I've been asked to…¶
Most people land here because someone asked them for something. Find the request below and start where it points.
Not sure where you stand?
Take the role-based assessment — answer questions relevant to your role and get a report showing which of these templates close your biggest gaps. Everything stays in your browser.
"Tell the board how exposed we are to the EU AI Act"¶
Usually asked by: Board, CEO, or Audit Committee
Rough effort: 1–2 days for a first pass
Start here, in this order:
- AI System Inventory — The single list of every AI system you build, buy, or have embedded in something you already licence. It is…
- EU AI Act — 25-point readiness checklist — A fast self-assessment of where your organisation stands against the EU AI Act. Work through it, mark what is…
- Board Pack Template — A structured report that gives the board what it needs to discharge its oversight duty: current posture, what…
Before you start
Take the assessment first and export the Board view — it produces most of the pack. Do not present a readiness percentage without an inventory behind it; the first question will be "how many systems is that out of?"
"Find out what AI we're actually using"¶
Usually asked by: Governance, Security, or Legal
Rough effort: 2–3 days including a discovery sweep
Start here, in this order:
- AI System Inventory — The single list of every AI system you build, buy, or have embedded in something you already licence. It is…
- Third-Party AI Risk Policy — How you assess, contract for, and monitor AI you did not build — including AI features that appear inside…
Before you start
Ask teams, then check SaaS release notes, expense claims, and SSO logs. Expect to find two to three times what people report.
"Write us an AI policy"¶
Usually asked by: Exec team or HR
Rough effort: Half a day to draft, 2 weeks to socialise
Start here, in this order:
- Acceptable AI Use Policy — The staff-facing rules for using AI at work: what is encouraged, what needs approval, and what is never…
- Data Classification & Handling Policy — Defines the sensitivity tiers your data falls into and the handling rules for each — including the rules that…
Before you start
Publish a usable one-pager this week rather than a complete one next quarter. Staff are already using AI; the policy is catching up, not getting ahead.
"Prove our AI isn't discriminating"¶
Usually asked by: Legal, DPO, or a customer
Rough effort: 1–2 weeks per system
Start here, in this order:
- AI Risk Assessment — A structured assessment of what could go wrong with a specific AI system, how bad it would be, and what you…
- Model Card / Model Risk Documentation — Standard documentation for a model: what it is for, what it was trained on, how well it performs and for…
- Data Quality Standard — Defines what "good enough" data means in measurable terms — the dimensions, how they are measured, the…
Before you start
Test subgroups, not just aggregate accuracy. A 95% accurate system can be systematically wrong about one group, and that group is who complains.
"Set up an AI governance committee"¶
Usually asked by: Exec sponsor
Rough effort: 1 week to charter, first meeting within a month
Start here, in this order:
- Committee Charter (Terms of Reference) — Establishes the forum where governance decisions are actually made: its authority, membership, quorum,…
- Governance Charter — A short, board-approved mandate that establishes the governance programme: why it exists, what authority it…
- RACI Matrix — Removes ambiguity about who does what. For every significant governance activity it names exactly one…
- Decision Rights & Escalation — States who can decide what, at what threshold, and what happens when people disagree or a decision is needed…
Before you start
Settle quorum and the right to halt a system before the first meeting. A committee that cannot stop anything is advisory.
"Do a DPIA for an AI system"¶
Usually asked by: DPO or Legal
Rough effort: 1–2 weeks
Start here, in this order:
- Processing & DPIA Log — The record of personal data processing activities and the impact assessments that cover them — the point…
- AI Risk Assessment — A structured assessment of what could go wrong with a specific AI system, how bad it would be, and what you…
- Data Classification & Handling Policy — Defines the sensitivity tiers your data falls into and the handling rules for each — including the rules that…
Before you start
Run it alongside the AI risk assessment and cross-reference them. Decide your answer on erasure before you build, not after.
"Assess an AI vendor before we sign"¶
Usually asked by: Procurement or Security
Rough effort: 2–3 days
Start here, in this order:
- Third-Party AI Risk Policy — How you assess, contract for, and monitor AI you did not build — including AI features that appear inside…
- AI System Inventory — The single list of every AI system you build, buy, or have embedded in something you already licence. It is…
Before you start
The two questions that matter most are whether your data trains their model, and whether you are told when the model changes.
"Show an auditor our AI controls work"¶
Usually asked by: Internal Audit or an external assessor
Rough effort: 1–2 weeks to assemble
Start here, in this order:
- Control Library & Assurance Map — Maps obligations to the controls that satisfy them, names an owner for each, and records how you would…
- Risk Register — The live record of data and AI risks: what could go wrong, how likely and how bad, what you are doing about…
- Issue & Incident Log — The record of what went wrong, what you did, and what changed as a result. It is both a management tool and…
Before you start
Take the assessment and export the Regulator view — it lists what evidence each obligation needs. Assemble against that list rather than guessing.
"Document a model before it goes live"¶
Usually asked by: ML lead or a release gate
Rough effort: 1–2 days per model
Start here, in this order:
- Model Card / Model Risk Documentation — Standard documentation for a model: what it is for, what it was trained on, how well it performs and for…
- AI Development & Deployment Standard — The engineering-facing requirements for building, testing, deploying, and operating AI systems — the…
Before you start
Write the limitations section first and honestly. A model card with no limitations tells a reader you did not look.
"Work out where to start with all of this"¶
Usually asked by: You, having just been handed the brief
Rough effort: Half a day
Start here, in this order:
- Maturity Assessment — A structured baseline of how capable your governance actually is today, across the dimensions that matter, so…
- AI System Inventory — The single list of every AI system you build, buy, or have embedded in something you already licence. It is…
- Governance Charter — A short, board-approved mandate that establishes the governance programme: why it exists, what authority it…
Before you start
Baseline honestly, then get a mandate in writing. An optimistic baseline destroys the credibility of every improvement you later report.
Not legal advice
These templates are a head start, not a substitute for professional judgement. Adapt them to your jurisdiction, sector, and risk appetite, and have qualified counsel review anything material before you rely on it.