Skip to content

30/60/90-day plans

Knowing which templates you need is not the same as knowing what order to do them in. These are sequenced plans with rough effort, so you can plan resource and tell a sponsor when things will land.

Effort is for one person, not full time

Estimates are person-days for whoever is running this, assuming it is not their only job. They cover a competent first pass — not a polished, audited version.

Pick your path

Path When it fits Total effort
Standing up a programme from nothing Nobody owns AI governance yet, or someone has just been handed the brief. ~18–24 person-days over 90 days
AI is landing faster than governance The business is shipping AI and you are trying to get in front of it. ~14–18 person-days over 90 days
A regulator or board is asking questions Something has prompted scrutiny and you need a defensible answer soon. ~10–14 person-days over 90 days
Small or flat organisation Fewer than ~150 people, no committee, no dedicated governance role, and this is somebody's third priority. ~6–9 person-days over 90 days

Standing up a programme from nothing

When it fits: Nobody owns AI governance yet, or someone has just been handed the brief.
Assumes: You can get a decision-maker in a room, and you have a few days a week.
Total effort: ~18–24 person-days over 90 days

Days 1–30 — Know what you have and get a mandate.

Effort: 6–8 days

  1. Baseline honestly with the maturity assessmentMaturity Assessment · 1 day
    Score what is true, not what is intended. This number is the benchmark every later improvement is measured against.
  2. Run a discovery sweep and build the AI inventoryAI System Inventory · 3–4 days
    Ask teams, then check SaaS release notes, expenses, and SSO logs. Budget for finding two to three times what people report.
  3. Screen everything for prohibited practicesAI Risk Assessment · 1 day
    Prohibited practices have been in force since February 2025. If you find one, this becomes urgent and everything else waits.
  4. Get a written mandateGovernance Charter · 1–2 days
    Two pages. The clauses that matter are the authority to halt a system and a named executive sponsor.

You are done when:

  • You can name every AI system in the organisation
  • Someone senior has signed something saying you own this
  • You know whether you have a prohibited-practice problem

Days 31–60 — Put the rules and the decision-making in place.

Effort: 6–8 days

  1. Publish the acceptable AI use policyAcceptable AI Use Policy · 1 day to draft
    The highest-value document in the kit for the effort. Staff are already using AI; this is catching up, not getting ahead.
  2. Classify every system by risk tierAI System Inventory · 2 days
    Record the rationale, not just the label.
  3. Stand up the committee and agree decision rightsCommittee Charter (Terms of Reference) · 2 days
    Settle quorum and who can halt a live system before the first meeting, not during the first incident.
  4. Agree the RACIRACI Matrix · 1–2 days
    Do it in a room with the actual people. The argument is the point.

You are done when:

  • Staff know what they may and may not do
  • Every system has a tier and a named owner
  • A forum exists that can actually decide things

Days 61–90 — Assess the risky ones and make it visible.

Effort: 6–8 days

  1. Assess your high-risk systems properlyAI Risk Assessment · 2–3 days each
    Test subgroups, not just aggregate accuracy, and check whether human oversight is real by looking at the override rate.
  2. Open the risk register and incident logRisk Register · 1 day
    You need the incident route defined before the first incident, not during it.
  3. Take the first board packBoard Pack Template · 2 days
    Take the assessment and export the Board view — it writes most of it. Lead with what you need, not what you did.

You are done when:

  • High-risk systems have completed assessments with owners
  • The board has seen a posture and been asked for something
  • You have a repeatable cycle rather than a project

AI is landing faster than governance

When it fits: The business is shipping AI and you are trying to get in front of it.
Assumes: Governance exists in some form; the problem is pace, not mandate.
Total effort: ~14–18 person-days over 90 days

Days 1–30 — Stop the bleeding.

Effort: 5–6 days

  1. Publish the acceptable AI use policy immediatelyAcceptable AI Use Policy · 1 day
    Ship a one-page version this week. A perfect policy next quarter is worth less than a usable one now.
  2. Build the inventory, starting with what is already liveAI System Inventory · 3 days
    Live systems first; pipeline second.
  3. Add an intake gate so new systems get screenedAI Development & Deployment Standard · 1–2 days
    One gate at intake beats a review at launch, because at launch the money is already spent.

You are done when:

  • Nothing new goes live unscreened
  • You know what is already running

Days 31–60 — Assess what is live and govern what is coming.

Effort: 5–7 days

  1. Run the EU AI Act readiness checklistEU AI Act — 25-point readiness checklist · Half a day
  2. Classify and assess high-risk systemsAI Risk Assessment · 2–3 days each
  3. Bring vendor AI under controlThird-Party AI Risk Policy · 2 days
    Most of your exposure is AI switched on inside software you already bought. Start with the release notes.

