1.Purpose
This procedure sets out how NCI staff and authorised users propose, evaluate, approve, use, monitor and report AI use. It operationalises the Artificial Intelligence (AI) Policy and may be updated independently where processes or systems change.
2.Scope
This procedure applies to institutional and professional AI use by NCI employees and to contractors, partners, students and suppliers where the AI Policy applies. Student learning and assessment use is also subject to the separate the Acceptable Use of Generative AI in Teaching, Learning and Assessment Policy.
3.Advice and Decision Channels
Queries and proposals must be directed according to their subject:
- Data protection, personal data, privacy notices or DPIAs: Data Protection Officer.
- Security, access, architecture, installation, integrations or approved technical configuration: Information Technology.
- Programme design, learning, teaching, assessment or academic integrity: relevant Academic Leadership and the APQC or LTAC pathway.
- Research ethics and integrity: Research Office and RIC pathway.
- Tool or institutional use-case approval: AI Governance Committee through the published AI Governance Review channel.
- Concerns about the use of generative AI on a person's work, or a request for a non-AI alternative: the accountable manager or academic lead and the AI Governance Committee; consult the DPO where personal data is involved.
- Routine low-risk use of an approved system or a Permitted External AI Tool within the Register conditions: the user, accountable manager and any normal business or academic approver.
IT is responsible for technical and security advice but is not the sole decision-maker on whether an institutional use is appropriate. The AI Governance Committee coordinates the combined evaluation and escalates decisions to SLT or Academic Council where required.
4.Evaluation Request and Documentation
Submit a request through the IT Helpdesk using the AI Tool and Use-Case Evaluation request category/form. This is the single formal intake route for a new tool, a new controlled use of an existing tool, institutional procurement, College-managed accounts, structured teaching deployment, lab or device installation, integration or automation. The Helpdesk ticket number is used to track the request, specialist reviews, decision, conditions and review date; a separate email to the AI Governance Committee is not required.
A status of ‘Under review’ in the Register means an evaluation is actively in progress. ‘Not approved unless added following evaluation’ means there is no current approval and no evaluation should be assumed to be planned; an interested staff member or accountable owner must initiate the Helpdesk request. The requester will be notified of the outcome and the Register will be updated where approval or permission is granted.
For a Level 2 or Level 3 submission, the requester completes the standard form sections covering Steps 1–4 and the accountable business or academic owner confirms the proposal. Specialist reviewers and the AI Governance Committee add their findings, decision and conditions to the same record. Routine Level 1 use needs no form or central submission where it remains within the Register conditions and involves no NCI purchase, managed account, installation, integration, automation or structured deployment; the user still retains any record required by Step 9 or by normal academic, research or business processes.
For teaching use, the programme or module academic owner submits the request and records the module/programme, learning outcome or industry/validation rationale, intended student activity, account and licence model, data to be used, accessibility and equity considerations, assessment implications and any lab or integration requirement. The AI evaluation and the existing lab-software installation/change process are coordinated through the same Helpdesk ticket but neither replaces the other. A one-off Level 1 browser-based demonstration using only public or synthetic information may proceed under the Register and academic policy; structured or repeated student use, required accounts or licences, assessment use, installation or integration must be submitted for review.
5.Approval Levels
| Level | Typical Characteristics | Decision |
| Level 1 - Routine/low risk | Approved system or register-permitted external tool; public information or Routine Low-Risk Institutional Content only; no Protected College Data, novel integration, automation or high-risk decision. | No AI Governance submission is required. The user follows the Register conditions, remains accountable and obtains any normal manager, academic or business approval. |
| Level 2 - Institutional/controlled | Protected College Data; system integration; automation; transcription; repeated controlled processing; supplier purchase; or material public, student or staff impact. | AI Governance Committee review with IT, DPO, Procurement, Academic Council or Research Committee as relevant. |
| Level 3 -High risk/significant | Potential EU AI Act high-risk use, automated significant decision, novel profiling, substantial modification or significant rights/safety risk. | Documented review and SLT approval; Academic Council approval where academic or research use is affected. |
6.Ownership, Documentation and Decision Record
Responsibility follows the subject matter throughout the process: IT does not automatically own Step 5 and the DPO does not automatically own Step 6. The accountable business or academic owner remains responsible for the proposal and implementation; the AI Governance Committee coordinates the decision, while IT, the DPO, Procurement and academic or research bodies provide and record specialist review where relevant.
