Governance toolkit

Studying the AIGP teaches you the frameworks. This page is for applying them — editable templates to start from, and the external tools worth using rather than rebuilding.

Templates

Plain Markdown and CSV — open them in anything, adapt freely. They are starting points shaped by common regulatory expectations, not legal advice.

AI system inventory

CSV

The register everything else hangs off. Columns for ownership, risk tier, role, DPIA status, oversight and review cadence — pre-filled with three worked examples. Maps onto a GDPR Art. 30 record.

Start here if you have nothing.

Download

AI impact assessment

Markdown

A GDPR Art. 35 DPIA extended with the socio-technical questions from ISO/IEC 42005 and the NIST AI RMF Map function. Covers necessity, Art. 22 analysis, a risk register, fairness testing and the Art. 36 prior-consultation decision.

Download

Article 22 review checklist

Markdown

Twenty minutes to work out whether an automated decision is lawful. Includes the honest test for whether your "human in the loop" is meaningful or a rubber stamp.

Highest value per minute.

Download

AI acceptable use policy

Markdown

A short organisation-wide policy people will actually read: principles, permitted and prohibited uses aligned to EU AI Act Art. 5, roles, and an intake route.

Download

Vendor due diligence questionnaire

Markdown

40 questions for procurement, with deal-breakers flagged — including the one that matters most: does the vendor train on your data, and can you contractually opt out?

Download

Model card

Markdown

Documentation for a model: intended and out-of-scope use, training data, subgroup evaluation, limitations, oversight and change log. Aligned to the fields an AI Act Annex IV file expects.

Download

AI incident response runbook

Markdown

For when the system stays up and keeps producing confident, wrong output — which your security IR plan probably has no trigger for. Severity ladder, containment options, notification decision points.

Download

Frameworks and external tools

Every link checked before publishing. Anything marked Standard is paid; everything else is free.

NIST AI Risk Management Framework

Framework

Voluntary, widely adopted, and the source of the Govern / Map / Measure / Manage structure the exam tests. Sector-neutral and free.

NIST AI RMF Playbook

Tool

The actionable companion — suggested actions, references and documentation for each RMF subcategory. This is what you use when someone asks "so what do we actually do?".

ICO AI and data protection risk toolkit

Tool

A practical, regulator-authored workbook that walks the AI life cycle and names the risks and controls at each stage. The most directly usable free tool on this list.

ICO guidance on AI and data protection

Guidance

The narrative guidance behind the toolkit — lawful basis, fairness, accuracy, and what meaningful human review looks like in practice.

CNIL — AI: how to comply with the rules

Guidance

French regulator guidance on applying the GDPR to AI development, including the legitimate-interests analysis for training data. Available in English.

CNIL AI self-assessment guide

Tool

An analysis grid for scoring the maturity of an AI system against the GDPR. Good for a first-pass internal audit.

EU AI Act — full text

Primary source

Regulation (EU) 2024/1689 on EUR-Lex. The authoritative source when a summary and the text disagree.

EU AI Act Explorer

Tool

A browsable, cross-referenced version of the Act with recitals mapped to articles. Far easier to navigate than the OJ text.

EU AI Act Compliance Checker

Tool

An interactive questionnaire that estimates your risk tier and resulting obligations. Useful for a first-pass classification — confirm with counsel before relying on it.

ISO/IEC 42001 — AI management systems

Standard

The certifiable AI management system standard, built on Plan-Do-Check-Act. Where an organisation goes when it needs to demonstrate governance to customers. Paid standard.

ISO/IEC 23894 — AI risk management

Standard

Extends ISO 31000 risk management to AI-specific risks, and supplies the risk process ISO 42001 assumes. Paid standard.

OECD AI Principles

Principles

The values-level foundation most other frameworks trace back to, and the source of the AI system definition the EU AI Act adopted.

Microsoft Responsible AI

Example

A mature published corporate programme, including an impact assessment template. Useful as a worked example of what a real internal standard looks like.

Google Secure AI Framework (SAIF)

Framework

Security-focused framework for AI systems, with a risk self-assessment. Complements the governance frameworks, which are typically thin on adversarial threats.

MITRE ATLAS

Security

Adversarial threat landscape for AI systems — a structured knowledge base of real attack tactics and techniques against ML. The reference for threat-modelling a model.

AI Incident Database

Reference

Searchable archive of documented AI harms. The fastest way to find a concrete precedent when you need to make a risk feel real to an executive.

AI Verify Foundation

Tool

Singapore's testing framework and toolkit for AI governance, including generative AI. A rare example of executable, automated governance testing.

EDPB guidelines

Guidance

Authoritative EU-level interpretation of the GDPR, including on automated decision-making and DPIAs. What supervisory authorities actually apply.

These templates are educational starting points, not legal advice, and they do not create compliance on their own. Adapt them to your jurisdiction, sector and risk appetite, and have anything you rely on reviewed by qualified counsel.

Study the whole syllabus free

Reference notes for all 13 competencies, 305 exam-style questions, flashcards and full-length timed mocks. Sign in with Google to save your progress across devices — which stores your email address and display name. See what is kept, and how to delete it.

Start studying free →