March 27, 2026
3
MIN READ

AI Procurement Policy Template: How to Govern AI Tool Purchases

No items found.

AI tools are entering every company faster than governance can keep up. With 68% of employees using unauthorised AI tools at work and shadow AI costing companies an average of $412,000 per year, a clear AI procurement policy is no longer optional. This guide provides a complete, seven-section AI procurement policy template designed for companies with 30 to 500 employees. It covers approved vendor lists, data classification tiers, cost-tiered approval workflows, usage-based spending caps, and quarterly review processes. The template includes actual policy language you can copy and adapt in an afternoon, plus practical advice on rolling out the policy without stifling the AI adoption your teams need. You will also learn how to automate enforcement using virtual cards, compliance questionnaires, and approval workflows so the policy works even when people are busy.

Illustration for AI Procurement Policy Template: How to Govern AI Tool Purchases
by
Harald Meyer-Delius

Why Every Company Needs an AI Procurement Policy Now

AI tools are entering your company whether you have a policy or not. According to Gartner, 68% of employees already use unauthorised AI tools at work. Shadow AI usage increased 156% between 2023 and 2025, and research from UpGuard found that more than 80% of workers, including nearly 90% of security professionals, use unapproved AI tools on the job.

The financial stakes are real. IBM's 2025 Cost of Data Breach Report found that AI-associated breaches cost organisations more than $650,000 per incident. Meanwhile, companies without governance lose an average of $412,000 per year to shadow AI, a figure that includes direct costs, productivity losses, and remediation.

Yet 43% of companies still have no policy on AI tool usage at all. That gap between adoption speed and governance readiness is where risk lives. An AI procurement policy closes it by giving your teams clear rules for evaluating, approving, budgeting, and reviewing AI tools, without slowing down the people who need them.

The good news: you do not need a 50-page document drafted by a committee of lawyers. A practical, two-page AI procurement policy that people actually follow beats a comprehensive framework that nobody reads. This guide gives you a ready-to-use template you can adapt in an afternoon, plus guidance on rolling it out and enforcing it automatically.

What Your AI Procurement Policy Should Cover

Before diving into the template itself, here is a quick overview of the five areas every AI procurement policy needs to address. Think of these as the non-negotiable sections. Everything else is optional and can be added later as your AI usage matures.

Approved vendor list and evaluation criteria

Start with what is already in use. Audit your current AI tools (you will almost certainly find more than you expect), then create an approved list with clear criteria for adding new ones. Evaluation criteria should cover security certifications (SOC 2, ISO 27001), data processing agreements, uptime SLAs, and whether the vendor trains models on your data. This is not about blocking tools; it is about ensuring the ones your team uses meet a baseline standard.

Data handling requirements

This is the highest-stakes section of your policy. Employees need a simple, memorable rule for what data they can and cannot share with AI tools. A practical framework uses three tiers: public data (marketing copy, published reports) is fine to use with any approved AI tool; internal data (strategy documents, financial projections) requires an enterprise AI account with a data processing agreement; and restricted data (customer PII, authentication credentials, source code with trade secrets) should never be entered into any external AI tool, regardless of the vendor's promises. If you would not paste it into a public website, do not paste it into a public AI tool. That single rule prevents most AI-related data incidents.

Approval thresholds by cost tier

Keep approval workflows proportional to spend. A practical tiering structure for companies with 30 to 500 employees looks like this: free-tier AI tools (ChatGPT free, Grammarly free) require no approval beyond accepting the acceptable use policy; tools under $50 per month need direct manager approval; tools between $50 and $500 per month require Finance approval; and anything above $500 per month needs sign-off from both Finance and IT. These thresholds are guidelines. Adjust them based on your company's size, risk tolerance, and budget. The key is that every tier has a clear owner so requests never stall in ambiguity.

Usage-based cost caps and alerts

AI tools with consumption-based pricing (OpenAI API, Anthropic API, AWS Bedrock) deserve special attention because costs can spike unpredictably. Your policy should define hard spending caps per tool, per team, or per project, along with automated alerts when usage hits 75% and 90% of the cap. Without caps, a single runaway API integration can burn through thousands of dollars before anyone notices.