| Step | Lead responsibility | Required record and supporting review |
| 1 – Need and owner | Requester drafts the proposal; accountable business or academic owner confirms and sponsors it. | Sections 1–4 of the AI Tool and Use-Case Evaluation Request for any submission; purpose, benefit, users, affected people, alternatives and authorship considerations. |
| 2 – Information and privacy | Accountable owner completes classification and initial screening. | Classification and screening in the request. The DPO advises whether a DPIA or further privacy documentation is required and reviews the privacy documentation; IT advises on data handling and security classification. |
| 3 – Risk and legal classification | Accountable owner, supported by the requester. | Risk and EU AI Act classification recorded in the request. IT, DPO, Procurement, Academic Leadership/APQC/LTAC or Research Office/RIC contribute according to the risks and context. |
| 4 -Tool selection | Requester and accountable owner check the Register and proposed use. | Register status, exact product/tier/configuration and eligibility evidence recorded. IT separately approves installation, integration, access to managed systems and lab compatibility. |
| 5 – Approval | AI Governance Committee owns coordination and the AI governance decision. | Helpdesk ticket and completed request form are the decision record. The Committee obtains specialist recommendations and escalates Level 3 or significant academic matters to SLT or Academic Council as required. |
| 6 – Controls | AI system/business owner implements and evidences the approved controls. | Control and implementation record. IT implements technical controls; the DPO advises on privacy controls; Procurement manages contract controls; academic or research owners implement contextual controls. |
| 7 – Use and review | User and accountable owner. | Output review and second approval where required, recorded in the appropriate business, academic or research record. |
| 8 – Human authorship and choice | User and accountable owner; the accountable manager or academic lead considers objections. | Author notification, rights-holder authority, objections, alternatives and any decision-maker rationale recorded in the appropriate business, academic or research record. |
| 9 – Record and disclose | User records use; accountable owner ensures the record and disclosure requirements are met. | Tool/version, purpose, reviewer, decision and required declaration retained with the relevant work or approval record. |
| 10 – Monitor and re-evaluate | AI system/business owner. | Monitoring, incidents, supplier/model changes and scheduled review evidence. AI Governance Committee reviews status; IT, DPO and academic/research bodies provide assurance in their areas. |
| 11 – Report and respond | Any user reports promptly; system/business owner suspends use where necessary. | Incident or Helpdesk record. IT leads security response, the DPO leads personal-data breach response and the AI Governance Committee coordinates governance action and register changes. |
7.Procedure
Step 1 - Define the Need and Owner
- Describe the problem, intended benefit, users, affected people, expected outputs and why AI is necessary.
- Nominate an accountable business or academic owner.
- Confirm whether a non-AI or lower-risk alternative would meet the need.
- Identify whether another person's original or unpublished work will be uploaded, analysed or materially edited, who owns or controls the relevant rights, and how the author will be informed.
- Where a submission is required, the requester records Steps 1–4 in the AI Tool and Use-Case Evaluation Request and the accountable owner confirms that the information is complete and accurate before it is submitted.
Step 2 - Classify Information and Screen Data Protection
- Identify all input, reference, connector and output data and classify it as public information, Routine Low-Risk Institutional Content or Protected College Data, applying the relevant NCI data classification.
