30 Days Gen AI Risk Trial -Start Now
Skip to main content
Policy in practice · Practical playbook

Review AI use when two organizations combine

A merger brings together more than two application lists. Each organization may have different AI accounts, approval assumptions and endpoint controls. Preserve those differences long enough to understand them, then review the new workflows created when people and information start crossing the former boundary.

For Integration leaders, CISOs and application portfolio owners

Synthetic example

Two approved-tool lists contain the same vendor

Both organizations use an assistant, but one has a managed workspace and the other permits limited personal-account research. Integration teams now want to summarize documents from both businesses together.

What you are working with

  • Both tool registers, approval rationales and account owners.
  • Endpoint deployment scope and known gaps on each side.
  • New workflows that combine information or connect shared systems.

A safer approach

  • Keep each approval's original scope visible during comparison.
  • Review combined-data tasks as new decisions.
  • Publish a temporary operating rule with an owner and review trigger.

Expected outcome: The integration team can continue defined work while security owners resolve account, data and control differences without silently broadening earlier approvals.

Put it into practice

Work through the procedure

  1. Collect records without flattening differences

    Bring the two inventories together with source labels and named owners. Include approved use, account arrangement, provider evidence and review dates. Two records with the same vendor name may describe different products or risk decisions; do not merge them into a single approved entry yet.

  2. Identify newly connected information

    Ask integration workstream owners which documents, systems and teams will cross the previous boundary. Separate public material from confidential integration plans and business records. Review the proposed use against the relevant data owners rather than assuming organizational combination authorizes every new AI submission.

  3. Define a workable interim arrangement

    Choose approved routes for immediate integration tasks and identify uses that need further assessment. Name who resolves conflicting policies and handles urgent exceptions. Make temporary rules discoverable to both workforces, including people whose devices have not joined the intended control deployment.

  4. Validate the future operating model

    Test representative tasks after account, identity or endpoint changes. Confirm which old workspaces and connections should remain, migrate or retire. Update the combined register with evidence and ownership, and keep unresolved exceptions visible until their actual implementation is checked.

Evidence before approval

What to check before proceeding

1. Earlier approvals retain their context

Ready when
The combined register preserves each original account and permitted use.
If the check fails
Recover the rationale before treating duplicate vendor names as equivalent.

2. New data flows have been reviewed

Ready when
Owners have evaluated tasks that combine previously separate information.
If the check fails
Use an approved narrower dataset or defer the combined submission.

3. Control coverage reflects the combined population

Ready when
Endpoint and account records identify which users are covered and which are not.
If the check fails
Maintain explicit interim instructions for the uncovered workflows.

Common mistakes to avoid

  • Assuming a tool approved by one business is approved for all information held by the combined organization.
  • Reporting a unified AI inventory while omitting acquired devices or accounts that have not entered the discovery scope.
Workforce AI Security

Evaluate this workflow with Aona

Where Aona can help

Aona's supported discovery and usage visibility can help inform the combined inventory where deployment is in place. Its supported policies can contribute to the chosen operating arrangement after the relevant workflows are configured and tested.

What to confirm

Aona does not merge provider accounts, interpret transaction agreements or automatically extend coverage to acquired endpoints. Organizational integration and data-sharing decisions remain with the responsible business and security owners.

Turning this policy into an operational rollout?

Discuss the teams, devices and AI tools in scope, who will own the policy, and which deployment and evidence requirements need to be met before rollout.

FAQ

Questions about this workflow

An interim authority is useful, but first understand the workflows and assumptions that differ. A policy choice needs implementation, account access and communication; publishing one document alone does not reconcile them.
Technical evaluation

Turning this policy into an operational rollout?

Discuss the teams, devices and AI tools in scope, who will own the policy, and which deployment and evidence requirements need to be met before rollout.

AI Security Review After a Merger | Aona AI