Review cadence

AI moves faster than any other software category. A tool that was best-in-class six months ago may have been surpassed by three competitors. Set a quarterly review cycle for your AI tool stack, covering utilisation rates, cost-per-user trends, new market entrants, and whether each tool still meets your security requirements. Annual reviews are not frequent enough for this category.

The AI Procurement Policy Template

Below is a complete, seven-section AI procurement policy template designed for companies with 30 to 500 employees. Each section includes actual policy language you can copy, paste, and edit to fit your organisation. The tone is deliberately professional enough to present to your CEO or board, while remaining concise enough that employees will actually read it.

Section 1: Purpose and Scope

"This policy establishes the standards, approval processes, and governance controls for the procurement, deployment, and ongoing management of artificial intelligence tools and services across [Company Name]. It applies to all employees, contractors, and third-party partners who purchase, subscribe to, or use AI-powered tools in connection with company business. For the purposes of this policy, 'AI tools' includes generative AI assistants (e.g., ChatGPT, Claude, Gemini), AI coding assistants (e.g., GitHub Copilot, Cursor), AI-powered SaaS features embedded in existing tools, and any service that processes company data using machine learning models."

Section 2: Approved AI Tools List

"The following AI tools are approved for use at [Company Name] as of [Date]. This list is reviewed quarterly and updated as tools are added, removed, or reclassified."

ToolCategoryApproved Use CasesData Tier AllowedOwner
ChatGPT EnterpriseGeneral AI AssistantDrafting, brainstorming, summarisationPublic + InternalIT
GitHub Copilot BusinessAI Coding AssistantCode generation, code reviewInternal (no secrets in prompts)Engineering
CursorAI Coding IDEDevelopment workflowInternal (no secrets in prompts)Engineering
Grammarly BusinessAI Writing AssistantCopy editing, tone adjustmentPublic + InternalMarketing

"Any AI tool not on this list is considered unapproved. Employees wishing to use an unapproved tool must submit a request through the AI Tool Request process outlined in Section 4."

Section 3: Evaluation Criteria for New AI Tools

"All new AI tool requests are evaluated against the following criteria before approval:"

  • Security and compliance: Does the vendor hold SOC 2 Type II, ISO 27001, or equivalent certifications? Is a signed Data Processing Agreement (DPA) in place? Does the vendor's privacy policy confirm they do not use customer data to train models?
  • Business justification: What problem does this tool solve? Is there an approved alternative already in the stack? What is the expected ROI or time savings?
  • Data exposure risk: What types of company data will the tool access or process? Does the tool integrate with existing systems (email, CRM, codebase), and if so, what permissions does it require?
  • Cost structure: Is pricing per-seat, usage-based, or flat-rate? What is the projected monthly and annual cost? Are there usage-based components that could lead to unpredictable spend?
  • Exit strategy: Can data be exported if we stop using the tool? What is the contract term and cancellation process? Are there auto-renewal clauses?

Section 4: Approval Workflow and Thresholds

"AI tool purchases and subscriptions follow a tiered approval process based on annual cost:"

Cost TierApproval RequiredTurnaround Target
Free tier toolsSelf-service (accept Acceptable Use Policy only)Immediate
Under $50/monthDirect manager approval2 business days
$50 to $500/monthFinance approval + compliance questionnaire5 business days
Over $500/monthFinance + IT approval + full vendor assessment10 business days

"Approvals are tracked in [Company's procurement system]. No AI tool subscription may be purchased using a personal credit card or expense claim. All subscriptions must be paid through company-issued virtual cards or the approved procurement channel."

Section 5: Data Classification and Handling

This section is the backbone of your AI policy. Without clear data rules, every other section is theoretical.

