or third-party rights
  • Use AI for any purpose that violates law, regulation, carrier agreement, customer agreement, employment policy, privacy policy, cybersecurity policy, or this policy
5
Human Review Requirement

AI output must be reviewed by a qualified human before it is used for business purposes.

Employees are responsible for the final content they use, send, publish, rely on, or approve. “AI made the mistake” is not an acceptable excuse.

Human review must check for:

  • Accuracy
  • Completeness
  • Bias or unfairness
  • Privacy issues
  • Confidentiality issues
  • Legal or insurance compliance issues
  • Tone and professionalism
  • Misleading claims
  • Source reliability
  • Customer impact
6
Insurance Compliance Rules

VisionOne must treat AI use in insurance-related work as high-risk unless leadership and compliance determine otherwise.

The NAIC Model Bulletin on AI states that decisions or actions impacting consumers and made or supported by AI systems must comply with applicable insurance laws and regulations, including unfair trade practice and unfair discrimination requirements. VisionOne employees may not use AI to make or support insurance-related decisions unless the use has been reviewed and approved.

AI May Not Make Final Insurance Decisions

AI may not make final decisions about:

  • Policy eligibility
  • Underwriting
  • Rating or pricing
  • Coverage recommendations
  • Claims handling
  • Claim approval or denial
  • Policy cancellation or nonrenewal
  • Customer risk scoring
  • Carrier placement
  • Customer prioritization where unfair discrimination could occur

Carrier and Contract Rules

Before using AI in work connected to any carrier, MGA, broker, agency, insurer, or insurance program, VisionOne must review carrier contract terms, data-sharing restrictions, confidentiality provisions, cybersecurity requirements, claims-handling requirements, advertising and marketing rules, recordkeeping obligations, state-specific insurance regulations, privacy and consumer-protection obligations, and errors and omissions insurance requirements.

If a carrier, regulator, or insurance partner prohibits or limits AI use, VisionOne must follow the stricter rule.

Documentation for Insurance Uses

For any approved AI system used in insurance-related workflows, VisionOne must keep records showing the AI tool used, business purpose, data used or entered, human reviewer, output generated, final decision made by a human, known limitations, bias or discrimination review, vendor documentation, and approval date and approving person.

No Unfair Discrimination

AI may not be used in a way that unfairly discriminates based on protected characteristics or proxies for protected characteristics. This includes improper use of data related to race, color, religion, national origin, sex, age, disability, marital status, genetic information, health status, ZIP code, income level, or other protected or sensitive factors where prohibited or inappropriate.

7
Privacy & Confidentiality

Employees must not enter confidential, personal, customer, employee, carrier, claims, financial, legal, or proprietary information into any AI system unless:

  • The tool is approved by VisionOne
  • The data use is legally permitted
  • The data use is allowed by contract
  • The tool has appropriate security controls
  • The information is necessary for the approved business purpose
  • The information is minimized where possible
  • The use is documented if high-risk
Public AI tools must be treated as external systems. Assume that anything entered into an unapproved AI tool may be stored, reviewed, reused, or exposed.
8
Cybersecurity Requirements

AI tools create cybersecurity risks, including data leakage, phishing, prompt injection, malicious code, fake content, and unauthorized automation. NIST’s Generative AI Profile identifies generative-AI-specific risks and recommended risk-management actions for organizations using these systems.

VisionOne requires:

  • Only approved AI tools may be used for company work
  • AI tools must use company-approved accounts, not personal accounts, when used for business
  • Employees may not upload passwords, credentials, API keys, customer files, contracts, claim files, or confidential records into AI tools unless explicitly approved
  • AI-generated code must be reviewed and tested before use
  • AI-generated links, attachments, scripts, macros, formulas, or commands must be treated as potentially unsafe
  • AI tools must not be connected to company systems, email, documents, CRM, customer databases, or carrier systems without IT/security approval
  • Any suspected AI-related data leak, security issue, or misuse must be reported immediately
9
Accuracy & Verification

AI tools can produce incorrect, outdated, fabricated, biased, or misleading information. Employees must verify AI outputs before use.

