Governance toolkit
Studying the AIGP teaches you the frameworks. This page is for applying them — editable templates to start from, and the external tools worth using rather than rebuilding.
Templates
Plain Markdown and CSV — open them in anything, adapt freely. They are starting points shaped by common regulatory expectations, not legal advice.
AI system inventory
CSVThe register everything else hangs off. Columns for ownership, risk tier, role, DPIA status, oversight and review cadence — pre-filled with three worked examples. Maps onto a GDPR Art. 30 record.
Start here if you have nothing.
DownloadAI impact assessment
MarkdownA GDPR Art. 35 DPIA extended with the socio-technical questions from ISO/IEC 42005 and the NIST AI RMF Map function. Covers necessity, Art. 22 analysis, a risk register, fairness testing and the Art. 36 prior-consultation decision.
DownloadArticle 22 review checklist
MarkdownTwenty minutes to work out whether an automated decision is lawful. Includes the honest test for whether your "human in the loop" is meaningful or a rubber stamp.
Highest value per minute.
DownloadAI acceptable use policy
MarkdownA short organisation-wide policy people will actually read: principles, permitted and prohibited uses aligned to EU AI Act Art. 5, roles, and an intake route.
DownloadVendor due diligence questionnaire
Markdown40 questions for procurement, with deal-breakers flagged — including the one that matters most: does the vendor train on your data, and can you contractually opt out?
DownloadModel card
MarkdownDocumentation for a model: intended and out-of-scope use, training data, subgroup evaluation, limitations, oversight and change log. Aligned to the fields an AI Act Annex IV file expects.
DownloadAI incident response runbook
MarkdownFor when the system stays up and keeps producing confident, wrong output — which your security IR plan probably has no trigger for. Severity ladder, containment options, notification decision points.
DownloadFrameworks and external tools
Every link checked before publishing. Anything marked Standard is paid; everything else is free.
NIST AI Risk Management Framework
FrameworkVoluntary, widely adopted, and the source of the Govern / Map / Measure / Manage structure the exam tests. Sector-neutral and free.
NIST AI RMF Playbook
ToolThe actionable companion — suggested actions, references and documentation for each RMF subcategory. This is what you use when someone asks "so what do we actually do?".
ICO AI and data protection risk toolkit
ToolA practical, regulator-authored workbook that walks the AI life cycle and names the risks and controls at each stage. The most directly usable free tool on this list.
ICO guidance on AI and data protection
GuidanceThe narrative guidance behind the toolkit — lawful basis, fairness, accuracy, and what meaningful human review looks like in practice.
CNIL — AI: how to comply with the rules
GuidanceFrench regulator guidance on applying the GDPR to AI development, including the legitimate-interests analysis for training data. Available in English.
CNIL AI self-assessment guide
ToolAn analysis grid for scoring the maturity of an AI system against the GDPR. Good for a first-pass internal audit.
EU AI Act — full text
Primary sourceRegulation (EU) 2024/1689 on EUR-Lex. The authoritative source when a summary and the text disagree.
EU AI Act Explorer
ToolA browsable, cross-referenced version of the Act with recitals mapped to articles. Far easier to navigate than the OJ text.
EU AI Act Compliance Checker
ToolAn interactive questionnaire that estimates your risk tier and resulting obligations. Useful for a first-pass classification — confirm with counsel before relying on it.
ISO/IEC 42001 — AI management systems
StandardThe certifiable AI management system standard, built on Plan-Do-Check-Act. Where an organisation goes when it needs to demonstrate governance to customers. Paid standard.
ISO/IEC 23894 — AI risk management
StandardExtends ISO 31000 risk management to AI-specific risks, and supplies the risk process ISO 42001 assumes. Paid standard.
OECD AI Principles
PrinciplesThe values-level foundation most other frameworks trace back to, and the source of the AI system definition the EU AI Act adopted.
Microsoft Responsible AI
ExampleA mature published corporate programme, including an impact assessment template. Useful as a worked example of what a real internal standard looks like.
Google Secure AI Framework (SAIF)
FrameworkSecurity-focused framework for AI systems, with a risk self-assessment. Complements the governance frameworks, which are typically thin on adversarial threats.
MITRE ATLAS
SecurityAdversarial threat landscape for AI systems — a structured knowledge base of real attack tactics and techniques against ML. The reference for threat-modelling a model.
AI Incident Database
ReferenceSearchable archive of documented AI harms. The fastest way to find a concrete precedent when you need to make a risk feel real to an executive.
AI Verify Foundation
ToolSingapore's testing framework and toolkit for AI governance, including generative AI. A rare example of executable, automated governance testing.
EDPB guidelines
GuidanceAuthoritative EU-level interpretation of the GDPR, including on automated decision-making and DPIAs. What supervisory authorities actually apply.
These templates are educational starting points, not legal advice, and they do not create compliance on their own. Adapt them to your jurisdiction, sector and risk appetite, and have anything you rely on reviewed by qualified counsel.