Writing an AI use policy for a surveying firm: what to include
How to write an AI use policy that meets the RICS AI standard: the sections to include, the records that must sit behind it, and the mistakes that make policies worthless.
Since the RICS professional standard on responsible use of AI took effect on 9 March 2026, most surveying firms have accepted they need “an AI policy”. Fewer have noticed what the standard actually asks for — which is less about the policy document and more about the records that sit behind it.
What the standard expects a policy to do
The standard requires firms that use (or intend to use) AI in delivering surveying services to develop and implement policies on responsible use, informed by the firm's AI risk register. These policies must cover internally developed AI as well as third-party tools, and they may live either as a standalone document or inside existing IT, data-protection and client-engagement policies.
It also blesses a practical shortcut: the required written assessment of whether AI is the appropriate tool can take the form of a periodically reviewed written policy or standing statement — one that sets out the firm's services, what AI is used for in each, and why it is the appropriate tool, with explicit reference to alternatives, data risks, error and bias risk, and environmental and stakeholder impacts.
A working structure
A policy that satisfies the standard and that staff will actually follow tends to have seven parts:
- Scope and definitions — what counts as an AI system in your firm, including embedded and free tools.
- Approved tools and adoption route — the current tool list (your AI systems register does this job) and how someone gets a new tool approved and logged.
- The materiality decision — who makes the call on each instruction, the test they apply, and where the decision and reasoning are recorded.
- Client communication — when and how clients are told, in writing and in advance (disclosure notices), and what your terms of engagement say about AI involvement, PI cover, and the client's routes to contest, seek redress or opt out.
- Human review of outputs — how AI output is checked and signed off before anyone relies on it, and by whom.
- Risk management — the risk register, its owner, and the at-least-quarterly review rhythm.
- Data rules — what may and may not be put into which tools, aligned with your data-protection obligations.
The mistakes that make policies worthless
- The blanket ban. Prohibiting AI does not stop use — it stops visibility. Ungoverned, invisible use of AI on client work, next to a written policy proving the firm identified the risk and chose prohibition over management, is the worst position to defend.
- Policy without records. The standard's verbs are record, maintain, notify — in writing. A beautifully drafted PDF with no register, no decision log and no client notices behind it shows intent, not practice.
- Write-once compliance. Tools, models and features change monthly; the standard expects periodic review. A policy dated March that nobody has reopened is evidence of exactly that.
- Copying someone else's vendor claims. Statements about what a tool does with your data belong to the vendor's current terms — verify rather than inherit them.
Policy first or records first?
If you have neither, start with the records — the systems register takes an hour and immediately tells you what your policy needs to govern. Then write the policy around what you actually use. For the wider context of what the standard requires, see the RICS AI standard explained and the compliance checklist.
ComplyQS gives a firm the operational half of the policy: tool register, per-project materiality decisions with named decision-makers, client notices and an immutable audit trail — the evidence your policy promises.
Start your 180-day free trialThis article is general information, not legal or professional advice — have your policy reviewed against your firm's circumstances. ComplyQS is not affiliated with or endorsed by RICS.