AI Governance Templates
Last updated: 2026-08-15
18 ready-to-use AI governance templates, covering the model register, consequence-based risk tiering, the approval gate checklist, vendor assurance questions, use case scoring, readiness assessment, and maturity rubric. Each is drawn from a practitioner playbook and written to be used without modification.
The working artefacts from the six AI playbooks, each published separately so it can be found, cited, and used on its own. Every template states the decision it supports, how to apply it, and what goes wrong when it is skipped.
- AI Model Register Template
An institution that cannot list its AI systems cannot govern them. The register is the base record that every other governance activity refers to: tiering, approval, review, and incident response all read from it and write back to it. From the AI Governance playbook. - AI Risk Tiering Criteria
Tiering schemes built around technology age badly, because every wave of capability needs a new rulebook, and they reach the wrong conclusion: a rules engine that denies a claim deserves more scrutiny than a language model that drafts meeting notes. From the AI Governance playbook. - AI Approval Gate Checklist
The gate is where governance either constrains behaviour or reveals itself as decoration. Its function is to refuse systems that cannot answer for themselves, which requires that someone present has the authority to say no. From the AI Governance playbook. - AI Use Case Scoring Sheet
Most use case prioritisation fails by averaging. A case with compelling value and no usable data scores respectably on a mean and then consumes a year proving it cannot be built. From the AI Use Case Discovery, Readiness & Maturity Assessment playbook. - AI Readiness Assessment
Readiness is a property of a use case in an organisation, not of the organisation alone. An institution can be ready for one system and entirely unready for another running on different data. From the AI Use Case Discovery, Readiness & Maturity Assessment playbook. - AI Maturity Rubric
A maturity score on its own changes nothing. The rubric is useful when it is read as a gap against specific planned work, which converts an assessment into a sequenced investment case. From the AI Use Case Discovery, Readiness & Maturity Assessment playbook. - AI Vendor Assurance Question Set
Where a system is bought rather than built, assurance replaces inspection. The contract and the questions asked before signing are the only governance instruments that still work once the system is in place. From the AI Security & Assurance playbook. - AI Control Checklist
Applying every control to every system guarantees that the controls are ignored on the systems that matter. Proportionality is what makes a control set survive contact with delivery pressure. From the AI Security & Assurance playbook. - AI Incident Triage Sheet
Incident response for AI systems fails when teams begin by diagnosing. An agent with live credentials continues acting while the investigation proceeds, and every minute of analysis is a minute of continued exposure. From the AI Security & Assurance playbook. - AI Centre of Excellence Operating Mode Selector
Most centres of excellence fail by choosing a mode that does not match the organisation around them: delivering where units can already build, or enabling where nobody can. From the AI-CoE / AI Transformation Office playbook. - AI Centre of Excellence Charter Template
A charter earns its place by settling arguments before they happen: what the centre decides, what it advises on, and what it declines. A charter that lists activities settles nothing. From the AI-CoE / AI Transformation Office playbook. - AI Use Case Intake Form
The intake form does most of the filtering that a governance committee would otherwise do slowly. A request that cannot name the decision it changes or the person who owns it is not a use case yet. From the AI-CoE / AI Transformation Office playbook. - Sovereignty Control Ladder
Sovereignty decisions are usually made implicitly, one procurement at a time, and only become visible when a dependency fails. The ladder makes the choices explicit and priced. From the Sovereign AI Strategy & Transformation playbook. - National AI Strategy Test
National AI strategies commonly announce capability without committing to the operating cost of keeping it, and without stating which dependencies are being accepted deliberately. From the Sovereign AI Strategy & Transformation playbook. - Five-Year AI Cost Model Structure
The most common failure in sovereign AI programmes is a capital budget with no operating budget behind it. Announcements are funded easily; year four is not. From the Sovereign AI Strategy & Transformation playbook. - AI Curriculum Map for Three Audiences
A single AI training programme delivered to an entire organisation satisfies nobody: it is too shallow for the people building systems and too technical for the people approving them. From the AI Leadership & Workforce Capability Building playbook. - AI Executive Session Design
Executive AI briefings usually fail by demonstrating success only, which leaves decision-makers unable to judge where a system will break and inclined either to over-trust or to prohibit. From the AI Leadership & Workforce Capability Building playbook. - AI Capability Evidence Framework
Training that is not recorded as an expectation decays within a year and has to be repurchased. Evidence attached to roles survives staff turnover in a way that attendance records do not. From the AI Leadership & Workforce Capability Building playbook.
Each template belongs to a longer playbook that sets out the reasoning, the rules of thumb, and the failure signals around it.