The AI Governance Toolkit
Build a working AI governance programme: a system register, risk classification, conformity assessments, overlays, AIBOM and an audit-ready evidence trail.
A practical implementation guide for turning an AI policy into something an auditor can test. Every technique works with a spreadsheet and a shared drive, and each section ends with a fillable checklist.
Most organisations have an AI policy. Few can show what it governs.
Shadow AI moved faster than procurement and security review. Generative and predictive tools now sit inside hiring, customer service, content moderation and code review, often before a governance team knew they existed.
An auditor does not test whether a policy is well written. They ask, for a named system, who owns it, what data it uses, how it was classified, which assessment approved it and what evidence shows the conditions were met. This toolkit builds the register and evidence trail underneath the policy.
What's inside the 35-page toolkit?
AI system register
Fillable register template with owner, purpose, data, decisions and risk tier.
Risk classification and review
A repeatable method for tiering systems and prioritising what gets assessed next.
Conformity assessments and overlays
Structured assessment steps plus how to map additional frameworks on top.
Remediation and supplier oversight
Remediation tracker and supplier due-diligence record, both fillable.
Evidence, monitoring and AIBOM
Evidence library conventions, post-deployment monitoring and an AI bill of materials template.
90-day roadmap and checklists
Week-by-week plan and eleven one-page fillable checklists.
Who is this toolkit for?
- Data protection officers
- Compliance officers
- Legal teams
- IT and security leads
- Multi-entity governance teams
Frequently asked questions
- Do I need Privacy360 to use this toolkit?
- No. Every section is designed to work with a spreadsheet and a shared drive. Notes on scaling with software are included for when a live AI estate outgrows a shared file.
- Does it cover the EU AI Act?
- Yes. The classification and assessment method is built around the obligations organisations need running before EU AI Act high-risk requirements apply, and the overlays section covers mapping further frameworks.
- What is an AIBOM?
- An AI bill of materials records what a system is built from — models, datasets, libraries and dependencies — so you can see what changed underneath it. The toolkit includes a fillable AIBOM template.
- Are the templates fillable?
- Yes. The register, remediation tracker, supplier record, AIBOM, roadmap and every appendix checklist are fillable PDF forms.
- Where should we start?
- With the register. Classification, assessment, remediation and evidence all operate on rows in that register, so the guide recommends building it before revising policy wording.
Get the Toolkit
Complete the download form to receive the AI Governance Toolkit.