The AI Governance Toolkit

Build a working AI governance programme: a system register, risk classification, conformity assessments, overlays, AIBOM and an audit-ready evidence trail.

A practical implementation guide for turning an AI policy into something an auditor can test. Every technique works with a spreadsheet and a shared drive, and each section ends with a fillable checklist.

Get the Toolkit

Most organisations have an AI policy. Few can show what it governs.

Shadow AI moved faster than procurement and security review. Generative and predictive tools now sit inside hiring, customer service, content moderation and code review, often before a governance team knew they existed.

An auditor does not test whether a policy is well written. They ask, for a named system, who owns it, what data it uses, how it was classified, which assessment approved it and what evidence shows the conditions were met. This toolkit builds the register and evidence trail underneath the policy.

What's inside the 35-page toolkit?

  • AI system register

    Fillable register template with owner, purpose, data, decisions and risk tier.

  • Risk classification and review

    A repeatable method for tiering systems and prioritising what gets assessed next.

  • Conformity assessments and overlays

    Structured assessment steps plus how to map additional frameworks on top.

  • Remediation and supplier oversight

    Remediation tracker and supplier due-diligence record, both fillable.

  • Evidence, monitoring and AIBOM

    Evidence library conventions, post-deployment monitoring and an AI bill of materials template.

  • 90-day roadmap and checklists

    Week-by-week plan and eleven one-page fillable checklists.

Who is this toolkit for?

  • Data protection officers
  • Compliance officers
  • Legal teams
  • IT and security leads
  • Multi-entity governance teams

Frequently asked questions

Do I need Privacy360 to use this toolkit?
No. Every section is designed to work with a spreadsheet and a shared drive. Notes on scaling with software are included for when a live AI estate outgrows a shared file.
Does it cover the EU AI Act?
Yes. The classification and assessment method is built around the obligations organisations need running before EU AI Act high-risk requirements apply, and the overlays section covers mapping further frameworks.
What is an AIBOM?
An AI bill of materials records what a system is built from — models, datasets, libraries and dependencies — so you can see what changed underneath it. The toolkit includes a fillable AIBOM template.
Are the templates fillable?
Yes. The register, remediation tracker, supplier record, AIBOM, roadmap and every appendix checklist are fillable PDF forms.
Where should we start?
With the register. Classification, assessment, remediation and evidence all operate on rows in that register, so the guide recommends building it before revising policy wording.

Get the Toolkit

Complete the download form to receive the AI Governance Toolkit.