04 — Policy & Guidelines
Everything you need to use AI tools at Miroma Group responsibly. Read the policy, understand the guidelines, and know how to handle data correctly.
Documents
Download and read our AI governance documents. These apply to all Miroma Group employees using AI tools.
PDF — Policy
Miroma Group's official policy on the use of generative AI tools. Covers permitted uses, prohibited activities, accountability and governance.
Download PDF
PDF — Guidelines
Practical guidance on how to apply AI tools responsibly day-to-day — covering data handling, client confidentiality, output review and attribution.
Download PDF
Word Doc — Template
Use this template when you plan to use AI tools with personal, client or sensitive data. Complete and submit to your Division Head and Legal before proceeding.
PDF — Rules
The rules governing use of Claude across Miroma Group. Covers data handling, permitted inputs, connectors, model selection, output review, and reporting obligations.
Download
PDF — Guidelines
The baseline rules for using AI notetakers and meeting-transcription tools (Zoom, Teams, Google Meet, Fireflies and others). Covers approved platforms, participant notice and opt-out, permitted purposes, data retention, access and human sign-off.
Download PDF
Guide — On this page
Not sure whether you can use AI with a particular dataset? Follow this step-by-step guide to understand the risk level and what steps to take before proceeding.
View the guide
Decision Guide
Not sure whether you can use AI with a particular dataset? Work top to bottom: identify your data, find its risk level, then follow that column down to the controls you need to apply.
🔴 High risk
Data types
Is a DPIA required?
Check the list — Personal data: yes, Customer data: yes. All others: review with Legal.
Implement HIGH controls
🟡 Medium risk
Data types
Does this involve client data or competitive info?
If yes: review client contracts for restrictions first.
Implement MEDIUM controls
🟢 Low risk
Data types
Implement LOW controls
Prefer the original diagram? Open the flowchart image ↗
At a Glance
A quick reference for using AI tools responsibly at Miroma. Always read the full policy documents above.
Do not enter personally identifiable information, client financial data, or proprietary business data into any AI tool without completing a DPIA first.
AI-generated content must be reviewed, fact-checked and edited by a human before being shared with clients or published externally. You are responsible for the final output.
Where AI has been used to create client-facing work, this should be disclosed appropriately. Check client contracts for any specific restrictions.
Do not input Miroma Group's, or any client's, proprietary strategies, creative IP, or trade secrets into external AI tools. Use only approved platforms.
Use the data handling flowchart above before using AI with any dataset. High-risk data requires a DPIA and legal sign-off before proceeding.
If you're unsure whether a particular use of AI is permitted, reach out to the AI team before proceeding. Better to check than to create a compliance issue.
Questions about AI compliance or data handling?
Contact the AI team at aiteam@miroma.com — we'll help you navigate the right approach.