Recording and Transcription Policy

This Recording and Transcription Policy (“Policy”) establishes guidelines for the appropriate and responsible recording and transcription of meetings through tools including, but not limited to: features made available through, or integrated into, software and systems used by The Chartis Group, LLC (“Chartis” or “the Company”); generative artificial intelligence-based recording, notetaking, or transcription tools; and other third-party technologies (collectively “transcription tools”). The purpose of this Policy is to:

  • Protect individuals’ freedom to communicate and privacy rights;

  • Ensure the confidentiality of sensitive Company information, including Chartis’s trade secrets and intellectual property;

  • Comply with applicable state and federal laws;

  • Minimize potential legal risks for the Company and its colleagues.

This Policy is subject to change and may be supplemented by related standards or procedures as new developments and ethical considerations arise.

I.  Scope

This Policy applies to all colleagues, associates, contingent workers, interns or temporary staff, and other individuals working on Chartis’s behalf (collectively “Users”) who use transcription tools, including when attending in-person, telephonic, online, and/or video Company meetings (including internal team meetings, client meetings, training sessions, and webinars and virtual conferences) where such tools may be used. This Policy applies to both Company-hosted meetings and any external meetings conducted on Company devices, colleague personal devices, networks, or accounts, or for authorized business purposes.

This Policy adds to – does not contradict, limit, or replace – applicable mandatory rules, standards, internal controls, legal requirements, contractual obligations, or other Company policies, such as the Chartis AI Policy.

II.  Use of Transcription Tools Generally

The use of transcription tools to record or transcribe meetings is prohibited except as outlined in this Policy.

Chartis only permits the use of those transcription tools that are included on the Information Technology Security approved for Chartis list.  Approved tools must meet Chartis' security, privacy, and compliance requirements, be covered under a valid enterprise or commercial license, and be authorized for use by Information Technology. Only colleagues who have completed any required training and received appropriate authorization may use approved transcription tools. Personal accounts, personal subscriptions, or individually purchased applications may not be used for Chartis business.

Meetings should not be recorded or transcribed unless (1) a clear business, legal, or compliance justification exists, and (2) each attendee’s prior consent is obtained by providing notice and an opportunity to object. Meeting organizers are responsible for ensuring compliance with consent, notification, and retention requirements under this Policy.

A “clear business, legal, or compliance justification” exists only for the following purposes:

  • Accessibility accommodation: to support a participant with a disability or accessibility need, such as hearing impairment or cognitive processing challenges. Use for accommodations must comply with applicable disability and privacy laws and be coordinated with HR as needed.

  • Training: for creating or sharing training materials that support colleague development, onboarding, or operational instruction.

  • Absence of a key decisionmaker or executive: when a critical participant, such as a senior leader or decision maker, cannot attend the meeting and needs to review the discussion to stay informed or make timely decisions.

  • Drafting and refining emails, reports, documents, proposals, and communications, as well as meeting notes and action items.

  • Language support and translation: to provide translations of meetings into another language for Users who speak a language other than the language in which the meeting is being held. Real-time translation may be used where necessary for cross-lingual collaboration, but meeting organizers must still comply with notice and consent requirements.

  • Other business needs: to support a specific operational, legal, or strategic objective not covered by the listed categories, such as where a business record is needed. These situations require a legitimate, documented business justification and prior approval from HR.

Users must anonymize or otherwise de-identify confidential, proprietary, or sensitive information whenever possible before using transcription tools to process the information. All Users are expected to maintain client and Company confidentiality and to adhere to applicable data privacy laws and regulations, as well as Company policies and data privacy and security measures. 

The obligation to maintain confidentiality requires that confidential information not be released to parties outside of the Company. Accordingly, transcription tools may not be used in any meeting, or any portion of a meeting, during which confidential or privileged information will be discussed. 

Attorney-client privileged or work-product information must not be recorded or transcribed absent prior approval from Legal, and if approved, must follow Legal’s prescribed safeguards.

All transcriptions and recordings must comply with any other applicable and related privacy, legal, and HR policies, including with respect to retention. If this Policy conflicts with a more specific policy, the more restrictive requirement applies.

III.  Prohibited Uses

The use of transcription tools is prohibited in the following instances:

  • If any participants do not consent to its use

  • During any meeting involving Human Resources or employee matters. This includes, but is not limited to, meetings related to recruiting, interviewing, hiring, onboarding, performance management, disciplinary actions, investigations, leaves of absence, accommodations, compensation discussions, and employment separation. The use of transcription tools in any Human Resources or employment-related context is not permitted unless prior written approval has been obtained from Human Resources for a specific, documented business purpose with appropriate safeguards in place.

  • If any participant resides in a jurisdiction with heightened data protection standards, such as those covered by GDPR (e.g, the European Union of UK).

  • When Sensitive PII and/or large amounts of PII are likely to be discussed.