- Complete an initial data-protection screening for a new institutional deployment or integration and for any use that involves, or may reasonably involve, personal data or Protected College Data. A formal screening is not required for routine Level 1 use involving only public or Routine Low-Risk Institutional Content.
- Consult the DPO and complete a DPIA where required; provide or update privacy information at collection where applicable.
- Minimise, anonymise or pseudonymise personal data wherever possible.
Step 3 - Evaluate Risk and Legal Classification
- Evaluate security, privacy, equality, accessibility, bias, academic integrity, copyright, records, supplier, environmental and operational risks.
- Classify content according to its substance and risk. Draft, unpublished, academic or research status alone does not make content Protected College Data.
- Evaluate how the provider retains and uses prompts, files and outputs, including any model-training or fine-tuning use, and identify the contractual or configuration controls required to prevent unauthorised reuse.
- Determine NCI's EU AI Act operator role and screen Article 6 and Annex III, including admissions, assessment, progression, examinations, employment and profiling.
- Document whether the use is Level 1, 2 or 3 and the rationale.
Step 4 - Select a Tool Appropriate to the Risk
- Check the Approved AI Tools and Services Register to determine whether the proposed use requires an exact approved product and configuration or falls within a permitted low-risk category.
- For Protected College Data, confirm approval of the exact product, version, tier, configuration, purpose and data category and verify that provider training, retention and onward use are disabled or contractually prohibited as required.
- For Level 1 use, an external tool need not be individually approved where the Register permits the category of tool and use. The tool must meet the minimum eligibility criteria published by the AI Governance Committee, and the user must confirm that the provider, product or category is not excluded or suspended. Confirm that the content is public or Routine Low-Risk Institutional Content and that provider terms, copyright and model-training conditions are acceptable.
- Where eligibility cannot be confirmed, or the provider, product or category is excluded or suspended, do not use it for NCI work until the AI Governance Committee has provided direction.
- Do not assume a paid tier, mobile app, browser extension, integration or new model version is approved.
- Do not install software or enable integrations on College-managed devices or systems without IT approval.
Step 5 - Obtain Approval
- Level 1 use may proceed within the Register conditions and normal business or academic approval without an AI Governance submission.
- Submit Level 2 or Level 3 proposals to the published AI Governance Committee for review.
- The AI Governance Committee owns the governance review from triage to decision. It assigns the required IT, DPO, Procurement, academic or research reviews, records their recommendations and conditions in the Helpdesk record, makes the decision within its authority and escalates matters requiring SLT or Academic Council approval. IT approval for installation and DPO privacy advice are specialist determinations and do not replace the overall AI governance decision.
- Do not procure, institutionally pilot, install, integrate, automate or deploy a Level 2 or Level 3 use until all required approvals and impact assessments are complete. This does not prevent permitted Level 1 use of an externally available tool that requires no NCI procurement, installation or integration.
Step 6 - Apply Controls
- Configure access, authentication, logging, retention, data boundaries, connectors and supplier controls.
- For Protected College Data or rights-managed content, apply settings and contractual controls that prevent prompts, uploaded work and outputs being used for model training, fine-tuning or unrelated supplier purposes. For Routine Low-Risk Institutional Content, review the provider terms and available privacy or training settings and do not use the tool where supplier reuse would conflict with copyright, research, contractual or other obligations.
- Nominate and train human overseers where required.
- For recording, transcription or meeting recap, provide appropriate notice, confirm the lawful basis, restrict access and apply approved retention.
- Define accuracy, bias, security, accessibility and performance tests and stop-use thresholds.
Step 7 - Use and Review Outputs
- Review relevance, accuracy, bias, confidentiality, copyright, citations and suitability.
- For routine teaching, research or coding work in an external tool, confirm that inputs contain no Protected College Data, credentials, secrets, restricted source code, confidential research material or third-party content whose terms prohibit the proposed use.
- For routine drafts and emails, the author reviews content, recipients, attachments, confidentiality and tone.
