AI governance policy templates.
Governance, data and security, legal and compliance — every document written to the same seven-part structure, with the obligation it discharges cited on its face. We map them to your systems, your roles and the regimes that actually reach you, and you own the result outright.
What is in every template
The same seven parts, in the same order, in all 34 documents. Consistency is what lets a reviewer find the same thing in the same place across the whole set.
Purpose & scope
What the policy is for, which systems and roles it binds, and what it deliberately excludes.
Definitions
Terms used in the sense the relevant regulation uses them, so the document survives being read by a regulator.
Roles & accountability
Named roles with decision rights, not a list of departments that might be involved.
Controls & procedure
The steps somebody actually performs, in the order they perform them.
Evidence produced
What each control leaves behind, and where it is filed. A control with no artefact is unauditable.
Regulatory mapping
The obligations the document discharges, cited to the article or clause.
Review cycle & owner
Who reviews it, how often, and the version history that shows they did.
All 34 policy templates
Grouped by what they govern, alphabetical within each group, with the obligation each one discharges on the row. Nobody needs all of them — which apply is a scoping question.
Core governance
12 templatesThe framework layer: who decides, on what principles, and how a model gets approved, changed and retired.
What counts as a substantial modification, who re-approves it, and when a change resets the review and documentation clock.
- EU AI Act Art. 43(4)
- ISO 42001 cl. 8
The uses you will not put AI to, stated before commercial pressure makes the question difficult.
- EU AI Act Art. 5
- NIST AI RMF GOVERN
The parent document. Scope, governance bodies, decision rights, escalation and how every other policy in the pack hangs off it.
- EU AI Act Art. 9
- ISO 42001 cl. 5
- NIST AI RMF GOVERN
Role-based training with a completion record. Article 4 is short, in force, and the obligation people most often discover late.
- EU AI Act Art. 4
- ISO 42001 cl. 7.2
Acceptance criteria before release, the evidence a model has to produce to meet them, and who signs that it did.
- EU AI Act Art. 17
- ISO 42001 cl. 8
How risk is identified, analysed, rated and mitigated across the lifecycle, and what residual risk you are prepared to accept.
- EU AI Act Art. 9
- ISO 42001 cl. 6
- NIST AI RMF MAP
Who reviews, on what trigger, with what authority to override, and what they are given before they decide.
- EU AI Act Art. 14
- GDPR Art. 22
- OSFI E-23 review
The gate between a model that works and a model that is in production, with the approval recorded rather than assumed.
- EU AI Act Art. 16
- ISO 42001 cl. 8
- OSFI E-23 deployment
Retirement as a controlled act: dependency check, retention decision, notification list, inventory status closed rather than deleted.
- OSFI E-23 decommission
- ISO 42001 cl. 8
Independent assessment of conceptual soundness and performance, scaled to the model’s risk rating.
- EU AI Act Art. 15
- OSFI E-23 review
- SR 11-7
What you watch after deployment, the thresholds that fire, and the route from a breached threshold to a decision.
- EU AI Act Art. 72
- OSFI E-23 monitoring
The short public statement the rest of the pack has to be consistent with. One page, and every line of it testable.
- NIST AI RMF GOVERN
- OECD AI Principles
Data & security
9 templatesWhat goes into the model, what it is allowed to keep, and how the system and its data are protected.
Who can call the model, retrain it, read its outputs and change its configuration — reviewed rather than granted once.
- GDPR Art. 32
- ISO 27001 A.5.15
The lawful basis and permitted purposes for every data flow into a model, including the secondary-use question.
- GDPR Arts. 5–6
- EU AI Act Art. 10
Field-level justification for what you collect, and pseudonymisation where identity is not needed for the task.
- GDPR Art. 5(1)(c)
- EU AI Act Art. 10
Detection to decision for AI-specific failures, wired into your existing security incident process rather than beside it.
- EU AI Act Art. 73
- GDPR Art. 33
- ISO 42001 cl. 10
A period per artefact — training sets, model versions, logs, outputs — with the justification and the deletion route named.