  • In a manner that is illegal, unethical, or violates the rights of any individual or entity, or knowingly generates content that misleads, deceives, or causes harm. 

  • To record personal conversations or content that does not pertain to work.

  • To produce content that is discriminatory, offensive, or harmful to individuals or groups.

If any of the prohibited uses listed above arise unexpectedly during a call, transcription should be paused or stopped for the duration of that discussion. For example, if legal advice is requested during a call, transcription should be paused or stopped immediately and for the duration of that discussion. Always exercise your business judgement before enabling AI Transcription for any meeting. When in doubt, turn off AI transcription.

IV.  Mandatory Transcription for Certain Functions

The Company may designate specific meeting types or business activities as requiring recording and/or transcription to meet legal, regulatory, contractual, quality, safety, or operational requirements, for example: (i) regulatory or compliance audits and examinations; (ii) product safety, incident, or crisis reviews; (iii) SOX or external reporting checkpoints; (iv) customer or supplier negotiations where commitments are made; (v) Board and Committee meetings where minutes require source validation; and (vi) other meetings or business activities expressly identified by Legal, Compliance, Information Technology or firm leadership  When a meeting has been designated for recording and/or transcription, meeting organizers are responsible for ensuring the required recording or transcription is enabled and that participants are notified in accordance with applicable laws and Firm policy.

V.  User Responsibilities and Expectations

A. Notification of Attendees

Users should have no expectation of privacy when attending meetings that may be recorded and/or transcribed. Users who do not wish to be recorded may state that they do not consent to the recording. Depending on the circumstances, Users may choose to exit the meeting, or the recording will be terminated, except where the meeting has been designated for Mandatory Transcription under Section IV and a lawful accommodation is available where required by law. Users present at the meeting who have been informed of the recording and continue to participate are deemed to have consented to the recording, as well as the collection and use of their data as stated in this policy and Colleague Privacy Notice.

In using transcription tools, Users are required to:

  • Exercise caution in uploading or transmitting material to the approved AI Transcription tool to avoid unauthorized disclosure of an individual’s or the Company’s confidential information, including PII or any information that may be identifiable to the Company, a customer, or a third party.

  • Only activate transcription tools after notifying meeting attendees (whether by including notice in the meeting invite, verbally, or otherwise). 

  • Immediately notify anyone joining a meeting virtually or in person that an in-progress meeting is being recorded and/or transcribed, including utilizing tools or functionalities to record Company meetings that include a visual feature (such as a “You are being recorded” message or on-screen icon) that notifies participants they are being recorded.

  • Immediately end the use of transcription tools if any attendees object to the recording and/or transcription of the meeting, unless the meeting has been designated “Mandatory Transcription” under Section IV. In that case, the organizer must consult Legal/HR to identify a lawful accommodation (e.g., non-speaking attendance, separate non-recorded session) or reschedule. 

  • Maintain the confidentiality of all Company and client information. Do not capture sensitive personal data (e.g., SSNs, health data) unless strictly necessary, legally permitted, and approved by Legal/Privacy.

Users may not share recordings and transcriptions outside of the original meeting audience except for purposes permitted in this Policy and with prior approval from Human Resources or Compliance or with the documented consent of all original meeting attendees. Before sharing recordings and transcriptions, Users must consider whether anything was discussed during the meeting that would not be appropriate to share (e.g., personal information, trade secrets, confidential projects, etc.) and redact that information as appropriate.

B. Verification of Outputs

Users must exercise caution because there is no guarantee regarding the reliability of content generated by AI-enabled transcription tools. AI transcription tools sometimes “hallucinate,” meaning they create content that was never stated. If circulated without review, hallucinations can misrepresent what occurred, create false commitments, or cause confusion about responsibilities. Accordingly, Users using AI transcription tools are responsible for independently reviewing all outputs to ensure their accuracy and reliability prior to use by the Company. Users must ensure Chartis has all rights to use the data generated by Teams and other AI transcription tools.

To mitigate these risks and ensure consistency, the following requirements apply whenever AI transcription or notetaking tools are used:

  • Draft Status Only. Any transcription, summary, or action items created by AI tools are considered drafts. They are not official records of any meeting or discussion.

  • Mandatory Validation. Before AI outputs are shared or relied upon for decision-making, they must be validated against the actual discussion and/or inputs, such as by reviewing the transcript, recording, or personal notes. Validation requires checking the accuracy of names, deadlines, numbers, and decisions.

  • Data Minimization and Scrubbing. Before any transcript, summary, or notes are shared or stored, Users must remove or redact confidential or irrelevant personal information (e.g., Social Security numbers, financial account numbers, health information, home addresses) and limit outputs to what is necessary for the business purpose. If retention of such data is legally required, document the basis and apply Company-approved safeguards.

  • No Unverified Commitments. AI-generated notes may not be used to confirm decisions, commitments, or obligations unless explicitly validated by the meeting participants.

