34 POLICY TEMPLATES · MAPPED TO 6 FRAMEWORKS · TAILORED, NOT DOWNLOADED

AI governance policy templates.

Governance, data and security, legal and compliance — every document written to the same seven-part structure, with the obligation it discharges cited on its face. We map them to your systems, your roles and the regimes that actually reach you, and you own the result outright.


A black archive box of filed records beside a stamp, reading glasses and a pen on a dark desk Illustrative materials
A document set is evidence of a programme, not a substitute for one
Governance Risk Data Security Transparency Incidents
Anatomy

What is in every template

The same seven parts, in the same order, in all 34 documents. Consistency is what lets a reviewer find the same thing in the same place across the whole set.

34 Templates Across 3 groups
7 Parts per document Identical structure throughout
6 Frameworks mapped Cited to article or clause
Yours Ownership Outright, nothing to renew
Part 1

Purpose & scope

What the policy is for, which systems and roles it binds, and what it deliberately excludes.

Part 2

Definitions

Terms used in the sense the relevant regulation uses them, so the document survives being read by a regulator.

Part 3

Roles & accountability

Named roles with decision rights, not a list of departments that might be involved.

Part 4

Controls & procedure

The steps somebody actually performs, in the order they perform them.

Part 5

Evidence produced

What each control leaves behind, and where it is filed. A control with no artefact is unauditable.

Part 6

Regulatory mapping

The obligations the document discharges, cited to the article or clause.

Part 7

Review cycle & owner

Who reviews it, how often, and the version history that shows they did.

The library

All 34 policy templates

Grouped by what they govern, alphabetical within each group, with the obligation each one discharges on the row. Nobody needs all of them — which apply is a scoping question.

Core governance

12 templates

The framework layer: who decides, on what principles, and how a model gets approved, changed and retired.

AI Change Management Standard

What counts as a substantial modification, who re-approves it, and when a change resets the review and documentation clock.

  • EU AI Act Art. 43(4)
  • ISO 42001 cl. 8
AI Ethical Use Charter

The uses you will not put AI to, stated before commercial pressure makes the question difficult.

  • EU AI Act Art. 5
  • NIST AI RMF GOVERN
AI Governance Policy

The parent document. Scope, governance bodies, decision rights, escalation and how every other policy in the pack hangs off it.

  • EU AI Act Art. 9
  • ISO 42001 cl. 5
  • NIST AI RMF GOVERN
AI Literacy & Training Programme

Role-based training with a completion record. Article 4 is short, in force, and the obligation people most often discover late.

  • EU AI Act Art. 4
  • ISO 42001 cl. 7.2
AI Quality Assurance Policy

Acceptance criteria before release, the evidence a model has to produce to meet them, and who signs that it did.

  • EU AI Act Art. 17
  • ISO 42001 cl. 8
AI Risk Management Policy

How risk is identified, analysed, rated and mitigated across the lifecycle, and what residual risk you are prepared to accept.

  • EU AI Act Art. 9
  • ISO 42001 cl. 6
  • NIST AI RMF MAP
Human Oversight Policy

Who reviews, on what trigger, with what authority to override, and what they are given before they decide.

  • EU AI Act Art. 14
  • GDPR Art. 22
  • OSFI E-23 review
Model Approval & Release Procedure

The gate between a model that works and a model that is in production, with the approval recorded rather than assumed.

  • EU AI Act Art. 16
  • ISO 42001 cl. 8
  • OSFI E-23 deployment
Model Decommissioning Procedure

Retirement as a controlled act: dependency check, retention decision, notification list, inventory status closed rather than deleted.

  • OSFI E-23 decommission
  • ISO 42001 cl. 8
Model Validation & Testing Standard

Independent assessment of conceptual soundness and performance, scaled to the model’s risk rating.

  • EU AI Act Art. 15
  • OSFI E-23 review
  • SR 11-7
Post-Market Monitoring Plan

What you watch after deployment, the thresholds that fire, and the route from a breached threshold to a decision.

  • EU AI Act Art. 72
  • OSFI E-23 monitoring
Responsible AI Principles

The short public statement the rest of the pack has to be consistent with. One page, and every line of it testable.

  • NIST AI RMF GOVERN
  • OECD AI Principles

Data & security

9 templates

What goes into the model, what it is allowed to keep, and how the system and its data are protected.

AI Access Control Standard

Who can call the model, retrain it, read its outputs and change its configuration — reviewed rather than granted once.

