AI Policy

Our commitment to responsible AI

Obizmax is committed to using artificial intelligence (AI) responsibly to support our consulting, training, digital marketing and business services. Our aim is to create practical value while protecting the interests of our customers, learners, website visitors and other people affected by our work.

This policy draws on ISO/IEC 42001:2023, the international standard for AI management systems. It sets out our intended commitments; it does not represent a claim of certification or verified conformity with the standard.

1. Scope and purpose

This policy applies to AI used by Obizmax, and by people acting on our behalf, in customer services, project delivery, training, content creation, analysis and website interactions. Where an AI feature or service is offered, its specific terms and privacy information also apply.

Our objectives are to improve the usefulness and quality of our services, manage AI risks, maintain appropriate human oversight and continually improve our approach.

2. Accountability and human oversight

Obizmax management will oversee this policy, assign responsibilities for AI use and ensure that relevant personnel receive appropriate guidance and training. Responsibility for our work remains with Obizmax, even when AI assists its preparation.

We will apply human review proportionate to the intended use and potential consequences. Decisions that could materially affect an individual will require appropriate human oversight and a route for raising concerns. Customers may request human clarification of AI-assisted service outputs.

3. Risk and impact assessment

Before introducing an AI use case, or making a significant change to one, we will assess its intended purpose, limitations and foreseeable risks. This includes potential effects on privacy, security, accuracy, fairness, intellectual property and affected individuals or groups.

We will select safeguards according to the level of risk, evaluate whether the use is appropriate and restrict or stop an AI use where risks cannot be adequately managed.

4. Transparency and appropriate use

We will provide clear information when customers or visitors interact directly with an AI system, and disclose material AI involvement where it affects how a service or deliverable should be understood. We will explain relevant limitations in language appropriate to the audience.

We will not knowingly use AI to mislead people, impersonate someone without authorization, produce unlawful discriminatory outcomes or create deceptive content.

5. Privacy, confidentiality and data protection

We will comply with applicable legal, regulatory and contractual requirements, including relevant personal data protection obligations. We will limit information used with AI to what is necessary for the agreed purpose and apply appropriate access and security safeguards.

We will not submit customer confidential information or personal data to an AI provider without an appropriate basis, authorization where required and a review of the relevant provider terms and safeguards. Use of customer information to train or fine-tune an AI model will require a separately agreed basis and appropriate protections.

Please avoid entering sensitive information into an AI-enabled website feature unless it is specifically designed and authorized to receive that information. This policy supplements our applicable privacy notices and customer agreements.

6. Quality, fairness and intellectual property

AI outputs can be inaccurate, incomplete or biased. We will check important factual claims and review customer-facing outputs according to their intended use. We will consider foreseeable bias and accessibility needs when selecting and evaluating AI applications.

We will respect intellectual property rights and assess permissions and licensing requirements for source materials and AI-assisted deliverables. We will not promise that every AI-generated output is unique or suitable for exclusive ownership.

7. Third-party AI providers

Where we use third-party AI services, we will evaluate their suitability, relevant security and privacy terms, data handling and known limitations. We will clarify responsibilities with customers and suppliers where AI forms part of a project. Third-party systems remain subject to their own terms and technical limitations.

8. Monitoring, concerns and corrective action

We will monitor significant AI uses, retain appropriate records and investigate reported errors, misuse or harmful outcomes. Where needed, we will correct outputs, adjust safeguards or suspend the affected use. We will communicate material incidents to affected parties where required by law, contract or the circumstances.

Visitors and customers can raise an AI-related question or concern through the contact channels on this website or their usual Obizmax representative. Please identify the relevant service or content and describe the issue without including unnecessary sensitive information.

9. Objectives and continual improvement

Management will establish and review measurable AI objectives appropriate to our services, such as output quality, staff competence, risk treatment and the handling of customer concerns. We will use reviews, feedback and incident findings to improve our AI management practices.

We will review this policy at least annually and after significant changes to our AI activities or applicable requirements. The approved version and effective date will be recorded when this policy is adopted.

Reference: ISO/IEC 42001:2023 — Artificial intelligence management systems.