- GDPR Art. 5(1)(e)
- EU AI Act Art. 12
What the system records automatically, for how long, and how a log is retrieved when an investigation needs it.
- EU AI Act Arts. 12, 26(6)
- OSFI E-23 monitoring
Injection, exfiltration and jailbreak controls for systems that take natural-language input from outside the organisation.
- ISO 27001 A.8
- NIST AI RMF MANAGE
Special category and other sensitive data: the additional condition, the extra controls, and where the model must not see it at all.
- GDPR Art. 9
- EU AI Act Art. 10(5)
Provenance, licensing, consent and quality for every dataset used to train or fine-tune — recorded at acquisition, not reconstructed later.
- EU AI Act Art. 10
- GDPR Art. 5(1)(b)
Legal & compliance
13 templatesThe outward-facing layer: what you tell regulators, customers and the people a system makes decisions about.
Owner, developer, reviewer, approver and user mapped to named people, with the board and management reporting line.
- EU AI Act Art. 22
- OSFI E-23 governance
- ISO 42001 cl. 5.3
What you require from a supplier before a bought model can be rated, reviewed and monitored like one of your own.
- EU AI Act Art. 25
- OSFI E-23 third party
How you determine which regimes reach a given system, and who owns the answer when the reading is arguable.
- EU AI Act Art. 2
- Multi-framework
Due diligence, contractual terms and ongoing oversight for third-party models, APIs and data suppliers.
- EU AI Act Art. 25
- GDPR Art. 28
The conformity assessment route for your system, the declaration, and the file that has to sit behind the mark.
- EU AI Act Arts. 43, 47–48
How an affected person raises an AI decision, what they are told, and how the outcome is recorded.
- EU AI Act Art. 85
- GDPR Arts. 15–22
The technical documentation package and the record trail that lets someone reconstruct why a system behaved as it did.
- EU AI Act Art. 11 & Annex IV
- ISO 42001 cl. 7.5
The FRIA methodology and template for deployers who owe one, with the residual-risk judgement written down.
- EU AI Act Art. 27
What goes into the EU database, who files it, and how the entry is kept current as the system changes.
- EU AI Act Arts. 49, 71
The Article 30 record for AI-specific processing: purposes, categories, recipients, transfers and retention, actually filled in.
- GDPR Art. 30
The notification decision tree and the reporting pack, with the clock defined from awareness rather than from confirmation.
- EU AI Act Art. 73
- GDPR Art. 33
When an open-weight or downstream model may be used, what documentation you must obtain, and where the carve-outs stop.
- EU AI Act Arts. 53–55
Chatbot disclosure, synthetic-media marking and the notice a person gets before an automated decision affects them.
- EU AI Act Art. 50
- GDPR Arts. 13–14
The mapping is the useful half. Every vendor has an “AI Governance Policy”; a title tells a reader nothing. What the document is written to discharge — cited to the article or clause — is what makes it checkable, and it is also what tells you quickly whether you need it at all.
What the pack supplies, per framework
Deliberately not a grid of ticks. A tick beside a regulation reads as “this makes you compliant”, which no document set does — so each row says what the pack actually provides for that regime.
- EU AI Act
- Risk management, data governance, technical documentation, human oversight, transparency, registration and incident reporting.
- ISO/IEC 42001
- The AI management system clauses — context, leadership, planning, support, operation, evaluation and improvement.
- NIST AI RMF
- Govern, Map, Measure and Manage, with the pack supplying the artefacts each function expects.
- GDPR
- Lawful basis, minimisation, retention, security, records of processing and the Article 22 safeguards.
- OSFI E-23
- Model inventory, risk rating, the five lifecycle stages and independent review.
- ISO/IEC 27001
- The security controls the AI-specific documents lean on rather than restate.
Documents evidence a programme; they are not the programme. What the pack removes is the blank page and the risk that an obligation is simply missing from your document set. What it cannot do is operate a control on your behalf, and any vendor telling you otherwise is selling a false sense of security.
Tailored, not downloaded
The obvious question about a page like this is why there is no download button. Four reasons, each a failure we have actually watched happen.
