M.A.I. Consulting
GuidePractitioner25 September 20264 min read

AI policy review: the six-month cycle and what triggers an early one

Why an AI policy needs a fixed six-month review against four specific questions, plus four yes-or-no triggers (departed contact, changed tool, repeated escalation, changed law) that force an earlier one.

The last piece in this series covered what happens in the moment something goes wrong: a named contact, a 24-hour clock, no penalty for reporting. That handles a single incident well. It says nothing about the slower failure mode, a policy written once and left untouched, drifting quietly out of date at exactly the pace the tools and the organisation's own practice change. Nobody notices the drift day to day. By the time someone does, the permitted-use table has been describing a version of the work that stopped being true months ago.

The answer is a fixed six-month review cycle, plus a short, specific list of events that force an earlier review regardless of where the calendar sits.

Why six months, and not a year or "as needed"

A year is long enough that a permissions table can drift a long way from what staff are actually doing before anyone catches it. "Review as needed" sounds sensible and fails for the same reason a soft escalation deadline fails: it hands someone the judgement call of deciding whether now counts as needed, and that judgement call quietly never gets made under normal workload pressure. Six months is short enough to catch drift before it compounds, long enough that reviewing does not become a constant background task nobody takes seriously. It is a deliberately blunt number, chosen for the same reason the 24-hour rule was: a fixed interval is something a DPO can actually put in a calendar and defend, where a discretionary one dissolves into never happening.

What the six-month review actually checks

A review is not a rewrite from scratch; treating it as one is exactly what makes people dread it and put it off. It is a structured check against four specific things: is every named contact from the escalation path still in that role, does the permitted-use table still match how staff are actually working, has any routinely used tool changed capability meaningfully since the last review, and do the escalation records from the period show a pattern worth acting on rather than isolated incidents. Each of those four has a clear yes-or-no answer, which is what keeps the review from turning into an open-ended discussion that nobody finishes.

What forces a review before six months are up

Six months protects against slow drift. It says nothing about the day something specific breaks the policy outright, and that needs its own trigger, not a place in next quarter's queue.

The trade-off in adding triggers on top of a fixed cadence

Every trigger added increases the odds a review happens exactly when something real needs it, but it also adds another condition someone has to actively track, and a trigger list that grows without discipline becomes as unusable as the review-as-needed rule it was meant to replace. The honest answer is the same discipline this series applied to the red-line list: keep the triggers few, and keep each one a clean yes-or-no question rather than a matter of judgement. "Did the named contact leave" has one answer. "Does this feel serious enough to warrant an early review" reintroduces exactly the hesitation a fixed rule exists to remove.

The practical takeaway

Fix the review at six months, treat each review as a structured check against four specific questions rather than a rewrite, and hold a short list of binary triggers, a departed named contact, a materially changed tool, a repeated escalation category, a changed law, that force an earlier review without ever needing anyone's judgement call about whether now feels urgent enough.

No external statistic cited; this article presents an internal practical guide rather than third-party evidence.

Series · Writing an AI use policy · part 6 of 6
Keep reading
02 ยท AI Use Policy

What are our people allowed to do, and how?

If this is the question on your desk, a thirty-minute call tells you whether the service fits, or that you do not need us yet.