You are done when:

  • Every live system has a tier
  • Vendor AI is assessed rather than assumed

Days 61–90 — Make it sustainable.

Effort: 4–5 days

  1. Document your material modelsModel Card / Model Risk Documentation · 1–2 days each
  2. Set up monitoring and the incident routeIssue & Incident Log · 1 day
  3. Start reporting a small metric setKPI / KRI Dashboard · 1 day
    Six metrics held stable beats twenty that change every quarter — trend is the point.

You are done when:

  • Governance runs at the pace of delivery rather than behind it

A regulator or board is asking questions

When it fits: Something has prompted scrutiny and you need a defensible answer soon.
Assumes: You have limited time and need evidence, not documents.
Total effort: ~10–14 person-days over 90 days

Days 1–30 — Be able to answer the question.

Effort: 5–6 days

  1. Take the assessment, Regulator view, and export itEU AI Act — 25-point readiness checklist · 1 day
    The export lists what evidence each obligation needs. Assemble against that list rather than guessing what they will ask for.
  2. Produce the inventory, however imperfectAI System Inventory · 2–3 days
    "We are still completing it, here is what we have and when it will be finished" is a far better answer than silence.
  3. Assemble a board pack from what existsBoard Pack Template · 1–2 days
    Be honest about the gaps. An amber pack with a plan lands better than a green one that unravels.

You are done when:

  • You can state your position with evidence behind it

Days 31–60 — Close the gaps that were exposed.

Effort: 3–5 days

  1. Build the control library and assurance mapControl Library & Assurance Map · 2 days
    The blank cells are the finding — obligations nobody is assuring.
  2. Formalise the risk registerRisk Register · 1 day
  3. Fix the highest-severity gaps from the assessmentAI Risk Assessment · 2–3 days

You are done when:

  • Every obligation has a control, an owner, and evidence

Days 61–90 — Show movement.

Effort: 2–3 days

  1. Re-run the assessment and show the deltaMaturity Assessment · Half a day
    Movement is more persuasive than any absolute score. Keep the first export so you can show the before.
  2. Report progress to the boardBoard Pack Template · 1 day
  3. Set the ongoing review cadenceCommittee Charter (Terms of Reference) · 1 day

You are done when:

  • Scrutiny has become a routine reporting cycle

Small or flat organisation

This is not a cut-down version

The rest of the kit assumes a committee and named specialist roles. This path deliberately does not — it is a different sequence for organisations that have neither.

When it fits: Fewer than ~150 people, no committee, no dedicated governance role, and this is somebody's third priority.
Assumes: Nothing. This path deliberately does not require a committee to exist.
Total effort: ~6–9 person-days over 90 days

Days 1–30 — The two things that actually reduce risk.

Effort: 2–3 days

  1. List your AI systems in a spreadsheetAI System Inventory · 1 day
    Owner, source, tier, rationale. Four columns is enough. Do not buy a tool.
  2. Publish a one-page AI use policyAcceptable AI Use Policy · Half a day
    Sections 2, 3 and 4 of the template only — the short version, approved tools, and what is never allowed.
  3. Check nothing is prohibitedAI Risk Assessment · Half a day
    The eight-item screen. This is the one check with no proportionality argument available.

You are done when:

  • You know what you run and staff know the rules

Days 31–60 — Accountability without bureaucracy.

Effort: 2–3 days

  1. Name one accountable person per systemRoles & Responsibilities · Half a day
    One person can hold several roles. The only split you must keep is that nobody assures their own work.
  2. Write down who can stop a systemDecision Rights & Escalation · Half a day
    Two levels is enough: who decides day to day, and who they escalate to. Keep suspension distributed.
  3. Assess anything that affects peopleAI Risk Assessment · 1–2 days
    Sections 1, 2 and 4 only — is it allowed, who could it hurt, who is watching. That fits on two pages.

You are done when:

  • Every system has a named human, and stopping one is possible

Days 61–90 — Enough evidence to answer a customer or auditor.

Effort: 2–3 days

  1. Start an incident log, even if it is emptyIssue & Incident Log · Half a day
    An empty log with a defined route beats no route. You need it before the first incident.
  2. Keep a short risk listRisk Register · Half a day
    A 3x3 matrix and five risks you actually review.
  3. Do a half-day review every quarterBoard Pack Template · Half a day per quarter
    A standing 45-minute item on an existing leadership meeting, with real minutes, beats a committee that quietly stops meeting.

You are done when:

  • You can evidence governance proportionate to your size
  • The cycle survives the person who set it up leaving

Not legal advice

These templates are a head start, not a substitute for professional judgement. Adapt them to your jurisdiction, sector, and risk appetite, and have qualified counsel review anything material before you rely on it.