A generic policy reads as a generic policy
Assessors have seen the same downloaded template many times. What earns credit is a document that names your systems, your roles and your actual approval route.
The controls have to match what you run
A policy promising a control you do not operate is worse than no policy: it converts a gap into a documented failure to follow your own procedure.
Scope decides which of these you need
Nobody needs all 34. Which apply depends on your role, your risk tier and the regimes that reach you — and that determination is the first thing we do.
They have to stay current
Colorado repealed and replaced its AI Act inside two years. A document set with no owner and no review cycle is a snapshot of a law that has since moved.
You own what we write. The documents are yours outright, with no licence, no renewal and no dependency on staying a customer. If you leave, the policies stay — which is the only arrangement that makes sense for something your regulator may one day read.
Frequently asked questions
What you get, what it covers, and what it does not claim to do.
Can I download the templates?
Not as generic documents, and that is a deliberate choice rather than a gate. A policy adopted verbatim is the artefact an assessor discounts fastest, and a document promising a control you do not run turns a gap into a documented failure to follow your own procedure. We tailor the set you need as part of a scoped engagement.
What format do they arrive in?
Editable documents you own outright, plus a mapping sheet that shows which obligation each one discharges. You keep them, you version them, and nothing depends on staying a customer.
Do I need all of them?
Almost certainly not. Which apply depends on whether you are a provider or a deployer, the risk tier of your systems, and which regimes reach you. Scoping that is the first step, and it usually shortens the list considerably.
What is in each document?
The same seven parts every time: purpose and scope, definitions, roles and accountability, controls and procedure, the evidence each control produces, the regulatory mapping, and the review cycle with a named owner. Consistency is what lets a reviewer find the same thing in the same place across the set.
Which frameworks are they mapped to?
The EU AI Act, ISO/IEC 42001, the NIST AI Risk Management Framework, GDPR, OSFI Guideline E-23 and ISO/IEC 27001. Each template carries its mapping on the row above, cited to the article or clause rather than to the framework in general.
Does adopting these make us compliant?
No, and any vendor who says otherwise is selling you a false sense of security. Documents evidence a programme; they are not the programme. What the pack does is remove the blank-page problem and make sure nothing an obligation asks for is simply missing.
We already have policies. Is this useful?
Usually more useful, not less. The common finding is not an absent policy but a set that predates the regime it now has to satisfy, with no mapping, no evidence requirement and no review owner. Gap-mapping what you have against the library is faster than rewriting it.
Do they work for a non-EU organisation?
Yes. The core governance and data documents are regime-neutral in substance; the mapping layer is what changes. If the EU AI Act does not reach you, the same controls map onto NIST AI RMF, ISO 42001 or your sector supervisor’s expectations.
How long does tailoring take?
It runs alongside the readiness review rather than after it, because the review is what tells us which documents you need and what your controls actually are. Most organisations see the first drafts inside the engagement rather than at the end of it.
What does it cost?
It is scoped before you are charged. The variables are how many systems are in scope, how many regimes reach you, and how much of your existing document set can be mapped rather than rewritten.
Who owns the documents afterwards?
You do, outright and without restriction. They are your policies; we are not a licensor and there is nothing to renew.
Get the pack scoped to your estate
We work out which of the 34 you actually need, map what you already have, and write the rest against your systems and your roles — scoped before you are charged.
The templates are guidance documents, not legal advice, and adopting them does not by itself make an organisation compliant with anything. Where an obligation is genuinely arguable we say so in the document rather than pick the convenient reading.
From Insights
Before you adopt a policy set
What an AI Governance Framework Actually Contains
Five working parts, not a policy document. What each one has to do, how to tell whether yours is real, and why a framework is not the same thing as compliance.
Read the guideHow to Prepare for an AI Audit: The Readiness Checklist
Six things to have ready before the engagement starts. Assembling them takes a fortnight off the clock — and tends to find the first two findings before an auditor does.
Read the notesWhat Is an AI Audit? Scope, Standards, and What You Get
An independent review of what your AI actually does, measured against a named standard — not a certificate, and not a review of what the documentation says it does.
Read the notes