Northwind Commerce · AI Governance

AI Policy — Version 1.1

Effective 2026-04-22 Owner: Aria · AI Governance Lead ISO/IEC 42001:2023 aligned

Northwind Commerce is a mid-size direct-to-consumer retailer (apparel, home goods, 140 staff, 9 markets in EU + UK). This policy tells our people exactly which AI tools to use, which data to put in them, and what to do when something goes wrong. It is opinionated on purpose. A policy that says "use AI responsibly" is a policy that says nothing.

If you are reading this at 11pm wondering whether to paste a customer email into a chatbot, the answer is in Section 3. Stop reading at Section 3 if you need to.

1.Scope & Intent

Applies to every Northwind employee, contractor, and agency partner who uses, builds, or buys AI. Covers generative AI (text, code, image, voice, video), predictive models (fraud, forecasting, recommendations), and autonomous agents.

Our stance. AI is a force multiplier for a 140-person company competing with 10,000-person incumbents. We adopt it deliberately, we pick specific vendors, and we never let it become the reason a customer loses trust in us.

2.Principles (the non-negotiables)

  1. Human accountability. A named human is accountable for every AI-influenced decision that affects a customer, employee, or financials. AI never signs contracts, fires people, sets final prices, or approves refunds above threshold.
  2. Transparency. If a customer is talking to AI, we tell them. AI-generated content is labelled where context matters.
  3. Data minimisation. Anonymise, aggregate, or mask before paste. Always.
  4. Proportional control. Rules scale with impact.
  5. Continual improvement. Reviewed quarterly. Incidents feed the next version.

3.Data Handling — the Three-Light Rule

LightData typeWhere it may go
GOProduct catalogue, public marketing copy, anonymised/aggregated analytics, generic how-to questions, our own public docsAny approved tool in Section 4
PAUSEInternal non-customer data (financial drafts, supplier terms, internal wiki, unreleased roadmap)Claude Enterprise or ChatGPT Team/Enterprise only. Never free/personal tiers.
STOPCustomer PII (name, email, address, phone, order history with identifiers), payment data, passwords, API keys, health data, data about children, employee performance data, legal/HR recordsNever. Not in any LLM tool. Not even "just to test". Not even masked if re-identification is plausible.

Screenshots count. Code that contains real data counts. CSV exports count. If you can mentally re-identify a person from it, it's STOP-tier.

4.Approved LLM Providers & Tools

We are opinionated about which models touch our data. The decision is about where the request goes, who controls the server, and whose laws apply to it.

4.1 Approved providers

ProviderStatusWhat we use it for
Anthropic (Claude)
Zero-retention, no-training on Enterprise. US, EU option available.
✓ PrimaryDefault for drafting, analysis, code, customer support, internal agents
OpenAI (ChatGPT Team/Enterprise, API)
Enterprise tier zero-retention + no-training. EU region on Enterprise.
✓ ApprovedImage generation (GPT Image), specific workflows, Claude fallback
GitHub Copilot (Business/Enterprise)
Microsoft/OpenAI pipeline, no-training on Business+.
✓ ApprovedCode suggestions only
Perplexity Enterprise
Cited research; Enterprise tier does not train on queries.
✓ ApprovedNamed research tasks. Never with customer data.
Google Gemini, Mistral⏸ Ask AriaNot banned, not approved. Reassessed each quarterly review.

4.2 Providers we do NOT use

No Chinese-hosted models. DeepSeek, Qwen (Alibaba), Kimi (Moonshot), Doubao, GLM, ERNIE, or any model hosted inside the PRC. Data may be legally compelled by Chinese state authorities under the National Intelligence Law (Art. 7), Data Security Law, and PIPL. No reliable DPA we can enforce in EU/UK jurisdiction. Not worth the category of risk, however capable the models are.
Not allowedReason
DeepSeek, Qwen, Kimi, Doubao, GLM, ERNIE (any Chinese-hosted LLM)PRC data-compulsion regime. No enforceable EU/UK DPA.
Free/personal consumer tiers (ChatGPT free, Gemini free, Claude free web, Copilot Free)Their terms allow training on your prompts. What you paste can end up in someone else's answer.
Random "ChatGPT wrapper" SaaSUsually a one-person shop proxying OpenAI with no DPA, no SOC 2. If it's not on the approved list, ask Aria first.
Open-source models on personal laptops with company dataNot the model's fault — the problem is the laptop, the backups, and the person who leaves.

4.3 Do we need on-prem / in-house inference?

Short answer: no, and you probably don't either. We are a 140-person retailer. A cluster of H100s depreciates faster than a phone, needs a dedicated ML-ops engineer, and still gives you a smaller model than Claude Sonnet. Running your own inference only makes sense for HIPAA-regulated healthcare handling raw PHI, classified government/defence work, or >$1M/year API spend with a measured ROI case. Revisit annually or when our API spend crosses $500K/year, whichever comes first.

5.Role-Based Rules

5.1 Customer Service

5.2 Marketing & Content

5.3 Engineering

5.4 Merchandising & Pricing

5.5 HR & Hiring

5.6 Finance & Fraud

6.Practical Tips — How We Actually Use Claude

Claude is our primary model. Staff get faster results if they use it the way it is designed.

6.1 claude.ai (web chat)

6.2 Claude Code (terminal / IDE)

6.3 Claude Cowork (MCP + autonomous workflows)

6.4 Good-chat hygiene

6.5 Prompt templates we keep around

Stored in the Aria Project on Claude Enterprise; anyone can copy-paste:

7.Incident Response — the 5-Minute Rule

  1. SPOT — notice it.
  2. SCREENSHOT — prompt, output, tool, timestamp.
  3. POST in #ai-incidents within 5 minutes. No blame. Just facts.
  4. PAUSE the tool for that task until Aria clears it.

Hiding an incident to avoid embarrassment is the only AI-related behaviour at Northwind that results in disciplinary action.

8.Vendors & Third Parties

Any supplier who touches Northwind customer data with AI must:

9.AI System Register (ISO/IEC 42001 Annex A alignment)

For every AI system Northwind builds or deploys, Aria maintains a one-page record:

10.Training & Awareness

11.Enforcement & Review