Member Trust First
Protect the privacy, security, and trust of members and partners.
A more engaging, web‑ready governance page—structured for clarity, trust, and quick scanning, inspired by modern governance layouts.
Scan‑friendly principles that anchor responsible AI at CUES. Each card can link to controls, SOPs, and tool guidance.
Protect the privacy, security, and trust of members and partners.
Align AI use with GLBA, GDPR, CCPA, and applicable regulations.
Communicate when and how AI is used; avoid misleading outputs.
AI outputs are advisory and require appropriate human review.
Use the least sensitive data required and apply privacy-by-design.
Obtain explicit consent and respect ownership and deletion requests.
Partner with regulators and members to evolve best practices.
Consider environmental impact and favor efficient solutions.
Click to expand. This layout is designed for modular web publishing and easy reading.
CUES embraces Artificial Intelligence (AI) — including Generative AI, Machine Learning and AI Agents — to improve operating efficiency and member engagement through safe, ethical and compliant use within our credit‑union association. This policy defines how AI is used responsibly with appropriate governance, privacy protections and security controls.
Our AI strategy is organized around two pillars:
This governance policy works together with the AI strategy: the strategy defines where AI creates value; the policy defines how AI is used responsibly.
Employees may use approved AI tools to:
Employees must not:
Data protection is central to maintaining member trust. The following controls apply:
CUES will manage AI risks through structured frameworks and adhere to relevant standards.
CUES recognises that AI-generated content may not be original. Employees must:
Oversight ensures that AI use is consistent with this policy and that accountability is enforced across the organization.
The IT Teamis an internal cross‑functional group. At minimum, representation includes:
Responsibilities:
CUES will continuously evaluate new AI risks and opportunities. The IT Team will update this policy in response to regulatory or technological changes. We will:
CUES uses approved meeting recording and note‑taking tools to support transcription, summarization and action‑item capture while applying strong privacy, consent and data‑handling controls.
Employees may use approved AI meeting‑recording tools for:
CUES will maintain a companion operational document (Meeting Recording & AI Note‑Taking SOP) that defines standard workflows, storage locations, consent templates, accessibility considerations and training guidance for staff.
CUES manages AI use through a structured, organization‑wide governance approach. This ensures AI is adopted intentionally, responsibly and in alignment with CUES’ mission, regulatory obligations and commitment to member trust.
For each AI use case, CUES requires clear documentation to support governance, oversight and accountability. Each use case must document:
CUES selects AI approaches based on business need and risk profile:
Note: The authoritative inventory is maintained in the AI Use Case Inventory. This appendix provides a snapshot for awareness and may change over time.
Used for development, personalization, and production AI solutions.
Used for building AI workflows, internal tools, and experimentation.
Used for training, marketing, and content production.
This policy references several supporting documents and resources. Internal links will be added to direct readers to these materials on the CUES intranet. Key references include:
---
Revision & Maintenance: This AI Governance Policy will be reviewed at least annually by the IT Team and updated as regulations, technologies and organizational needs evolve. Employees, members and partners are encouraged to provide feedback via the reporting channels outlined above.
A compact visual module for how AI initiatives move from idea → production → review.
Log the use case in the inventory.
Complete AIA/DPIA and required controls.
Department or Governance Committee review.
Monitor outcomes; modify, pause, or retire.
No—unless the tool and the specific use case are explicitly approved, secured, and documented for that purpose. Default to data minimization and approved environments.
Members/customers retain ownership of content created with their data. CUES does not reuse member data for model training without explicit consent.
Reports are reviewed by the IT Team, triaged for severity, and escalated as needed. Findings are incorporated into quarterly reviews and annual transparency reporting.