30/60/90-day plans¶
Knowing which templates you need is not the same as knowing what order to do them in. These are sequenced plans with rough effort, so you can plan resource and tell a sponsor when things will land.
Effort is for one person, not full time
Estimates are person-days for whoever is running this, assuming it is not their only job. They cover a competent first pass — not a polished, audited version.
Pick your path¶
| Path | When it fits | Total effort |
|---|---|---|
| Standing up a programme from nothing | Nobody owns AI governance yet, or someone has just been handed the brief. | ~18–24 person-days over 90 days |
| AI is landing faster than governance | The business is shipping AI and you are trying to get in front of it. | ~14–18 person-days over 90 days |
| A regulator or board is asking questions | Something has prompted scrutiny and you need a defensible answer soon. | ~10–14 person-days over 90 days |
| Small or flat organisation | Fewer than ~150 people, no committee, no dedicated governance role, and this is somebody's third priority. | ~6–9 person-days over 90 days |
Standing up a programme from nothing¶
When it fits: Nobody owns AI governance yet, or someone has just been handed the brief.
Assumes: You can get a decision-maker in a room, and you have a few days a week.
Total effort: ~18–24 person-days over 90 days
Days 1–30 — Know what you have and get a mandate.¶
Effort: 6–8 days
- Baseline honestly with the maturity assessment — Maturity Assessment · 1 day
Score what is true, not what is intended. This number is the benchmark every later improvement is measured against. - Run a discovery sweep and build the AI inventory — AI System Inventory · 3–4 days
Ask teams, then check SaaS release notes, expenses, and SSO logs. Budget for finding two to three times what people report. - Screen everything for prohibited practices — AI Risk Assessment · 1 day
Prohibited practices have been in force since February 2025. If you find one, this becomes urgent and everything else waits. - Get a written mandate — Governance Charter · 1–2 days
Two pages. The clauses that matter are the authority to halt a system and a named executive sponsor.
You are done when:
- You can name every AI system in the organisation
- Someone senior has signed something saying you own this
- You know whether you have a prohibited-practice problem
Days 31–60 — Put the rules and the decision-making in place.¶
Effort: 6–8 days
- Publish the acceptable AI use policy — Acceptable AI Use Policy · 1 day to draft
The highest-value document in the kit for the effort. Staff are already using AI; this is catching up, not getting ahead. - Classify every system by risk tier — AI System Inventory · 2 days
Record the rationale, not just the label. - Stand up the committee and agree decision rights — Committee Charter (Terms of Reference) · 2 days
Settle quorum and who can halt a live system before the first meeting, not during the first incident. - Agree the RACI — RACI Matrix · 1–2 days
Do it in a room with the actual people. The argument is the point.
You are done when:
- Staff know what they may and may not do
- Every system has a tier and a named owner
- A forum exists that can actually decide things
Days 61–90 — Assess the risky ones and make it visible.¶
Effort: 6–8 days
- Assess your high-risk systems properly — AI Risk Assessment · 2–3 days each
Test subgroups, not just aggregate accuracy, and check whether human oversight is real by looking at the override rate. - Open the risk register and incident log — Risk Register · 1 day
You need the incident route defined before the first incident, not during it. - Take the first board pack — Board Pack Template · 2 days
Take the assessment and export the Board view — it writes most of it. Lead with what you need, not what you did.
You are done when:
- High-risk systems have completed assessments with owners
- The board has seen a posture and been asked for something
- You have a repeatable cycle rather than a project
AI is landing faster than governance¶
When it fits: The business is shipping AI and you are trying to get in front of it.
Assumes: Governance exists in some form; the problem is pace, not mandate.
Total effort: ~14–18 person-days over 90 days
Days 1–30 — Stop the bleeding.¶
Effort: 5–6 days
- Publish the acceptable AI use policy immediately — Acceptable AI Use Policy · 1 day
Ship a one-page version this week. A perfect policy next quarter is worth less than a usable one now. - Build the inventory, starting with what is already live — AI System Inventory · 3 days
Live systems first; pipeline second. - Add an intake gate so new systems get screened — AI Development & Deployment Standard · 1–2 days
One gate at intake beats a review at launch, because at launch the money is already spent.
You are done when:
- Nothing new goes live unscreened
- You know what is already running
Days 31–60 — Assess what is live and govern what is coming.¶
Effort: 5–7 days
- Run the EU AI Act readiness checklist — EU AI Act — 25-point readiness checklist · Half a day
- Classify and assess high-risk systems — AI Risk Assessment · 2–3 days each
- Bring vendor AI under control — Third-Party AI Risk Policy · 2 days
Most of your exposure is AI switched on inside software you already bought. Start with the release notes.
