August 27, 2026
Russell Reynolds Associates, Inc. and its group companies around the world (collectively “RRA,” “we,” or “our”) are committed to using AI Tools responsibly. This AI Tools Notice (“Notice”) explains who we are, how we use artificial intelligence and other technology-enabled systems (“AI Tools”) in connection with our executive search and leadership advisory services and related business operations (“Services”), and how you can exercise your rights.
Where RRA processes your Personal Data using an AI Tool without your direct use of that Tool, this Notice supplements the privacy information provided to you under RRA’s Privacy Notice.
Russell Reynolds Associates is a global search and leadership advisory firm. Our 425+ consultants in 46 offices work with public, private, and non-profit organizations across all industries and regions. Our parent company, Russell Reynolds Associates, Inc., is headquartered in the United States, but we have offices in multiple locations throughout the world. Details regarding the locations of RRA’s group companies are available here. You can also find out more about our business and the Services here.
We use the following vendors when providing our Services, which may have embedded some form of AI functionality in their software stack. In such cases, they operate as the provider or AI Tools, whereas RRA is the deployer of such tools.
We are committed to using AI ethically. Our Responsible AI Principles are grounded in a People-First approach: ensuring human oversight to advance trust and to avoid unintended consequences.
These Principles govern our use of AI Tools:
|
People First |
Use AI to help people and organizations build great relationships, advance exceptional leadership, and achieve their highest potential. All other principles support this value. |
|
Human Responsibility |
Take full accountability for the technology we develop and deploy to ensure that our use of AI is in service of the needs and interests of people, teams, and organizations. Keep humans accountable and in ultimate control of quality, work product, and final decisions. |
|
Fairness |
Develop and deploy AI systems that treat people fairly. Represent diverse points of view when planning AI solutions to augment our work, including systems for discovering, assessing, and developing leaders. |
|
Privacy |
Take full accountability for the technology we develop and deploy to ensure that our use of AI is in service of the needs and interests of people, teams, and organizations. Keep humans accountable and in ultimate control of quality, work product, and final decisions. |
|
Safety & Security |
Protect the wellbeing of our clients, candidates, colleagues, and communities by aligning with AI best practices for cybersecurity, sustainability, and resilience. |
|
Transparency & Explainability |
Document how and where AI systems are at work in our business. Ensure that we can explain how algorithms operate and make choices. |
|
Accuracy & Reliability |
Evaluate all AI systems so that we can have confidence in our use and trustworthiness in all our relationships. |
RRA personnel remain responsible for their work and are required to review AI-generated output for accuracy, bias and appropriateness.
The AI Tools assist RRA personnel with human-defined tasks in connection with the Services, including, where appropriate, market and candidate research and sourcing, registering, organizing, verifying and summarizing information, scheduling and transcribing meetings, providing administrative support, preparing draft working materials, data analysis, workflow optimization, quality control, and network monitoring and information security.
It is becoming very common for our vendors to have integrated some form of AI in their software offering. The following AI Tools can be considered RRA’s ‘main’ or ‘primary’ AI Tools:
RRA ChatGPT: We use a private instance of OpenAI’s enterprise ChatGPT to assist RRA personnel with defined tasks in connection with the Services. Where appropriate, we may use RRA ChatGPT to summarize information, provide administrative support or prepare draft working materials. ChatGPT may generate text, summaries and other draft materials in response to instructions provided by RRA personnel. These outputs are used as supporting or draft material and are subject to human review. RRA’s ChatGPT is not used to rank, evaluate, or score candidates.
Microsoft 365 Copilot: We use Microsoft 365 Copilot as part of our enterprise Microsoft 365 subscription to assist RRA personnel with defined tasks in Microsoft 365 applications and services, such as summarizing documents, emails, chats or meetings, analyzing information, and preparing draft working materials. Where appropriate, your information may be included in instructions provided by RRA personnel or accessed from Microsoft 365 content that the user is permitted to access. Copilot may generate summaries, draft text, analyses and other responses, which we use as supporting or draft material and which are subject to further human review and processing.
Findem: We use a private RRA instance of Findem to support candidate research and sourcing. RRA consultants define search criteria relevant to a particular assignment and Findem processes professional and other profile information to identify and surface potential Candidates whose information corresponds to those criteria. The resulting search and matching information is used as research input for further research and review performed by RRA personnel.
Different AI Tools provide different types of output, and this is especially so for generative AI Tools. Their output may include text, summaries, documents, images, slides, reports and other draft materials, all in response to instructions provided by RRA personnel.
