Kirameki
Governance and policy setup — written rules, clear boundaries, structured oversight

Service 03 · Five Weeks · ¥31,000

Written rules for how your organisation uses AI tools — before those tools create problems that are harder to address

The Governance and Policy Setup engagement produces a written policy suited to your organisation's size, a staff briefing session, and a register template for tracking the tools in use — all completed in five weeks, with legal, technical and operational input throughout.

What this delivers

At the close, your organisation has written rules it can actually point to and apply

When staff begin using AI tools without any formal guidance, the organisation is in an uncertain position. It may not know which tools are in use, what data is being entered into them, or how the output is being relied upon in decisions. That uncertainty carries risk — compliance risk, confidentiality risk, and the more ordinary risk of staff making inconsistent choices because no agreed standard exists.

This engagement establishes that standard. The output is a written policy that fits your organisation's situation — not a generic template — along with a briefing session so staff understand what it requires of them, and a register template so the tools in use are tracked and visible going forward.

The engagement draws on legal, technical and operational input across its five weeks. The result is a policy that is grounded in how your organisation actually works, rather than one that looks complete on paper but is disconnected from practice.

Written policy

Tailored to your organisation's size, sector, and the tools already in use. Covers approved applications, data boundaries, review requirements, and record keeping.

Staff briefing session

A structured session in which the policy is explained to staff — what it requires, what it permits, and how questions or edge cases should be handled.

Register template

A template for tracking which AI tools are in use, by whom, and for what purposes — so the policy can be maintained and reviewed as tools change.

Legal, technical, operational input

The engagement draws on perspectives from all three areas throughout. The policy is not written from one angle only.

The situation many organisations are in

Staff have often begun using AI tools well before any policy exists to guide that use

The adoption curve for AI tools in everyday work has been steep. Writing assistants, summarisation tools, and code generation utilities have moved into professional use faster than most organisations have been able to consider their implications. The result, in many workplaces, is a situation where tools are in active daily use but no one has formally decided which ones are sanctioned, what information may be entered into them, or how their output should be treated when it feeds into a decision.

This is a practical problem before it becomes a compliance one. Staff working without clear guidance make inconsistent choices — entering data into external services that were never cleared for that purpose, relying on output without knowing whether it should be checked, or avoiding tools altogether out of uncertainty about what's permitted.

A written policy removes that ambiguity. It does not have to be restrictive to be useful. It needs to be clear, to reflect the organisation's actual situation, and to be explained to the people it applies to.

No visibility over tools in use

Without a register, management cannot know which AI tools staff are using or what data is being processed through them.

Unclear data boundaries

Staff do not know which categories of information may or may not be entered into external AI services. They make individual judgments in the absence of guidance.

No review standard for AI output

When AI-generated content feeds into a document or decision, there is no agreed standard for whether or how it should be checked before use.

The approach

Five weeks with legal, technical, and operational input at each stage

The engagement does not produce a policy by filling in a template. It builds one from the organisation's actual situation, drawing on perspectives from different parts of the work.

01

Current state review

We establish which tools are currently in use, in what contexts, and what — if any — informal guidance already exists. This forms the basis for everything that follows.

02

Policy drafting

A draft policy is produced covering approved applications, data that may not be entered into external services, review requirements for output, and record keeping obligations.

03

Review and finalisation

The draft is reviewed with legal, technical and operational input. Adjustments are made. The final version is confirmed with your team before the briefing session is scheduled.

04

Briefing and handover

A staff briefing session explains the policy in plain terms. The register template is delivered. Your organisation has everything it needs to begin applying and maintaining the policy.

Working together

What five weeks of governance work looks like in practice

The engagement begins with a set of structured conversations — with staff who use AI tools in their work, with whoever handles compliance or legal questions in the organisation, and with anyone responsible for technical systems. These conversations are not long, but they produce a much clearer picture of the actual situation than any assumptions about it would.

From that picture, a draft policy is produced in week two. It is not a generic document with your name inserted — it reflects the specific tools your staff are using, the data those tools interact with, and the review requirements appropriate to your sector and size. You review it, and adjustments are made in week three based on your feedback and any further legal or technical input needed.

Weeks four and five cover finalisation, the staff briefing, and handover. The briefing is structured so that it is practical rather than cautionary — staff leave understanding what is permitted, what is not, and how to handle situations that are not clearly covered. The register template is provided alongside the policy so that tracking tools in use becomes a routine part of how the organisation operates.

The engagement is conducted in English or Japanese. For organisations where staff work in both languages, the briefing can be delivered in either or both.

Week 1

Current state review. Conversations with staff, legal, and technical leads. Tools in use identified. Existing informal guidance noted.

