AI Policy for Research Agencies: Now a Written Requirement
An AI policy for research agencies stopped being optional. What the revised standard asks for, what the code makes you declare, and what the log has to hold.
A procurement form lands with a page nobody had to fill in last year. Describe your written policy on the use of AI and automation, and say how you check that it is followed. The proposal is due Friday. Somebody now has to decide whether an AI policy for research agencies is a document the firm already has, one it can write by Thursday, or a reason to drop the bid.
Key Takeaways
- The international standard for market research was revised and now requires a written AI and automation policy, with monitoring requirements attached. More than 400 agencies worldwide hold third party certification against it.
- The ICC and ESOMAR code requires in writing that the client be told when AI, synthetic data or synthetic personas enter a study, with a statement of how much human oversight there was.
- GreenBook's GRIT reports 44 percent of client side researchers and 42 percent of analytics professionals trusting that their own company controls AI misuse. Where the expectation is clear, that reads 68 percent against 32 percent where it is not.
- GRIT does not publish a sample size or a field period on the pages consulted, so those figures are directional and should not be quoted as precision statistics.
- Stanford HAI puts agent deployment in production below 10 percent in almost every business function, which is a useful check on anyone claiming their operation is already automated.
What the revised standard actually asks for
An AI policy is a written document saying where automated steps are used in your research process, what a person still decides, and how you check that both statements stay true.
The revision changed the kind of question a client can ask. Research Live reported the revision of the ISO 20252 standard, which added a written AI and automation policy to the requirements, with monitoring attached. More than 400 agencies worldwide hold third party certification against that standard.
Two things follow. The question stopped being a matter of opinion, because there is now a document behind it. And a buyer can ask for that policy by name, which is what the procurement page is doing.
Nothing here says an agency has to be certified. Certification is a separate claim. It rests on an audit, and no vendor can hand it to you.
How agencies answer the AI question today
PERSONAL EXPERIENCE Answer first: by writing the answer fresh, each time, in the proposal.
- A procurement form or a client question about AI arrives with a bid.
- Whoever is writing the proposal drafts a paragraph describing what the team does.
- That paragraph is checked with one or two people who know the tools.
- It goes out, and it is never filed anywhere the next proposal can find it.
- The next bid arrives, and somebody writes a slightly different paragraph.
The drift is the problem. Three proposals go out in a quarter, each describing the same operation differently, and none of them was wrong when it was written. Then a client compares two of them.
There is a second version. The agency has a policy, written once, and nobody has checked whether the tools in use today match what it says.
The pain, and who signs it
The cost is not writing the document. It is standing behind it.
Whoever signs the proposal is claiming that the process described is the process. In an agency that grew its AI use the way most did, tool by tool, with no register, that claim is a guess. A senior person is putting their name on a description of work they cannot fully see.
PERSONAL EXPERIENCE The sentence we hear is familiar in shape: we still do not have a list of what everyone is using. The word that gives it away is the same word clients use about spreadsheets and manual field control.
The exposure runs in two directions. A policy that overstates human oversight is a claim that fails an audit. A policy that understates AI use loses bids to agencies that describe theirs plainly.
What the industry reports about its own governance
What the industry says about its own AI governance
Five horizontal bars from GreenBook's GRIT research, followed by one from Stanford HAI. Among client side researchers, 44 percent trust that their own company controls AI misuse. Among analytics professionals the same question reads 42 percent. Where the expectation about AI use is clear, trust reads 68 percent. Where the expectation is not clear, it reads 32 percent, roughly half. And 67 percent of research suppliers already embed generative AI directly in what they deliver to the client. A caveat panel states that GRIT does not publish a sample size or a field period on the pages consulted, so these figures are directional and must not be quoted as precision statistics. The final bar, from Stanford HAI's AI Index, shows agent deployment in production sitting below 10 percent in almost every business function, which measures deployment rather than capability.
The 68 against 32 split is the one worth staring at. Stating the expectation is what moves the number, and stating it is what a policy does.
Answer first: the sector says its problem is governance rather than capability.
GreenBook's GRIT work on AI governance reports 44 percent of client side researchers and 42 percent of analytics professionals trusting that their own company controls the misuse of AI. Fewer than half, on both sides of the same building.
The split underneath is the useful part. Where the expectation about AI use is clear, trust reads 68 percent. Where it is not, 32 percent. Roughly double, from clarity alone.
Now the caveat, and it is not decoration. GRIT does not publish a sample size or a field period on the pages consulted, so every one of those figures is directional. Use them to frame a conversation, never as a precision statistic, and never as a projection onto the whole market.
What has to be declared to the client
Disclosure means telling the client, in the study documentation, that AI took part and how much a person supervised it.
That is a code duty now rather than a selling point. The ICC and ESOMAR code of conduct requires in writing that the client be told when AI, synthetic data or synthetic personas enter a study. It asks for a statement of how much human oversight there was. Reading that against a specific contract is work for your client's legal team, not for a vendor page.
It also stopped being an edge case. GRIT reports 67 percent of research suppliers already embedding generative AI in what they deliver. When two thirds of suppliers do it, the question moves from whether you use it to how you say so.
