ComplyQS
HomeArticles › Writing an AI use policy for a surveying firm: what to include

Writing an AI use policy for a surveying firm: what to include

How to write an AI use policy that meets the RICS AI standard: the sections to include, the records that must sit behind it, and the mistakes that make policies worthless.

Since the RICS professional standard on responsible use of AI took effect on 9 March 2026, most surveying firms have accepted they need “an AI policy”. Fewer have noticed what the standard actually asks for — which is less about the policy document and more about the records that sit behind it.

What the standard expects a policy to do

The standard requires firms that use (or intend to use) AI in delivering surveying services to develop and implement policies on responsible use, informed by the firm's AI risk register. These policies must cover internally developed AI as well as third-party tools, and they may live either as a standalone document or inside existing IT, data-protection and client-engagement policies.

It also blesses a practical shortcut: the required written assessment of whether AI is the appropriate tool can take the form of a periodically reviewed written policy or standing statement — one that sets out the firm's services, what AI is used for in each, and why it is the appropriate tool, with explicit reference to alternatives, data risks, error and bias risk, and environmental and stakeholder impacts.

A working structure

A policy that satisfies the standard and that staff will actually follow tends to have seven parts:

  1. Scope and definitions — what counts as an AI system in your firm, including embedded and free tools.
  2. Approved tools and adoption route — the current tool list (your AI systems register does this job) and how someone gets a new tool approved and logged.
  3. The materiality decision — who makes the call on each instruction, the test they apply, and where the decision and reasoning are recorded.
  4. Client communication — when and how clients are told, in writing and in advance (disclosure notices), and what your terms of engagement say about AI involvement, PI cover, and the client's routes to contest, seek redress or opt out.
  5. Human review of outputs — how AI output is checked and signed off before anyone relies on it, and by whom.
  6. Risk management — the risk register, its owner, and the at-least-quarterly review rhythm.
  7. Data rules — what may and may not be put into which tools, aligned with your data-protection obligations.

The mistakes that make policies worthless

Policy first or records first?

If you have neither, start with the records — the systems register takes an hour and immediately tells you what your policy needs to govern. Then write the policy around what you actually use. For the wider context of what the standard requires, see the RICS AI standard explained and the compliance checklist.

ComplyQS gives a firm the operational half of the policy: tool register, per-project materiality decisions with named decision-makers, client notices and an immutable audit trail — the evidence your policy promises.

Start your 180-day free trial

This article is general information, not legal or professional advice — have your policy reviewed against your firm's circumstances. ComplyQS is not affiliated with or endorsed by RICS.