← Policies & standards

Information Security Policy

Updated for AI-enabled services and Microsoft cloud governance

Applies to: The Freethinking Group, Republic of Media, Numodo and Intelligence22 Version: 0.3 Updated: 06 August 2026 Next review: 06 August 2027 or following material change

1. Purpose

This policy protects TFG information assets against internal, external, deliberate and accidental threats. It supports confidentiality, integrity and availability through an Information Security Management System aligned to ISO/IEC 27001:2022 and applies existing controls to cloud, automation and AI-enabled services.

2. Scope

This policy applies to all TFG operating companies, personnel, locations, managed devices, information assets and business systems. It includes Microsoft 365, SharePoint, OneDrive, Teams, Exchange, Azure and Entra ID; campaign platforms; reporting and automation services; potent.ai; approved AI agents; prompts, instructions, knowledge sources, retrieval indexes, model outputs and audit records.

3. Governance and accountability

The Board provides oversight. The Senior Leadership Team supports implementation. The Group Operations Director / ISMS Lead owns the ISMS. The Information Security Function, supported by Simplify IT, maintains controls and monitoring. Information Asset Owners approve appropriate use and access. Product or Agent Owners are accountable for AI-enabled services throughout design, testing, deployment, monitoring and retirement.

4. Core security requirements

Least privilege, role-based access, business need and controlled joiner/mover/leaver processes.

Multi-factor authentication and approved identity controls for in-scope services.

Information classification and handling rules applied to prompts, knowledge sources, outputs and logs.

Encryption in transit and at rest where appropriate to risk, legal and contractual requirements.

Logging, monitoring and periodic access review for critical services and privileged access.

Data minimisation, purpose limitation and retention controls for client and company information.

Supplier and sub-processor due diligence before access to in-scope information or systems.

Controlled change, testing, rollback and approval for material system, data and AI changes.

5. AI and agent security

AI-enabled tools and agents must be approved before business use. Each service must have a named owner, documented purpose, approved data sources, access boundaries, risk assessment and lifecycle status. Agents must not receive broader authority than required. Human approval is mandatory before high-impact client, regulatory, financial, employment or public outputs are acted upon.

Confidential, restricted, special-category, credential, security-sensitive or client-prohibited information must not be entered into unapproved AI tools. Prompt injection, unsafe tool execution, data leakage, excessive permissions and unverified output are treated as information-security risks and must be tested and monitored.

6. Microsoft-aligned controls

Use Entra ID identities, least privilege and managed access for approved Microsoft AI services.

Apply Microsoft 365 permissions and information-protection controls to source content before enabling Copilot or agent access.

Use Microsoft Purview capabilities, where licensed and configured, to support classification, retention, audit, data loss prevention and AI data-security oversight.

Use Defender, Azure Monitor, Application Insights or equivalent approved monitoring where relevant to the service architecture.

Do not claim a Microsoft control is active unless it is licensed, configured, tested and evidenced.

7. Incident management

Suspected information leakage, prompt injection, unauthorised agent action, inappropriate output disclosure, credential compromise, model or connector misuse, or unexpected access must be reported immediately and managed under the Incident Response Plan.

8. Assurance and review

The ISMS is monitored through risk review, internal audit, access review, supplier review, incident review, technical monitoring and management review. This policy is reviewed annually and following material legal, contractual, technical or risk change.

CERTIFICATION WORDING Republic of Media Limited holds ISO 27001:2022 certification for communications planning, media planning and buying, digital media planning and buying, and media research services. Broader TFG policy scope must not be represented as the certification boundary unless confirmed by the certificate and auditor.