  • GDPR Art. 32
  • ISO 27001 A.5.15
AI Data Use Policy

The lawful basis and permitted purposes for every data flow into a model, including the secondary-use question.

  • GDPR Arts. 5–6
  • EU AI Act Art. 10
Data Minimisation for AI

Field-level justification for what you collect, and pseudonymisation where identity is not needed for the task.

  • GDPR Art. 5(1)(c)
  • EU AI Act Art. 10
Incident Response for AI Systems

Detection to decision for AI-specific failures, wired into your existing security incident process rather than beside it.

  • EU AI Act Art. 73
  • GDPR Art. 33
  • ISO 42001 cl. 10
Model & Data Retention Schedule

A period per artefact — training sets, model versions, logs, outputs — with the justification and the deletion route named.

  • GDPR Art. 5(1)(e)
  • EU AI Act Art. 12
Operational Logging Standard

What the system records automatically, for how long, and how a log is retrieved when an investigation needs it.

  • EU AI Act Arts. 12, 26(6)
  • OSFI E-23 monitoring
Prompt Security & Hardening

Injection, exfiltration and jailbreak controls for systems that take natural-language input from outside the organisation.

  • ISO 27001 A.8
  • NIST AI RMF MANAGE
Sensitive Data Handling for AI

Special category and other sensitive data: the additional condition, the extra controls, and where the model must not see it at all.

  • GDPR Art. 9
  • EU AI Act Art. 10(5)
Training Data Sourcing Policy

Provenance, licensing, consent and quality for every dataset used to train or fine-tune — recorded at acquisition, not reconstructed later.

  • EU AI Act Art. 10
  • GDPR Art. 5(1)(b)

Legal & compliance

13 templates

The outward-facing layer: what you tell regulators, customers and the people a system makes decisions about.

AI Accountability & Roles

Owner, developer, reviewer, approver and user mapped to named people, with the board and management reporting line.

  • EU AI Act Art. 22
  • OSFI E-23 governance
  • ISO 42001 cl. 5.3
AI Procurement Standard

What you require from a supplier before a bought model can be rated, reviewed and monitored like one of your own.

  • EU AI Act Art. 25
  • OSFI E-23 third party
AI Regulatory Compliance Policy

How you determine which regimes reach a given system, and who owns the answer when the reading is arguable.

  • EU AI Act Art. 2
  • Multi-framework
AI Vendor Risk Policy

Due diligence, contractual terms and ongoing oversight for third-party models, APIs and data suppliers.

  • EU AI Act Art. 25
  • GDPR Art. 28
CE Marking Readiness Procedure

The conformity assessment route for your system, the declaration, and the file that has to sit behind the mark.

  • EU AI Act Arts. 43, 47–48
Complaints & Redress Procedure

How an affected person raises an AI decision, what they are told, and how the outcome is recorded.

  • EU AI Act Art. 85
  • GDPR Arts. 15–22
Documentation & Traceability Standard

The technical documentation package and the record trail that lets someone reconstruct why a system behaved as it did.

  • EU AI Act Art. 11 & Annex IV
  • ISO 42001 cl. 7.5
Fundamental Rights Impact Assessment

The FRIA methodology and template for deployers who owe one, with the residual-risk judgement written down.

  • EU AI Act Art. 27
High-Risk System Registration

What goes into the EU database, who files it, and how the entry is kept current as the system changes.

  • EU AI Act Arts. 49, 71
Records of Processing for AI

The Article 30 record for AI-specific processing: purposes, categories, recipients, transfers and retention, actually filled in.

  • GDPR Art. 30
Serious Incident Reporting Procedure

The notification decision tree and the reporting pack, with the clock defined from awareness rather than from confirmation.

  • EU AI Act Art. 73
  • GDPR Art. 33
Third-Party & Open-Weight Model Use

When an open-weight or downstream model may be used, what documentation you must obtain, and where the carve-outs stop.

  • EU AI Act Arts. 53–55
Transparency & User Notice Policy

Chatbot disclosure, synthetic-media marking and the notice a person gets before an automated decision affects them.

  • EU AI Act Art. 50
  • GDPR Arts. 13–14

The mapping is the useful half. Every vendor has an “AI Governance Policy”; a title tells a reader nothing. What the document is written to discharge — cited to the article or clause — is what makes it checkable, and it is also what tells you quickly whether you need it at all.

Coverage

What the pack supplies, per framework

Deliberately not a grid of ticks. A tick beside a regulation reads as “this makes you compliant”, which no document set does — so each row says what the pack actually provides for that regime.

