Skip to main content
Valuemate Valuemate

Digital Services

Digital ServicesProactive IT management and SLAs Service DeskMultichannel IT support with AI Digital WorkplaceEnd-to-end workplace management Hardware SupplyDevice supply and logistics Professional ServicesStrategic ICT consulting IT StaffingIT professionals embedded in your teams

Cybersecurity

CybersecurityCompetence Center, 6 areas NIS2 & DORA ComplianceAssessment and regulatory governance Cyber-Risk ScannerSelf-assessment in 1 minute

Systems Engineering

Systems Engineering →

MBSE and systems engineering to govern complexity.

AI Services

AI ServicesApplied artificial intelligence AI-LABNewFree AI tools Valuemate NextNewInternal AI programme
Insights AI-LABNew Company Careers Contact us
IT|EN
Home  /  Company  /  AI Policy

AI Policy · V1.0

AI Policy

How Valuemate governs the development, adoption and use of Artificial Intelligence internally and in the services offered to clients, in line with Regulation (EU) 2024/1689 (EU AI Act).

Foreword

This AI Policy integrates and operationally specifies the AI ethical principles set out in Valuemate's Code of Ethics (sec. 4.3), in line with Regulation (EU) 2024/1689 (the EU AI Act) and consistent with the GDPR and the ICT risk management framework already adopted for NIS2.

It applies to all Artificial Intelligence systems developed, adopted or offered by Valuemate: internal tools supporting operations, AI features embedded in services (e.g. Service Desk, StockWave, AI-LAB), and solutions built for clients as part of AI Services.

1. Purpose and scope

The Policy defines accountability roles, risk classification criteria, human oversight requirements, transparency obligations and incident management procedures for the use of AI at Valuemate. It applies to directors, employees and collaborators, and, where relevant, to suppliers and partners who develop or integrate AI systems on the company's behalf.

2. Governance and accountability

2.1 AI Ethics & Governance Committee

Valuemate establishes a cross-functional committee (Legal, Compliance, DPO, CISO, Head of AI or technical lead) responsible for: approving the adoption of new medium- or high-risk AI systems; maintaining the register of active AI systems; overseeing periodic audits; validating human oversight procedures for the most critical use cases.

2.2 System owner

Every significant AI system has an internally identified owner, responsible for keeping its technical documentation up to date, monitoring its operation, and acting as the point of contact for anomalies or reports.

3. Risk classification

Before adoption, every AI system is classified according to a four-tier approach consistent with the taxonomy of Regulation (EU) 2024/1689:

  • Unacceptable risk: prohibited practices (e.g. subliminal manipulation, social scoring, emotion recognition at work). These are never developed or adopted under any circumstances.
  • High risk: systems affecting decisions about people in sensitive areas (e.g. personnel selection, performance evaluation). These require Committee approval, technical documentation, formalised human oversight and, where applicable, a Fundamental Rights Impact Assessment (FRIA) integrated with the DPIA.
  • Specific risk/transparency: systems that interact directly with people or generate content (chatbots, automated assistants, synthetic content). These require clear disclosure to users and, for generated content, labelling of its artificial origin.
  • Minimal risk: internal support tools with no direct impact on decisions about people (e.g. optimisation of technical processes). Subject only to the general rules of this Policy.

4. Human oversight

For every system classified as high or specific risk, Valuemate identifies by name the people responsible for supervision, who must: understand the system's capabilities and limitations; be able to correctly interpret its outputs; be able to decide at any time not to use the system, to disregard its output, or to halt its execution. No AI-assisted output is used operationally without human verification, consistent with what is already established in the Code of Ethics.

5. Transparency towards clients and users

When a client or user interacts with one of Valuemate's AI systems, or receives content generated by it, they are clearly informed, unless this is already evident from the context of use. Synthetic content intended for publication carries an indication of its artificial origin.

6. Data, security and non-discrimination

Data processed by AI systems follows the same confidentiality and protection principles already in force across the organisation (GDPR, NIS2 security measures). High-risk systems undergo bias assessment before adoption and periodic review, to identify and mitigate any discriminatory distortions.

7. Incident management

A malfunction, a clearly erroneous output, or a detected misuse of an AI system is reported to the system owner and, for high-risk or systemic cases, to the AI Ethics & Governance Committee, which assesses its impact and any corrective measures, in coordination with the incident management procedures already in place for cybersecurity.

8. Training

Valuemate promotes AI Literacy programmes tailored by role: governance and accountability principles for management; conscious use and bias awareness for operational staff; data security and prompt injection prevention for IT and cybersecurity.

9. Updates

This Policy is updated periodically to reflect regulatory developments (in particular the implementing decrees of Law 132/2025) and the technological evolution of the AI systems adopted. For the complete regulatory framework, see Valuemate's EU AI Act white paper (available in Italian).

Version V1.0, 23/07/2026 · Approved · Valid until a new version is issued.

Valuemate

Valuemate s.r.l.
Registered office: Corso Re Umberto 65, 10128 Turin, Italy
Operations: Corso Valdocco 2, 10122 Turin
Operations: Via Jervis 11/D, 10015 Ivrea (TO)

Company

  • About us
  • ESG
  • Whistleblowing
  • Careers
  • Why Valuemate
  • FAQ

White Papers

  • NIS2 White Paper IT
  • Digital Services White Paper
  • AI Enterprise White Paper
  • EU AI Act White Paper IT

AI Governance

  • AI Policy
  • AI Act Compliance
  • AI Notice
  • AI Transparency Policy

Contact

  • info@valuemate.it
  • Phone +39 011 088 6495
  • LinkedIn
  • Employee login
© 2026 Valuemate s.r.l., All rights reserved Whistleblowing (Italian Legislative Decree 24/2023) Privacy Policy · Cookie Policy · Terms of Use · Cookie preferences P.IVA 12682690016 · REA TO-1308407 · LEI 52990057QTCUFJENFO03 · Cap. Soc. i.v. €100.000 Valuemate®, registered trademark (UIBM reg. no. 302025000148969). All rights reserved.

We respect your privacy

We use technical cookies required for the site to work and, with your consent, analytics and third-party cookies to improve your experience. You can accept, reject or set your preferences. For details see our Cookie Policy and Privacy Policy.

Cookie preferences

Manage consent by category. Technical cookies are always active as they are required for the site to work. The others stay off until you enable them.

Technical and functional

Required for navigation and basic features (e.g. language and theme preference). No consent needed.

Analytics

Aggregated statistics on site usage (e.g. Google Analytics) to improve content.

Marketing and third parties

Profiling cookies and embedded third-party content (e.g. social, video, maps).