Ethical Use of AI Management Standard
EUMS Version 1.0
Five pillars. Three badge tiers. One passing score, with floors on every pillar and a higher minimum on human oversight.
Key term
Human in the loop.
A named individual responsible for reviewing, approving, or overriding AI outputs before they take real-world effect.
Every AI use in your organisation must have a named human in the loop. Not a team, not a role, not a process — a person, by name, who can be asked why a specific output was accepted and is accountable for the answer.
How certification is scored
Weighted across the pillars.
Pillar 1
Use AI Responsibly
Do your people have clear rules for how to use AI?
Pillar 2
Keep Humans in ChargeMinimum: 70%
Do you know what AI you're using? Is a named human always in the loop? Can they explain the output?
A · AI Register & Human-in-the-loop
Is every AI tool documented, and is a named human accountable and able to explain each one?
B · Hallucination awareness
Can your people identify and handle AI hallucinations?
Pillar 3
Be Open
Are clients and staff informed about your AI use?
Pillar 4
Support Your People
Do employees know what's expected of them?
Pillar 5
Respond to Problems
Do you log and learn from AI incidents?
How the weights work
The weights sum to 100%, so if you score X% on every pillar your overall score is X%. Because Pillar 2 carries the heaviest weight, strong human oversight lifts your overall score more than any other single area — which reflects the right priority.
Why every pillar has a floor
Certification is a whole-organisation signal. No pillar can be entirely neglected in exchange for over-performance elsewhere. The 70% per-pillar floor prevents an organisation from banking a high overall score while leaving a whole area — for example incident response or client disclosure — effectively unaddressed.
Passing score: 70% overall, with a 70% floor on every pillar (Pillar 2 also carries a 70% minimum).
The floor is not a free pass. An organisation scoring 85% overall but only 55% on Pillar 3 (Be Open) does not pass — the pillar floor is not met. Certification requires the overall threshold and genuine effort across every pillar.
Badge Tiers
Three tiers, awarded only when all pass conditions are met.
Green Badge
70–79% overall
Given to organisations that have met the minimum threshold for certification, but whose AI governance is still maturing. Expect visible gaps: an incomplete AI Register, uneven disclosure practices, or human oversight that is named but not yet consistently exercised. A Green Badge signals that the organisation is on the record and under active review — customers, partners, and counterparties should treat it as a work in progress rather than a mark of confidence. Green Badge holders are expected to remediate identified weaknesses and return for reassessment within six to twelve months, with the goal of progressing to Gold.
Awarded only when the overall score, per-pillar floors, and the Pillar 2 minimum are all met.
Gold Badge
80–89% overall
Given to organisations that have meaningfully implemented all five pillars with documented processes and disciplined follow-through. AI is deployed in client-facing or operational contexts with a maintained AI Register, named humans in the loop for each use case, disclosure practices that are actually observed, and incident logging that is used rather than merely written down. Customers, partners, and counterparties should read a Gold Badge as a credible mark of confidence: the organisation is taking ethical AI use seriously and operating well above the certification floor, with visible headroom to progress to Blue.
Blue Badge
90–100% overall
Given to organisations with exemplary AI governance across the full standard. Every AI use in the Register is scoped, disclosed, and covered by named human accountability; incident response is mature and rehearsed; disclosure is rigorous and consistent; and internal review cycles keep policy in step with how AI is actually used day to day. Customers, partners, and counterparties should read a Blue Badge as the strongest signal Ethicality issues: the organisation has cleared the bar in every pillar with real margin and is operating at the leading edge of responsible AI use.
The Pillars
Five pillars. Every requirement applies.
Each certified organisation must meet every specification listed below. Where a requirement is genuinely not applicable to the nature of the business, the certifier may grant a documented concession — recorded against the relevant pillar and reviewed at each recertification.
PILLAR 01
Use AI Responsibly
Weight · 20%
The organisation has clear, written rules for how employees use AI at work.
Requirements
- ·An Acceptable Use Policy covering which tools employees may use, for what purposes, and what is prohibited.
- ·Disclosure rules: the circumstances under which employees must inform a client or customer that AI contributed to an output.
- ·A prohibition on using AI to make sensitive decisions without human review.
- ·A list of prohibited uses — categories of decision or content for which AI may not be used at all.
- ·Data handling rules: which categories of data (personal, confidential, client-privileged) may not be entered into AI tools, and which tools are approved for which data types.
- ·A requirement that AI-assisted client deliverables are reviewed by a qualified human before issue.