Synthetic personas are AI generated participants built from qualitative material. They are a different thing from synthetic data, which is generated records. The code names both, and so should your policy. We wrote about where personas hold up in [synthetic respondents and concept testing](/blog/synthetic-respondents-concept-testing).
What a written policy has to contain
The six parts of a written AI policy, and who signs each
A document structure drawn as six stacked sections, each with the question it answers and the role that owns it. One, scope: which studies and which client contracts the policy covers, owned by the managing director. Two, the stage register: for every stage of the research process, whether it is manual, assisted or automated, owned by the operations lead. Three, human decision points: the stages where a named person must approve before work continues, owned by the research director. Four, the client disclosure clause: the exact wording that goes into study documentation when AI, synthetic data or synthetic personas are used, owned by the research director. Five, the usage log: who ran what, on which project and for which client, recorded outside the tool's own conversation history, owned by the technology lead. Six, the review cadence: the date the register is checked against the tools actually in use, owned by the managing director. A note at the foot says that sections two and five are the ones agencies skip, and they are the two an auditor can verify.
Sections two and five are the auditable ones. A policy without a stage register is a statement of intent with a signature on it.
UNIQUE INSIGHT A policy that names no owner per section is a policy that will not survive its first audit.
The register in section two turns a paragraph into a document. Go stage by stage through the process, such as screener writing, script testing, field monitoring, coding, tabulation and reporting. Mark each one manual, assisted or automated. Anything you cannot mark is a stage nobody is watching.
Section three is where the standard's monitoring language becomes concrete. Consider script testing: the agent walks every path, and a named person approves the release to field. The rule we apply to our own builds is in [agent evaluation without an answer key](/blog/ai-agent-evaluation-without-an-answer-key).
The usage log people forget
Answer first: a chat history is not an audit trail.
Anthropic's engineering material argues that a durable record has to live outside the execution loop. Compacting and pruning context are one way decisions about what is kept. The conclusion carries straight over. If the only record of what an agent did lives inside the tool that did it, that record gets trimmed with the work.
A usage log is a separate, append only record of who ran which automated step, on which project, for which client, and on what date. It is the thing that answers a client's question a year later, when the person who ran the study has moved on.
This is also the gap clients describe to us directly. There is no control over what the team is doing, which is the same problem the [enterprise platform argument](/blog/why-chatgpt-is-not-a-research-platform) starts from.
Where Cassi.ai comes in
Cassi.ai is a software engineering company specialized in the pains of market research, innovation and insights, working with research agencies and corporate insights teams. We are not a certification body and we do not issue compliance opinions.
What we build is the plumbing a policy has to describe truthfully. The Super Agents line runs inside the client's own environment, on premises, in a private cloud or air gapped. Every step it takes writes to a record outside its own session, by user, project and client. That deployment choice is the subject of [open weight models and what the license allows](/blog/open-weight-models-in-market-research). The rest sits in the Cassi.ai portfolio.
What a policy cannot do for you
| The claim | What it needs | Who can give it |
|---|---|---|
| We have a written AI policy | The document, with owners named | Your own leadership |
| We are certified to the standard | A third party audit | An accredited certification body |
| We disclose AI use to clients | The clause in study documentation | Your research director |
| Our policy matches what we do | A stage register and a review date | Your operations lead |
| Our AI use is legally compliant | A reading of the code against your contracts | Your client's legal team |
The standard requirement comes from the Research Live report and the disclosure duty from the ICC and ESOMAR code. The split of who can give what is ours.
One more check before the confidence gets ahead of the operation. Stanford HAI's AI Index puts agent deployment in production below 10 percent in almost every business function. That measures deployment rather than capability, and it is a good reason to write a policy describing what runs today rather than what was demonstrated once.
FAQ
Does ISO 20252 now require an AI policy?
Yes. The revised standard added a requirement for a written policy on AI and automation, with monitoring requirements attached, as reported by Research Live. More than 400 agencies worldwide hold third party certification against the standard.
What has to be disclosed to a client about AI use?
That AI, synthetic data or synthetic personas were used in the study, and how much human oversight there was. The ICC and ESOMAR code puts that in writing. How it applies to a specific contract is a reading for your client's legal team.
What should an AI policy actually contain?
Six parts: scope, a stage register marking every research stage manual, assisted or automated, the human decision points, the client disclosure wording, a usage log, and a review date. Each part carries one named owner. The register and the log are the two an auditor can verify.
Is a chat history enough as an audit record?
No. Anthropic's engineering material argues that a durable record belongs outside the execution loop, since compacting and pruning context are one way decisions. A usage log recorded separately by user, project and client is what answers a question a year later.
How much do research buyers trust their own AI governance?
Less than half, on the industry's own numbers. GRIT reports 44 percent among client side researchers and 42 percent among analytics professionals. It reads 68 percent where the expectation about AI use is clear, and 32 percent where it is not. GRIT publishes no sample size or field period on those pages, so read them as directional.
The policy is not the point. The register behind it is, because that is the only part of the document a client can check against what your team actually did last quarter.
If a procurement page has already asked you this question, the useful hour is with your stage list and three people who run studies, marking each stage manual, assisted or automated. Whatever you cannot mark is what the policy has to fix before it can be written.
Published by Cassi.ai. Read the full article at https://www.cassiai.com/blog/ai-policy-for-research-agencies.