Write it so that any leader can read it once and know what to do. Include rules about data usage and privacy, model error tolerance by use case, latency budgets, cost budgets, where a human must be in the loop, what gets logged, and what triggers incident escalation. In the era of AI you should also specify what decision trails must contain, which prompts and responses must be stored, where data may reside, and how often model drift must be checked. If boundaries are vague, teams will optimise locally and create hidden risks. If boundaries are clear, teams will innovate inside known guardrails and audits will move faster because controls are inside the workflow.