"Company data is classified into three tiers for the purpose of AI tool usage:"

  • Public data: Information already available publicly or intended for public release. Examples: published blog posts, marketing materials, press releases, public financial filings. May be used freely with any approved AI tool.
  • Internal data: Non-public information used in day-to-day operations. Examples: internal strategy documents, financial projections, product roadmaps, meeting notes, non-public metrics. May only be used with approved enterprise AI tools that have a signed Data Processing Agreement and do not use inputs for model training.
  • Restricted data: Highly sensitive information subject to regulatory or contractual protections. Examples: customer personally identifiable information (PII), payment card data, employee health records, authentication credentials, proprietary source code, trade secrets. Must never be entered into any external AI tool under any circumstances.

"When in doubt about a data classification, treat it as Restricted and consult your manager or the IT team before proceeding."

Section 6: Budgeting and Cost Management

"All AI tool subscriptions are subject to the following cost management controls:"

  • Each AI subscription is assigned a dedicated virtual card with a monthly spend limit matching the approved budget.
  • Usage-based AI tools (API services, consumption-priced platforms) must have hard spending caps configured at the payment level. Caps are reviewed monthly.
  • Automated alerts are triggered when spend reaches 75% and 90% of the monthly cap.
  • AI spend is reported as a separate line item in the monthly software budget review.
  • Department heads are responsible for justifying AI spend variances exceeding 20% of the approved budget.

"The Finance team conducts a monthly AI spend review to identify cost anomalies, underutilised licences, and opportunities to consolidate tools."

Section 7: Review and Sunset Process

"AI tools are reviewed on a quarterly cycle. Each review assesses:"

  • Utilisation rates: Is the tool actively used by the team that requested it?
  • Cost efficiency: Has the cost-per-user changed? Are there cheaper alternatives that meet the same requirements?
  • Security posture: Has the vendor maintained its certifications? Have any data incidents been reported?
  • Market changes: Have superior alternatives entered the market since the last review?
  • Compliance: Does the tool still comply with any new regulatory requirements (e.g., the EU AI Act)?

"Tools that fail the review on utilisation or cost efficiency grounds enter a 30-day sunset period. During this period, the tool owner must either justify continued use or migrate users to an approved alternative. After 30 days, the subscription is cancelled."

How to Roll Out the Policy Without Killing Innovation

The biggest risk with any AI governance policy is not that it is too lenient. It is that it is so restrictive or so bureaucratic that employees ignore it entirely, and you end up with more shadow AI than you started with. Here is how to avoid that.

Start with amnesty, not an audit. Announce the new policy alongside an amnesty period (two to four weeks) where employees can declare any AI tools they are already using without consequences. This surfaces your real AI footprint and builds trust. You will almost certainly discover tools you did not know about. That is the point.

Make approved tools easy to access. If the approved path is harder than signing up for a free ChatGPT account with a personal email, people will take the easy route. Pre-provision approved AI tools for teams that need them. Ensure the request process for new tools is genuinely fast, especially for low-cost tools where the risk is minimal.

Communicate the "why" in business terms. "We need an AI policy for compliance" gets eye-rolls. "Three companies in our space had data leaks through AI tools last quarter, and we are making sure we are not next" gets attention. Frame the policy around protecting the company and its customers, not around adding bureaucracy.

Appoint AI champions, not AI police. Designate one person per department (ideally someone already enthusiastic about AI) as the go-to resource for AI tool questions. They help colleagues find approved tools, submit requests for new ones, and flag issues early. This distributes governance responsibility instead of bottlenecking it in IT or Finance.

Iterate based on friction. After the first quarter, review which parts of the policy caused the most confusion, the most approval bottlenecks, or the most workarounds. Simplify those sections. A good policy evolves; it is not carved in stone.

How Cledara Enforces AI Procurement Policies Automatically

Writing a policy is the first step. Enforcing it consistently, across every team and every tool, is where most companies fall short. Spreadsheet-based tracking breaks down the moment someone forgets to update it. Cledara automates enforcement at the process and payment layers so the policy works even when people are busy.

Compliance questionnaires built for AI tools. Cledara's customisable compliance questionnaire can be configured specifically for AI tool requests, with sections covering data handling practices, approved use cases, model training policies, and risk assessment. When an employee requests a new AI tool, the questionnaire captures the information your policy requires before approval is granted. No separate form needed.