- ·A sign-off protocol: material AI-assisted outputs require named human authorisation before acting on them.
- ·Periodic policy review; at minimum annually or when a material tool change occurs.
PILLAR 02
Keep Humans in Charge
Weight · 40%
Higher minimum · 70%
A person — not a system — is responsible for every AI-assisted outcome, can explain it, and knows what the organisation uses AI for. This is the heart of the standard.
NoteHigher minimum: 70% on this pillar to pass certification.
Human in the loopA named individual responsible for reviewing, approving, or overriding AI outputs before they take real-world effect. Every AI use must have one — by name.AAI Register & Human-in-the-loop
30%Requirements
- ·An AI Register documenting every AI tool in use, its purpose, and the named human in the loop responsible for it.
- ·A plain-language description of what each tool does and how it produces its outputs.
- ·An annual review of the Register, with a changelog recording additions, removals, and material changes.
- ·For every tool in the Register, a named human in the loop is responsible for overseeing how that tool is used and for any outcome it contributes to.
- ·A Human-in-the-Loop Policy that requires a human to make any final decision, even when AI has informed or assisted it. AI output is input. The decision is always human.
- ·All AI use is explainable. For every tool in use, a responsible person can describe, in plain language, how the AI produces its outputs and on what basis.
- ·AI tools whose reasoning cannot be understood or explained are not used.
- ·AI is not permitted to make decisions autonomously on the organisation's behalf.
- ·A process for employees to notify the Register owner when a new AI tool enters use, so a named human in the loop can be assigned before reliance.
- ·The named human in the loop reviews all material AI outputs before delivery. AI-generated work is not routed directly to a client without that review.
- ·The named human in the loop can explain how a specific output was produced and why it was accepted, modified, or rejected.
BHallucination awareness
10%Requirements
- ·Employees who use AI tools understand that AI can produce confident, plausible, and wrong outputs — and are briefed on how to recognise them.
- ·A verification expectation: factual claims, citations, figures, and quotations generated by AI are checked against source material before use.
- ·Verification is documented for client-facing deliverables: the reviewer records what was checked and against what source.
PILLAR 03
Be Open
Weight · 15%
The organisation is transparent about how AI is used — with clients and with staff.
Requirements
- ·Disclosure language for client-facing communications where AI contributed to an output, respecting commercial confidentiality.
- ·Internal communications so employees understand how AI is and is not used in their workplace.
- ·A plain-language summary of AI use available to clients on request.
- ·Active disclosure: clients are informed that AI was used in a specific deliverable, not only when they ask.
- ·A record that disclosure was made — a log or sample sufficient to demonstrate the practice, not just the policy.
PILLAR 04
Support Your People
Weight · 10%
The people using AI know what's expected of them, and have somewhere to go when they're uncertain.
Requirements
- ·All employees who use AI tools are briefed on the Acceptable Use Policy and Human-in-the-Loop Policy before using them.
- ·A named point of contact for AI questions — the person employees go to when unsure whether a use is appropriate.
- ·A refresh briefing when policies or tools change materially, or at minimum annually.
- ·New employees are oriented as part of onboarding, before they use any AI tool.
- ·Role-specific guidance for employees whose work involves AI-assisted client outputs, covering their verification responsibilities.
- ·Evidence of briefings: a record that each employee has been briefed, sufficient to demonstrate the practice to an assessor.
PILLAR 05
Respond to Problems
Weight · 15%
The organisation has a plan for when AI produces a harmful or incorrect outcome — and learns from it.
Requirements
- ·An Incident Response Process: how to identify, log, and escalate an AI-related problem.
- ·A review process: a named person or group decides what went wrong and what changes as a result.
- ·A record of incidents and how they were resolved.
- ·A trigger mechanism connecting the review process to Pillar 4: if the review determines a policy or training change is needed, a named person is responsible for actioning it within a defined timeframe.
- ·A client notification protocol: if an AI-related error affects a client output, the process for informing them and remediating.
- ·An annual review of the incident log to identify patterns, even in the absence of individual incidents.
- ·Root cause analysis is documented for material incidents and retained for a minimum of three years.
Need a starting point? See ready-to-use templates and examples for every document required under EUMS.
Passing Grade
One threshold. Floors on every pillar.
70% overall
60% floor on every pillar
70% minimum on Pillar 2
Every certified organisation must reach 70% overall, clear 60% in every pillar, and reach 70% in Keep Humans in Charge.
The three badge tiers — Green, Gold, Blue — reflect overall score above that threshold: 70–79% Green, 80–89% Gold, 90–100% Blue.
