Using AI safely with site data

A one-page checklist to go through before any site data goes near an AI tool.

  1. 01

    Use your work account

    Sign in to Copilot with your organisation's account so enterprise data protection applies. Never paste site data into a personal or consumer AI tool.

  2. 02

    Check your site's AI policy first

    If your business has an AI or IT acceptable-use policy, it wins. If it doesn't, ask before you start.

  3. 03

    Anonymise before you upload

    Remove customer names, personal data, consumer contact details and anything commercially sensitive you don't need for the task.

  4. 04

    Give it the source, not your conclusion

    Upload the records and ask for structure, themes or gaps. Don't ask it to confirm what you already think.

  5. 05

    Verify against the source records

    Sample the output against the original records every time. Counts, dates and batch codes are where mistakes hide.

  6. 06

    Keep the decision human

    Root cause, CAPA, risk scoring, product release and anything a certificate depends on stay with a competent person.

  7. 07

    Don't let AI output become the record

    The controlled record is the one you've checked and approved. Keep the AI draft out of your document control system.

TFCD content is general guidance, not professional advice for your site. Always check requirements against your own licensed copy of the BRCGS Standard and your customers' codes of practice.