Verification is required for:

  • Customer-facing statements
  • Insurance-related information
  • Legal or compliance information
  • Financial information
  • Policy or coverage information
  • Claims information
  • Medical, safety, or health-related information
  • Vendor or contract information
  • Regulatory information
  • Any information used to make a business decision

Employees must check primary sources where possible, such as carrier manuals, signed contracts, state insurance department guidance, official regulations, internal procedures, or approved legal/compliance materials.

10
Customer Communications

AI may help draft customer communications, but a VisionOne employee must review and approve the message before it is sent.

Customer communications must not:

  • Misrepresent AI-generated content as independently verified
  • Promise coverage, claim outcomes, savings, approval, pricing, eligibility, or benefits unless confirmed through approved processes
  • Provide legal or insurance coverage advice beyond the employee’s authority
  • Include confidential information improperly
  • Sound threatening, deceptive, discriminatory, or misleading
  • Use fake personalization or pretend a human performed work that was not performed

When appropriate, VisionOne may disclose that AI-assisted tools were used, especially if AI materially shaped the communication or decision-support process.

11
Employee Use & Workplace Rules

Employees may use AI to improve productivity, but they remain responsible for their work.

Employees must not:

  • Use AI to secretly record, monitor, evaluate, or profile coworkers
  • Use AI to make employment decisions without HR/legal approval
  • Upload employee records into unapproved AI tools
  • Use AI to create offensive, discriminatory, harassing, or inappropriate content
  • Use AI to impersonate another employee, customer, executive, carrier representative, or vendor
  • Use AI to avoid doing required professional review
12
Vendor & Third-Party AI Tools

Before VisionOne uses a third-party AI vendor for business purposes, leadership, IT/security, and compliance must review the vendor.

Vendor review should include:

  • Data privacy terms
  • Whether customer/company data is used for model training
  • Data retention and deletion rules
  • Security certifications or controls
  • Access controls
  • Audit logs
  • Breach notification terms
  • Contractual indemnity and liability
  • Insurance coverage
  • Regulatory compliance
  • Subprocessor use
  • Location of data storage
  • Ability to export or delete data
  • Human oversight features
  • Bias, testing, and risk documentation
No employee may independently purchase, install, integrate, or subscribe to an AI tool for company use without approval.
13
AI Governance Program

VisionOne will maintain an internal AI governance program. This program follows the basic structure of recognized AI risk-management systems, including NIST AI RMF and ISO/IEC 42001-style management controls.

The program must include:

  • AI inventory
  • Approved tool list
  • Prohibited tool list
  • Risk classification
  • Vendor review
  • Human review rules
  • Data protection rules
  • Insurance compliance review
  • Training
  • Incident reporting
  • Periodic audits
  • Policy updates
14
AI Risk Levels

Low-Risk Uses

Examples: grammar editing, formatting internal documents, brainstorming ideas, creating generic outlines, summarizing public information.

Low-risk uses still require employee review.

Medium-Risk Uses

Examples: drafting customer emails, drafting marketing materials, summarizing internal non-sensitive documents, creating training materials, supporting operational decisions.

Medium-risk uses require human review and may require manager approval.

High-Risk Uses

Examples: insurance underwriting support, claims support, coverage interpretation, customer risk scoring, pricing or eligibility support, employment decisions, legal/compliance analysis, use of personal or sensitive data, automated customer communications, AI connected to company systems.

High-risk uses require written approval from leadership, compliance, and IT/security before use.
15
Data Rules

Employees must follow these data rules:

Data TypeApproved AI?Rule
Public informationYesVerify accuracy
Internal non-confidential informationUsuallyUse approved tools only
Confidential company informationOnly with approvalMust have business need and security controls
Customer personal informationOnly with approvalMust comply with privacy, insurance, and contract rules
Claims informationOnly with approvalTreat as high-risk
Policyholder informationOnly with approvalTreat as high-risk
Employee recordsOnly with approvalHR/legal review required
Passwords, API keys, credentialsNoNever enter into AI tools
Carrier manuals / contractsOnly with approvalCheck confidentiality and carrier terms first
Legal documentsOnly with approvalLegal review required
16
Intellectual Property & Ownership

Employees must not use AI in a way that violates copyrights, trademarks, trade secrets, licensing terms, or third-party rights.