- For significant public, academic, contractual, financial, employment or student-facing outputs, obtain a qualified second review and normal formal approval.
- Do not use AI-detection tools as determinative evidence of misconduct.
Step 8 - Respect Human Authorship and Choice
- Do not require a person to use generative AI to create or materially edit content where the objective can reasonably be achieved without it, unless the AI use is an essential learning outcome or a documented institutional requirement.
- Where AI use is required, communicate this in advance and consider a reasonable non-AI alternative where practicable.
- Do not upload or materially alter another person's original or unpublished work without the author's knowledge and appropriate authority from the relevant rights holder or institutional owner.
- Record and respond to objections transparently. If an objection cannot be accommodated, document the necessity and proportionality of the AI use and the decision-maker's rationale.
- This step does not apply to approved background or embedded AI functions that do not materially create or alter the person's work.
Step 9 - Record and Disclose Material Use
- Record material AI use, the tool/version, purpose, human reviewer and decision where required.
- Where applicable, record author notification, rights-holder authority, objections raised, alternatives considered and the rationale for any decision not to accommodate an objection.
- Use the standard declaration or another approved wording for official outputs and third-party deliverables.
- Routine low-risk drafting does not normally require external disclosure unless another rule requires it.
Step 10 - Monitor and Re-evaluate
- Monitor performance, impacts, bias, security, complaints, supplier changes, model changes and compliance with approval conditions.
- Re-evaluate material changes in data, purpose, users, version, tier, configuration, integrations or supplier terms.
- Complete scheduled annual review and retire the use when it is no longer needed or risks cannot be controlled.
Step 11 - Report and Respond
- Report security incidents, data breaches, harmful bias, significant hallucinations, failures, complaints or suspected non-compliance to the AI Governance Committee.
- Report personal-data incidents to the DPO and security incidents to IT without delay.
- Suspend or stop the system where approval conditions, safety, rights or legal requirements may be compromised.
8.Monitoring and Assurance
- Users and managers check routine compliance and output quality.
- System owners maintain monitoring evidence, logs, incidents, performance and review actions.
- IT monitors technical controls; the DPO oversees privacy assurance; Academic Council and it’s sub-committees LTA and APQC oversee academic integrity and programme use.
- The AI Governance Committee reviews approvals, register changes, incidents, training completion and outstanding actions.
- The Director of Information, Technology & Innovation reports annually to SLT and Academic Council.
9.Records
Records must be retained in accordance with NCI's Records Management Guidelines and applicable law. Depending on the use, records include the use case, classification, impact assessments, approvals, supplier evidence, tool/version, oversight, notices, decisions, automatically generated logs under NCI's control, monitoring, incidents, complaints and review actions. Records must also include, where relevant, evidence of author notification, rights-holder authority, objections, alternatives considered and decisions concerning the use of AI on a person's work.
For Level 2 and Level 3 proposals and any tool-approval, procurement, teaching-deployment, installation or integration request, the Helpdesk ticket and completed AI Tool and Use-Case Evaluation Request form the authoritative process record. The AI Governance Committee is responsible for ensuring that the final decision, conditions, owner and review date are recorded; each specialist reviewer remains responsible for the accuracy of their recorded advice or determination.
10.Related Documents and Version Control
- Artificial Intelligence (AI) Policy.
- Approved AI Tools and Services Register.
- Acceptable Use of Generative AI in Teaching, Learning and Assessment Policy.
- Data Protection, Information Security, Procurement and Records Management policies and procedures.
Version Control
| Document Status | Final | Approval Body | Senior Leadership Team |
| Policy/Procedure Manager | Director of Information, Technology & Innovation | Executive Owner | Director of Information, Technology & Innovation |
| Date Approved | 11/08/2026 | Effective Date | 11/08/2026 |
| Date of Next Review | 11/08/2027 | Version Number | V1.0 |
Comments
0 comments
Please sign in to leave a comment.