Week 2

Draft policy produced. Covers approved tools, data categories, review standards, and record keeping. Provided to your team for review.

Week 3

Review with legal, technical and operational input. Adjustments made. Final version agreed with your team.

Weeks 4–5

Staff briefing session delivered. Register template provided. Policy and all supporting materials handed over. Engagement complete.

Investment

¥31,000 for the full five-week engagement

This covers the current state review, policy drafting and finalisation, the staff briefing session, and all deliverables. There are no ongoing costs attached to the engagement.

What's included

  • Structured conversations with staff, legal, and technical leads
  • Current state review identifying tools in use and existing informal guidance
  • Written policy tailored to your organisation's size and situation
  • Legal, technical and operational review of the draft policy
  • Revision based on your team's feedback before finalisation
  • Staff briefing session in English or Japanese (or both)
  • Register template for tracking AI tools in use going forward
  • All materials delivered in editable formats your team can maintain

Cost structure

Current state review Week 1
Policy drafting and review Weeks 2–3
Briefing session and handover Weeks 4–5
Total fixed fee ¥31,000

No recurring costs. Editable deliverables. Payment terms discussed on enquiry.

Who this suits

Organisations where staff have begun using AI tools without any formal policy in place, or where a policy exists informally but has not been written down, reviewed legally, or communicated clearly to staff.

Measurement framework

What the policy covers and how its completeness can be assessed

The policy is not measured by length or complexity. It is measured by whether it addresses the areas that create risk and whether staff who have read it can answer the questions that arise in their daily work.

Policy area Measured before Measured after
Tools in use Undocumented — known partially or not at all Registered in the tracking template, with approved status noted for each
Data boundaries No documented guidance on what may be entered into external services Written categories of permitted and restricted data, referenced in the policy
Output review standard Individual judgment — inconsistent across staff and teams Defined review requirements for output used in decisions, written into the policy
Staff awareness Variable — some staff aware of risks, others not Briefing delivered, questions addressed, policy available for reference

Editable deliverables

The policy and register template are delivered in formats your team can update as the tool landscape and the organisation's situation change.

Proportionate scope

The policy is written to match your organisation's actual size and situation. It is not designed to be more complex than necessary to address the risks that are present.

No software sold

Kirameki does not benefit from recommending or restricting specific tools. The policy reflects your situation, not a preference for any particular product.

How we approach commitment

The policy is yours to use, adjust, and maintain — without depending on us to do so

The deliverables from this engagement are written so that your organisation can maintain them independently. The policy is not encrypted or locked to any format. The register template works in any standard spreadsheet application. The briefing materials can be reused if new staff join and need to be brought up to the same level of understanding.

The engagement also includes a revision round before finalisation. If the draft policy does not accurately reflect how your organisation works, or if it covers areas that are not relevant to your situation, those adjustments are part of the engagement, not a separate cost.

An initial conversation is available before any commitment. If you're uncertain whether your organisation has a policy problem — as opposed to a different kind of AI-related question — that conversation is a reasonable starting point, and it carries no obligation.

One revision round included

If the draft policy needs adjusting after your team reviews it, those changes are part of the engagement at no additional cost.

Maintained by your team going forward

All materials are delivered in editable formats. You do not need to return to Kirameki to update the policy or register as circumstances change.

No-obligation initial conversation

Before committing, you can speak with us about your organisation's situation. We'll tell you honestly whether this engagement addresses what you're describing.

How to proceed

Five weeks from a starting conversation to a policy your staff have been briefed on

The path to a completed governance engagement is short and requires relatively little from your team in terms of preparation — mainly access to the people and information we need in week one.

01

Send a message

Describe what you know about the situation — which tools staff are using, whether any informal guidance exists, and whether there are particular areas of concern. Any amount of detail is a reasonable starting point.

02

Initial conversation

We'll discuss your organisation's situation in enough detail to confirm that a governance engagement is the right approach. If a different service would be more useful, we'll say so.

03

Engagement begins

We agree a start date and identify who we'll need to speak with in week one. The five-week engagement runs from there, with the policy and register in your hands by the close.

Governance and Policy Setup

If your staff are using AI tools without clear written guidance, a conversation is a reasonable place to start

The initial conversation is without charge and carries no obligation. We can tell you whether what you describe sounds like a governance problem and whether this engagement would address it.

Five weeks · ¥31,000 · Tokyo consulting, Japan · info@domain.com

Cookie preferences

Essential cookies

Always active — required for the site to work.

Always on

Analytics cookies

Help us understand how pages are used.

Marketing cookies

Used for advertising and personalisation.

Personalisation cookies

Remember preferences for your visits.