  • Retention of Source Record. Records must be stored in approved, access-controlled systems and deleted promptly once validation is complete or the information is no longer required, or as otherwise required by the Company’s record retention requirements. Users must not download, export, or store transcripts or recordings on personal devices or unapproved platforms.

  • Responsibility for Accuracy. The User circulating meeting notes, summaries, or other content generated by AI transcription tools remains responsible for accuracy, regardless of AI use.

  • Respect for Intellectual Property. Certain AI transcription tools may incorporate content that requires a license or other authorization from a patent or copyright holder for lawful use. Users must ensure that such content is not included in materials shared outside of the Company without first acquiring any necessary licenses or other authorizations from the applicable rights holder. Users must adhere to intellectual property and copyright laws when using AI transcription technologies. If a User is unsure whether a particular use of an AI transcription tool violates intellectual property rights or constitutes copyright infringement, they should contact a member of the Compliance team for guidance.

C. Ethical Use of AI Transcription Technologies

AI transcription tools must not be used for creating, spreading, or promoting malicious, harmful, or offensive content, including hate speech, discriminatory language, or false information, or content that violates any applicable laws or regulations. AI transcription tools must not be used to generate misleading, biased, or inappropriate content. Any content generated using AI technology tools should align with the Company's vision, values, ethical standards, and all other Company policies describing appropriate conduct in the workplace. 

VI.  Data Retention and Recordkeeping

Users acknowledge that transcription tools such as Teams may store their interactions to improve the tools’ performance and refine Users’ experience. With respect to approved transcription tools, this information will not be shared with the relevant transcription tool vendor and will remain within the Chartis environment. When used in a meeting context, by default, if transcription is turned on, transcripts are accessible to everyone within Chartis who was invited to the meeting, as well as meeting organizers and designated management personnel. Guests and external attendees can only view a recording if they are sent a direct link to the recording. Recordings and transcripts should be retained only for as long as necessary to fulfill the purposes for which they were created, and for any periods required by law. Recordings and transcriptions are otherwise stored in accordance with Chartis's standard retention practices. 

VII.  Enforcement

Chartis reserves the right to monitor the use of transcription tools, whether specifically licensed by the Company for the User’s role, used on Chartis equipment, or used by an individual in the performance of their role.

Any violations of this Policy or improper use of transcription tools could be subject to corrective action up to and including termination of employment. If a User becomes aware of or reasonably suspects a violation of this policy, it should be reported to an appropriate supervisor or to the Human Resources Department. Suspected security or privacy incidents must be reported immediately to Compliance pursuant to the Company’s Incident Response Plan.

VIII.  Non-Interference with Applicable Laws 

Nothing in this Policy should be construed to prevent or restrict lawful personal conduct during nonworking hours, or to prohibit or infringe upon any right, activity, or practice protected under applicable state or federal law, including recordings made by colleagues under whistleblower protections, labor-rights protections (including under Section 7 of the National Labor Relations Act), or when reasonably necessary to document unlawful conduct or protect legitimate legal rights, provided that the disclosure does not exceed the extent of disclosure protected by such law, regulation, or order. This may include, for example, documenting unsafe working conditions or hazards, recording uneven application of workplace rules, capturing evidence for use in employment-related actions (such as conversations revealing discrimination), recording discussions about terms and conditions of employment, and other protected activities. Colleagues with concerns or questions about permissible recordings should contact Compliance,

Users shall not be held criminally or civilly liable under any Federal or State trade secret law for the disclosure of a trade secret that: (a) is made (i) in confidence to a Federal, State, or local government official, either directly or indirectly, or to an attorney, and (ii) solely for the purpose of reporting or investigating a suspected violation of law; or (b) is made in a complaint or other document filed in a lawsuit or other proceeding, if such filing is made under seal. 

IX.  Contact

If you have questions or complaints about this Policy, please contact a member of the Compliance team. Questions about tool configuration, access, or retention should be directed to IT; questions about legal requirements, consent, and privilege should be directed to Legal.

X.  Exceptions and Amendments

As AI is a rapidly changing and evolving area, this Policy is subject to periodic updates or amendments based upon advances in technology and data security, ethical guidelines, and legal standards in this area. 

The Company may approve an exception to or revise this Policy. All amendments and/or exceptions shall be promptly disseminated to all Company employees.

XI.  Violations

Violations of this Policy may result in disciplinary action, up to and including termination, legal action, reports to Company regulators, and/or, in cases that may involve violations of criminal law, reports to law enforcement. Violations may be reported to compliance or human resources.

XII.  Acknowledgement

By using transcription tools, Users acknowledge that they have read, understand, and will comply with this Policy.

Contact Us

Get in Touch

Let us know how we can help you advance healthcare.

Contact Our Team
About Us

About Chartis

We help clients navigate the future of care delivery.

About Us