You are done when:
- Every live system has a tier
- Vendor AI is assessed rather than assumed
Days 61–90 — Make it sustainable.¶
Effort: 4–5 days
- Document your material models — Model Card / Model Risk Documentation · 1–2 days each
- Set up monitoring and the incident route — Issue & Incident Log · 1 day
- Start reporting a small metric set — KPI / KRI Dashboard · 1 day
Six metrics held stable beats twenty that change every quarter — trend is the point.
You are done when:
- Governance runs at the pace of delivery rather than behind it
A regulator or board is asking questions¶
When it fits: Something has prompted scrutiny and you need a defensible answer soon.
Assumes: You have limited time and need evidence, not documents.
Total effort: ~10–14 person-days over 90 days
Days 1–30 — Be able to answer the question.¶
Effort: 5–6 days
- Take the assessment, Regulator view, and export it — EU AI Act — 25-point readiness checklist · 1 day
The export lists what evidence each obligation needs. Assemble against that list rather than guessing what they will ask for. - Produce the inventory, however imperfect — AI System Inventory · 2–3 days
"We are still completing it, here is what we have and when it will be finished" is a far better answer than silence. - Assemble a board pack from what exists — Board Pack Template · 1–2 days
Be honest about the gaps. An amber pack with a plan lands better than a green one that unravels.
You are done when:
- You can state your position with evidence behind it
Days 31–60 — Close the gaps that were exposed.¶
Effort: 3–5 days
- Build the control library and assurance map — Control Library & Assurance Map · 2 days
The blank cells are the finding — obligations nobody is assuring. - Formalise the risk register — Risk Register · 1 day
- Fix the highest-severity gaps from the assessment — AI Risk Assessment · 2–3 days
You are done when:
- Every obligation has a control, an owner, and evidence
Days 61–90 — Show movement.¶
Effort: 2–3 days
- Re-run the assessment and show the delta — Maturity Assessment · Half a day
Movement is more persuasive than any absolute score. Keep the first export so you can show the before. - Report progress to the board — Board Pack Template · 1 day
- Set the ongoing review cadence — Committee Charter (Terms of Reference) · 1 day
You are done when:
- Scrutiny has become a routine reporting cycle
Small or flat organisation¶
This is not a cut-down version
The rest of the kit assumes a committee and named specialist roles. This path deliberately does not — it is a different sequence for organisations that have neither.
When it fits: Fewer than ~150 people, no committee, no dedicated governance role, and this is somebody's third priority.
Assumes: Nothing. This path deliberately does not require a committee to exist.
Total effort: ~6–9 person-days over 90 days
Days 1–30 — The two things that actually reduce risk.¶
Effort: 2–3 days
- List your AI systems in a spreadsheet — AI System Inventory · 1 day
Owner, source, tier, rationale. Four columns is enough. Do not buy a tool. - Publish a one-page AI use policy — Acceptable AI Use Policy · Half a day
Sections 2, 3 and 4 of the template only — the short version, approved tools, and what is never allowed. - Check nothing is prohibited — AI Risk Assessment · Half a day
The eight-item screen. This is the one check with no proportionality argument available.
You are done when:
- You know what you run and staff know the rules
Days 31–60 — Accountability without bureaucracy.¶
Effort: 2–3 days
- Name one accountable person per system — Roles & Responsibilities · Half a day
One person can hold several roles. The only split you must keep is that nobody assures their own work. - Write down who can stop a system — Decision Rights & Escalation · Half a day
Two levels is enough: who decides day to day, and who they escalate to. Keep suspension distributed. - Assess anything that affects people — AI Risk Assessment · 1–2 days
Sections 1, 2 and 4 only — is it allowed, who could it hurt, who is watching. That fits on two pages.
You are done when:
- Every system has a named human, and stopping one is possible
Days 61–90 — Enough evidence to answer a customer or auditor.¶
Effort: 2–3 days
- Start an incident log, even if it is empty — Issue & Incident Log · Half a day
An empty log with a defined route beats no route. You need it before the first incident. - Keep a short risk list — Risk Register · Half a day
A 3x3 matrix and five risks you actually review. - Do a half-day review every quarter — Board Pack Template · Half a day per quarter
A standing 45-minute item on an existing leadership meeting, with real minutes, beats a committee that quietly stops meeting.
You are done when:
- You can evidence governance proportionate to your size
- The cycle survives the person who set it up leaving
Not legal advice
These templates are a head start, not a substitute for professional judgement. Adapt them to your jurisdiction, sector, and risk appetite, and have qualified counsel review anything material before you rely on it.