Employees must not:

  • Ask AI to copy protected material unlawfully
  • Upload copyrighted materials into AI tools unless permitted
  • Use AI-generated logos, slogans, images, or marketing content without review
  • Assume AI-generated content is original or legally safe
  • Use AI-generated content from unapproved tools in official materials without review

Marketing, branding, customer-facing, legal, and insurance-related materials must be reviewed before publication.

17
Bias, Fairness & Non-Discrimination

AI must not be used to unfairly discriminate or produce unfair outcomes.

VisionOne must review high-risk AI systems for:

  • Biased input data
  • Biased outputs
  • Discriminatory patterns
  • Proxy variables that may create unfair outcomes
  • Unequal impact on protected groups
  • Lack of explainability
  • Overreliance by employees
  • Inaccurate recommendations

AI systems used in insurance-related work must be especially scrutinized because regulators expect AI-supported, consumer-impacting decisions to comply with insurance laws and consumer-protection rules.

18
Transparency & Disclosure

VisionOne will be transparent about AI use when required by law, contract, carrier rule, regulator request, or customer expectation.

Disclosure may be required when:

  • AI materially assists a customer-impacting decision
  • AI is used in claims, underwriting, pricing, or eligibility support
  • A customer is interacting with an AI chatbot or automated system
  • AI-generated content is used in official communications
  • A regulator, carrier, auditor, or insurance partner requests documentation

Employees must not hide AI use from management, compliance, auditors, regulators, customers, carriers, or insurance partners when disclosure is required.

19
Records & Audit Trail

VisionOne must maintain records for approved AI tools and high-risk AI uses. Records should include:

  • Tool name
  • Vendor
  • Owner
  • Business purpose
  • Risk level
  • Data types used
  • Approval date
  • Approved users or departments
  • Security review
  • Compliance review
  • Vendor contract review
  • Human oversight controls
  • Testing or validation results
  • Known limitations
  • Incident history
  • Renewal or review date
20
Training

All employees must receive AI training before using AI for business purposes. Training must cover:

  • Approved and prohibited uses
  • Privacy and confidentiality
  • Insurance compliance
  • Human review
  • Bias and discrimination
  • Cybersecurity risks
  • AI hallucinations and false outputs
  • Customer communication rules
  • Incident reporting
  • Examples of acceptable and unacceptable AI use

Employees in insurance, claims, customer service, HR, finance, compliance, IT, and management roles may require additional training.

21
Incident Reporting

Employees must immediately report:

  • Confidential data entered into an unapproved AI tool
  • Customer or employee information exposed through AI
  • AI-generated false information sent to a customer, carrier, vendor, regulator, or employee
  • Suspected discriminatory AI output
  • Unauthorized AI tool use
  • AI-connected system malfunction
  • Suspicious AI-generated emails, links, files, code, or instructions
  • Any AI use that may violate this policy, law, regulation, contract, or insurance requirement
Reports should go to VisionOne compliance, IT/security, and — for workplace-related matters — HR, at info@visiononeperformance.com. No employee will be retaliated against for reporting a good-faith AI concern.
22
Enforcement

Violations of this policy may result in:

  • Removal of AI access
  • Retraining
  • Written warning
  • Disciplinary action
  • Termination
  • Contract termination for vendors or contractors
  • Legal action where appropriate
  • Notification to affected customers, carriers, regulators, or insurers where required
23
Responsibilities

Executive Leadership

  • Approve AI strategy
  • Assign policy ownership
  • Ensure resources for governance, compliance, and training
  • Review high-risk AI uses