EU AI Act
Risk management, data governance, technical documentation, human oversight, transparency, registration and incident reporting.
ISO/IEC 42001
The AI management system clauses — context, leadership, planning, support, operation, evaluation and improvement.
NIST AI RMF
Govern, Map, Measure and Manage, with the pack supplying the artefacts each function expects.
GDPR
Lawful basis, minimisation, retention, security, records of processing and the Article 22 safeguards.
OSFI E-23
Model inventory, risk rating, the five lifecycle stages and independent review.
ISO/IEC 27001
The security controls the AI-specific documents lean on rather than restate.

Documents evidence a programme; they are not the programme. What the pack removes is the blank page and the risk that an obligation is simply missing from your document set. What it cannot do is operate a control on your behalf, and any vendor telling you otherwise is selling a false sense of security.

How they are delivered

Tailored, not downloaded

The obvious question about a page like this is why there is no download button. Four reasons, each a failure we have actually watched happen.

A generic policy reads as a generic policy

Assessors have seen the same downloaded template many times. What earns credit is a document that names your systems, your roles and your actual approval route.

The controls have to match what you run

A policy promising a control you do not operate is worse than no policy: it converts a gap into a documented failure to follow your own procedure.

Scope decides which of these you need

Nobody needs all 34. Which apply depends on your role, your risk tier and the regimes that reach you — and that determination is the first thing we do.

They have to stay current

Colorado repealed and replaced its AI Act inside two years. A document set with no owner and no review cycle is a snapshot of a law that has since moved.

You own what we write. The documents are yours outright, with no licence, no renewal and no dependency on staying a customer. If you leave, the policies stay — which is the only arrangement that makes sense for something your regulator may one day read.

Questions

Frequently asked questions

What you get, what it covers, and what it does not claim to do.

1 The library
Can I download the templates?

Not as generic documents, and that is a deliberate choice rather than a gate. A policy adopted verbatim is the artefact an assessor discounts fastest, and a document promising a control you do not run turns a gap into a documented failure to follow your own procedure. We tailor the set you need as part of a scoped engagement.

What format do they arrive in?

Editable documents you own outright, plus a mapping sheet that shows which obligation each one discharges. You keep them, you version them, and nothing depends on staying a customer.

Do I need all of them?

Almost certainly not. Which apply depends on whether you are a provider or a deployer, the risk tier of your systems, and which regimes reach you. Scoping that is the first step, and it usually shortens the list considerably.

What is in each document?

The same seven parts every time: purpose and scope, definitions, roles and accountability, controls and procedure, the evidence each control produces, the regulatory mapping, and the review cycle with a named owner. Consistency is what lets a reviewer find the same thing in the same place across the set.

2 Coverage and fit
Which frameworks are they mapped to?

The EU AI Act, ISO/IEC 42001, the NIST AI Risk Management Framework, GDPR, OSFI Guideline E-23 and ISO/IEC 27001. Each template carries its mapping on the row above, cited to the article or clause rather than to the framework in general.

Does adopting these make us compliant?

No, and any vendor who says otherwise is selling you a false sense of security. Documents evidence a programme; they are not the programme. What the pack does is remove the blank-page problem and make sure nothing an obligation asks for is simply missing.

We already have policies. Is this useful?

Usually more useful, not less. The common finding is not an absent policy but a set that predates the regime it now has to satisfy, with no mapping, no evidence requirement and no review owner. Gap-mapping what you have against the library is faster than rewriting it.

Do they work for a non-EU organisation?

Yes. The core governance and data documents are regime-neutral in substance; the mapping layer is what changes. If the EU AI Act does not reach you, the same controls map onto NIST AI RMF, ISO 42001 or your sector supervisor’s expectations.

3 The engagement
How long does tailoring take?

It runs alongside the readiness review rather than after it, because the review is what tells us which documents you need and what your controls actually are. Most organisations see the first drafts inside the engagement rather than at the end of it.

What does it cost?

It is scoped before you are charged. The variables are how many systems are in scope, how many regimes reach you, and how much of your existing document set can be mapped rather than rewritten.

Who owns the documents afterwards?

You do, outright and without restriction. They are your policies; we are not a licensor and there is nothing to renew.

Ready when you are

Get the pack scoped to your estate

We work out which of the 34 you actually need, map what you already have, and write the rest against your systems and your roles — scoped before you are charged.

The templates are guidance documents, not legal advice, and adopting them does not by itself make an organisation compliant with anything. Where an obligation is genuinely arguable we say so in the document rather than pick the convenient reading.