← Governance framework
Governance

Responsible AI Usage Policy

Principles and controls governing the use of AI in matching, drafting, fraud triage and content generation.

Version
v1.0
Effective
2026-07-19
Last reviewed
2026-07-19
Next review
2027-07-19
Owner
Chief Trust Officer
Approver
Board of Trustees
Anchored by content hashissued 2026-07-29
Payload hash
deca606c02fb21fffead35946951dd950a9b8e4d979c3c8159c6f64a370c0abc
SHA-256 digest of the receipt content
Issuer AID
EP1_FGkcwfHAuih6VUzv9kgAVBvvSoaswSUao61lkxhE
Party that issued this receipt
ImpactMiles handle
audit:governance:deca606c02fb21ff

This receipt is anchored by content hash. A resolvable credential SAID is not available for this record.

Applies to

  • All AI features on the platform

Jurisdictions

  • Hong Kong (PDPO, IRD s.88)
  • United Kingdom (UK GDPR, DPA 2018)
  • European Union (GDPR)
  • Singapore (PDPA)
  • Australia (Privacy Act 1988)
  • Japan (APPI)
  • Wider APAC per country taxonomy

How this is applied in-product

  • AI never issues credentials or signs on behalf of users
  • Human review before any AI-drafted content is published
  • Public sub-processor register lists AI providers

1. Principles

  • Human in the loop for anything affecting eligibility, disbursement or credential issuance.
  • Explainability - every AI-generated match, ranking or flag carries a rationale.
  • No personal data in prompts unless a DPIA has authorised it.

2. Controls

  • Retrieval grounded in ACDC evidence, cited by SAID.
  • Rate limits and cost caps.
  • Model and provider changes tracked in the change log.
Questions or concerns about this policy? Contact the DPO.

Related policies