Governance Templates
Ready-to-use document templates for every policy, assessment, matrix, and report referenced across the 43 controls. Copy, customize, and implement.
Defines permitted AI use cases, prohibited activities, data handling requirements, and approval workflows.
Documents organizational AI risk tolerance across key categories with thresholds and approval authorities.
Defines roles and responsibilities across all AI governance activities using RACI assignments.
Structured evaluation rubric for assessing AI vendors and models across security, privacy, performance, and risk dimensions.
Centralized register tracking all AI systems, models, agents, and tools with ownership, risk classification, and status.
Structured checklist for reviewing AI-generated and AI-integrated code covering security, quality, and compliance.
Defines mandatory human review checkpoints in the AI development lifecycle with criteria and escalation procedures.
Test plan for validating AI data pipelines covering data quality, lineage, bias detection, and integrity checks.
Standardized model card documenting model purpose, capabilities, limitations, performance, and ethical considerations.
Structured threat modeling template for AI systems covering attack surfaces, threat actors, and mitigation strategies.
Security guidelines for writing, testing, and hardening AI prompts against injection, leakage, and manipulation attacks.
Documents permission boundaries, tool access, and operational limits for each AI agent.
An AI-specific red team engagement playbook with attack scenarios, execution templates, and remediation tracking.
A pre-deployment checklist ensuring all security, performance, and governance requirements are met before go-live.
A structured change request form for model updates with impact assessment, testing evidence, and approval chain.
Defines SLA targets, performance baselines, and monitoring thresholds for AI systems.
An AI-specific incident response plan covering detection, triage, containment, and post-incident review procedures.
Defines key performance and risk indicators for AI governance with targets, thresholds, and dashboard specifications.
A quarterly compliance report template summarizing control status, audit findings, incidents, and training completion.
A post-incident review template with timeline, root cause analysis, corrective actions, and lessons learned.
An AI governance maturity assessment tool with level definitions, domain scoring, gap analysis, and improvement roadmap.