Approval flows that match your thresholds. Configure single or dual approval workflows that trigger automatically based on cost. A $30 per month writing assistant routes to the direct manager. A $400 per month coding tool routes to Finance with a compliance review. A $2,000 per month enterprise AI platform routes to Finance and IT. The thresholds in your policy become the rules in Cledara, enforced on every request.

Virtual cards with hard spend limits. Every AI subscription gets its own virtual Mastercard with a spend limit that matches your approved budget. If your policy says "maximum $200 per month for Cursor," the card enforces it at the payment layer. For usage-based AI tools like OpenAI or Anthropic APIs, hard caps act as a circuit breaker that prevents runaway costs before they hit your bank account.

AI Dashboard for usage-based spend. Cledara's AI Dashboard connects directly to AI providers (OpenAI, Anthropic, Cursor) via API keys. It tracks daily usage-based spend, applies budgets per team or project, and visualises consumption trends so Finance can spot anomalies before they become budget problems.

Certification tags for vendor risk. Tag each AI vendor in Cledara with their compliance status: SOC 2, ISO 27001, GDPR compliance, Data Processing Agreement on file. During quarterly reviews, you can filter your AI tool stack by certification status to quickly identify vendors that need attention.

One-click cancellation for sunset tools. When your quarterly review identifies an AI tool for retirement, cancellation is as simple as freezing the virtual card. No vendor runaround, no forgotten auto-renewals, no need to hunt for the account owner. The payment stops, and the subscription ends.

The combination of questionnaires, approvals, spend controls, and usage tracking means your AI procurement policy is not just a document in a shared drive. It is an active set of controls enforced on every purchase, every month, automatically. Learn more about SaaS governance frameworks and how they apply to AI tool management.

What is an AI procurement policy?
An AI procurement policy is a formal document that defines how a company evaluates, approves, budgets, and manages AI tool purchases. It typically covers approved vendor lists, data handling rules, cost-tiered approval workflows, spending caps, and review schedules. Companies with a clear AI procurement policy reduce shadow AI risk and keep AI spending under control.
How do you create an AI tool approval process?
Start by defining cost tiers with matching approval levels. A practical structure for mid-market companies: free-tier tools need no approval, tools under $50 per month need manager sign-off, $50 to $500 per month requires Finance approval, and over $500 per month needs Finance plus IT. Add a compliance questionnaire covering data handling, security certifications, and business justification for each request.
What data should employees never share with AI tools?
Employees should never enter restricted data into external AI tools, regardless of the vendor. This includes customer personally identifiable information (PII), payment card data, employee health records, authentication credentials, and proprietary source code containing trade secrets. A simple rule: if you would not paste it into a public website, do not paste it into a public AI tool.
How does Cledara help enforce AI procurement policies?
Cledara automates AI policy enforcement through virtual cards with hard spend limits per subscription, configurable approval workflows tied to cost thresholds, customisable compliance questionnaires for AI tool requests, and an AI Dashboard that tracks usage-based spend from providers like OpenAI and Anthropic. This turns a written policy into active controls enforced on every purchase.
Why is a quarterly review cycle important for AI governance?
AI tools evolve faster than any other software category. A tool that was best-in-class six months ago may have been surpassed by multiple competitors. Quarterly reviews assess utilisation rates, cost efficiency, security posture, and market changes to ensure your approved tools still represent the best options. Annual reviews are not frequent enough for AI governance in 2026.

Contents

Contents

The software management solution for finance teams.

Learn more

Subscribe to our newsletter

Receive the latest insights in your inbox

Harald Meyer-Delius

Harald was told that he could never write for a living, so he became a Content Writer to prove them wrong. Now, with over ten years of experience, he is a content marketing professional specializing in fintech and startups. In his spare time he likes playing video games, writing fiction, and drinking coffee.

Share this post

Subscribe to our newsletter and stay informed on the latest SaaS insights

Sign up

Explore more

No items found.