Compliance Officer / Policy Owner

  • Maintain this policy
  • Review AI use cases
  • Track legal, regulatory, carrier, and insurance requirements
  • Maintain AI risk records
  • Coordinate audits

IT / Security

  • Approve AI tools from a security standpoint
  • Manage access controls
  • Review integrations
  • Monitor data protection risks
  • Respond to AI-related security incidents

Managers

  • Ensure employees follow this policy
  • Approve appropriate use cases
  • Escalate high-risk AI uses
  • Confirm human review is happening

Employees

  • Use only approved AI tools
  • Protect confidential and personal information
  • Review AI output before use
  • Report concerns immediately
  • Never use AI to bypass judgment, compliance, or accountability

Vendors & Contractors

  • Follow this policy when working for VisionOne
  • Use only approved AI tools and workflows
  • Protect VisionOne data
  • Disclose AI use when required
  • Cooperate with audits and investigations
24
Approval Process for New AI Tools

Before using a new AI tool, the requesting employee or department must submit:

  • Tool name
  • Vendor name
  • Business purpose
  • Users or departments
  • Data types involved
  • Whether customer, employee, carrier, claims, or policy data will be used
  • Whether the tool affects customer, insurance, employment, financial, or legal decisions
  • Vendor security documents
  • Terms of service and privacy policy
  • Cost and contract terms
  • Requested start date

Approval must come from the department manager, IT/security, compliance, legal (if required), and executive leadership for high-risk uses.

25
Approved AI Tool Register

VisionOne maintains a current internal register of approved AI tools. Each approved tool is recorded with the following fields:

  • Tool
  • Approved use
  • Risk level (Low / Medium / High)
  • Approved users
  • Data allowed
  • Data prohibited
  • Owner
  • Review date
Employees may not assume a tool is approved because it is popular, free, available online, or used by another company.
26
AI Use in Marketing & Public Content

AI-generated marketing or public content must be reviewed before publication. Marketing content must not:

  • Make unsupported claims
  • Misrepresent insurance products
  • Promise savings, coverage, approval, or claim outcomes unless verified
  • Use misleading testimonials or fake reviews
  • Use copyrighted images, logos, or brand assets improperly
  • Use deepfakes or synthetic people deceptively
  • Violate carrier marketing rules
  • Violate state insurance advertising rules
27
AI Use in Legal & Compliance Work

AI may help organize or summarize legal or compliance materials, but it may not replace legal counsel, compliance review, or official regulatory analysis.

Employees must not rely on AI as the final authority for:

  • Laws
  • Regulations
  • Insurance rules
  • Contract interpretation
  • Coverage interpretation
  • Employment obligations
  • Privacy obligations
  • Regulatory filings
  • Customer disputes
  • Claims disputes
28
AI Use in Customer Service

AI may assist customer service by drafting responses, summarizing interactions, or helping employees find information. It may not be used to mislead customers or make final decisions.

Customer service employees must:

  • Verify AI-generated answers
  • Use approved scripts and procedures
  • Escalate uncertain insurance, legal, claims, or coverage questions
  • Avoid entering customer data into unapproved AI tools
  • Document material customer-impacting decisions
29
AI Use in Claims, Underwriting & Coverage

Unless specifically approved in writing, employees may not use AI for claims, underwriting, rating, eligibility, risk scoring, or coverage analysis.

If approved, the AI system must include:

  • Human final decision-making
  • Compliance review
  • Bias review
  • Documentation
  • Audit trail
  • Vendor review
  • Carrier approval if required
  • State-specific regulatory review if required
  • Consumer-disclosure process if required
  • Appeals or correction process where applicable
30
Review Schedule

This policy must be reviewed:

  • At least annually
  • When VisionOne adopts a new AI tool
  • When a major AI-related law, regulation, carrier rule, or insurance requirement changes
  • After any significant AI incident
  • When entering a new line of business, state, carrier relationship, or insurance program

Questions about responsible AI at VisionOne?

We’re glad to walk through how this policy applies to your account, your data, or a project we’re working on together. Reach out and a member of our team will follow up.