# AI spending policy template

Prepared by SpendAssure: https://www.spendassure.com/guides/ai-spending-policy-template/

Editable operational starting point. Adapt and approve it within your organisation.
This template is not a legal compliance policy or a statement of product availability.
Replace all bracketed fields before adopting it. Sample thresholds are deliberately omitted.

## Policy owner and review

- Organisation: [name]
- Policy owner: [name and role]
- Approving authority: [name and role]
- Effective date: [YYYY-MM-DD]
- Review cadence: [cadence]
- Next review: [YYYY-MM-DD]
- Version and evidence location: [reference]

## 1. Scope

Included provider organisations, projects and enterprise workspaces:
[list resource identifiers, billing sources and owners]

New or unverified resources are recorded separately until reviewed.
The inventory does not guarantee discovery of all accounts.

## 2. Responsibilities

- Operational owner: explains usage, maintains resource mapping, requests changes.
- Budget approver: approves amount, currency, period and scope.
- Technical operator: applies authorised changes and verifies the result.
- Finance reviewer: reviews actual spend, forecasts, control coverage and unresolved gaps.
- Backup owners: [roles and escalation contacts]

## 3. Required resource record

For every included resource retain:

- Provider, product and resource identifier.
- Operational owner and budget approver.
- Approved budget, currency and period.
- Applicable parent controls and any overlapping scope.
- Configured provider control and material exclusions.
- Control class: Contractually bounded / Provider-capped / Velocity-bounded / Unbounded.
- Evidence source: API-observed / manually attested / other (describe).
- Evidence date, author and next review.
- Alert recipients and expected response.
- Operating floor and service-impact considerations.
- Next decision and responsible owner.

A budget approval is separate from a provider enforcement setting.
Show forecasts as estimates. Do not aggregate overlapping parent and child controls.

## 4. Change request

Request identifier: [reference]
Resource: [identifier]
Current approved budget/control: [amount, currency, period, scope]
Requested budget/control: [amount, currency, period, scope]
Business reason: [reason and expected workload]
Production/service effect: [impact and escalation]
Temporary exception: [yes/no; expiry or review date]
Requester: [name]
Approver and decision: [name, approve/deny, date, conditions]
Technical operator: [name]
Execution status: [not started / pending / executed / failed]
Observed setting and verification date: [evidence]
Follow-up owner and date: [record]

Approval, execution and verification are separate steps.

## 5. Authority and service continuity

Increases require approval by [authority].
Reductions must respect the locally authorised operating floor [record per resource].
Service-stopping actions require [explicit local approval or defined emergency rule].
Irreversible actions are never automated.
An alert alone does not authorise an increase, shutdown or key revocation.
Emergency escalation contacts: [roles and channels].

## 6. Evidence and exceptions

Manual attestations identify the person, value, resource, date and evidence.
Review them after [period; SpendAssure proposes 30 days by default].
Conflicting evidence invalidates reliance pending review.
An attestation does not create or verify enforcement.
Record unresolved gaps and service exceptions with an owner and review date.

## 7. Monthly review

- Assign owners to new resources.
- Hand over resources owned by departing staff.
- Review changed settings and expiring exceptions.
- Investigate unallocated spend and stale evidence.
- Separate actual spend, forecast, budget authority and control coverage.
- Preserve source currency; explain any conversion.
- Give each gap an action, owner and next review date.

## 8. Enforcement limitations

Provider caps retain their documented delays and overshoot behaviour.
A rate is a speed limit, not a ceiling; show the daily equivalent beside an hourly amount.
Uncovered material billable dimensions remain visible.
A guaranteed maximum may be stated only for a defined contractual scope covering all relevant charges.