These outputs are used as supporting or draft material and are subject to further research and review by RRA personnel for further use in preparing materials including internal documents, candidate letters, client deliverables, research reports, and white papers. For more information on how RRA uses your personal information, please see our Privacy Notice.
All our AI Tools benefit from enterprise-grade agreements with appropriate information security, data protection, and artificial intelligence governance provisions. We vet AI Tools prior to contracting to understand their compliance with important legislation and frameworks, including the EU AI Act, the National Institute for Standards and Technology AI Responsible Management Framework, and the ISO/IEC 42001:2023 AI Management System standard.
We do not allow AI providers to train on our, our clients’, or our candidates’ identifiable data, we have set our retention period for chats in generative AI Tools to the minimum of 90 days, and it is a strict requirement for all our consultants to carefully review, evaluate, and update any AI output and be fully end-responsible for any deliverables. Although we do leverage AI Tools to optimize workflows and control quality and thus give it access to assignment information and our proprietary candidate database, we determine the purposes for which information including personal data is processed using these systems and the tasks for which they are used. This means that some processing of personal information is not human-initiated, controlled or directed, for example where an AI Tool ingests information, determines the steps for research and analysis, or is generating output, but an AI Tool is not allowed to define additional purposes for which to use personal information beyond the human-defined prompts, instructions, permissions, access management rules, and information security and policy limits set for it.
Our main AI Tools apply the following safeguards:
RRA ChatGPT: OpenAI’s Model Spec is its formal framework for intended model behavior and it uses that framework to train toward, evaluate and improve model behavior. OpenAI also applies security and privacy safeguards to its business products, including encryption of content at rest and in transit, and does not use RRA’s information to train its models. OpenAI’s models and systems are subject to benchmark evaluations, adversarial testing and ongoing safety monitoring. OpenAI has undergone an independent SOC 2 Type 2 examination for its ChatGPT business product services and maintains an ISO/IEC 42001:2023 AI Management System certification covering its business AI products and models.
RRA applies its own Responsible AI, privacy, security and human review requirements in addition to these safeguards.
Microsoft 365 Copilot: Microsoft develops Microsoft 365 Copilot in accordance with its Responsible AI principles of fairness, reliability and safety, privacy and security, inclusiveness, transparency and accountability, which are implemented through Microsoft's Responsible AI Standard. Microsoft 365 Copilot applies existing Microsoft 365 identity and access permissions so that it can access organizational information only where the relevant user has permission to access that information. Microsoft also applies safeguards including encryption, sensitivity labels, retention and audit controls, and measures intended to address harmful content and prompt-injection risks. Prompts, responses and organizational data accessed through Microsoft Graph are not used to train the underlying foundation models. Microsoft 365 Copilot and Microsoft 365 Copilot Chat are ISO/IEC 42001:2023 certified for AI management systems and are covered by Microsoft's existing Microsoft 365 privacy, security and compliance commitments.
RRA applies its own Responsible AI, privacy, security and human review requirements in addition to these safeguards.
Findem: Findem’s Responsible AI governance program is based on the National Institute of Standards and Technology Artificial Intelligence Risk Management Framework (NIST AI RMF), which it applies across employment fairness, AI transparency, information security and data privacy. Findem’s additional safeguards include documented and bounded AI functions, human oversight, fairness and disparate-impact testing, independent bias audits, role-based access controls, administrator audit logs, incident response processes and processes for managing data protection rights. Findem’s privacy program is designed by reference to the NIST Privacy Framework and its information security controls are subject to an annual SOC 2 Type II audit. Findem does not use RRA’s information to train its models.
RRA applies its own Responsible AI, privacy, security and human review requirements in addition to these safeguards.
More information on safeguards implemented by AI Tools used by RRA may be found on the respective websites of the providers of these AI Tools, as well as details on the respective codes, certifications and principles to which they adhere. Given the rapid developments in the industry, the information on the website of our AI Tool providers is leading.
AI Tools may influence the manner in which your personal data about is collected, used, reviewed, summarized or presented to RRA personnel or clients. Your data protection rights described in our Privacy Notice continue to apply where we process your personal information using AI Tools. Our use of these systems does not prevent us from giving effect to requests to access, correct or delete your personal information, or to restrict or object to its processing, where those rights apply.
Please feel free to contact us with any comments, questions, complaints, or suggestions you might have regarding the information or practices described in this Notice.
You may contact us by sending a message to Xander Menger via privacy@russellreynolds.com. You can also write to us using the details below:
Russell Reynolds Associates
Burj Daman, Business Tower - 12th floor
DIFC, PO Box 507008
Dubai, United Arab Emirates
Attention: RRA Privacy Office