Guides and free tools
Practical, source-backed guides that connect recorded obligations to what a team actually does, plus free templates, checklists and registers you can preview online and download with a free account.
Featured guides
-
Guide EU AI ActEU AI Act readiness for AI startups: the 90-day path from inventory to evidence
Most startups are providers without knowing it. In 90 days: role, prohibited-use screen, risk classification, high-risk workstreams and an evidence pack, each step linked to the recorded obligation and its deadline.
-
Guide NIST AI RMFISO/IEC 42001AI governance for startups: the four artefacts every buyer and regulator asks for
Skip the year-long programme. Build the four artefacts procurement, insurers and regulators actually request (inventory, risk register, policy, incident process) with free templates and recorded obligations.
-
Guide ISO/IEC 42001EU AI ActISO/IEC 42001 vs the EU AI Act: what certification proves and what it does not
Certification is not conformity. An obligation-by-clause crosswalk that shows where ISO/IEC 42001 helps with the EU AI Act, where it stops, and how CISOs should use both.
-
Guide NIST AI RMFEU AI ActNIST AI RMF vs the EU AI Act: turning a voluntary framework into legal evidence
Built on NIST AI RMF and selling into Europe? See which Govern, Map, Measure and Manage outputs count as EU AI Act evidence, and which binding duties the framework never covers.
Free tools and templates
Preview every field online. Downloads are free and need a free account so we can send you the file link and tell you when a related requirement changes. Templates are provided under CC BY 4.0 for use inside your organisation. They are informational resources, not legal advice, and completing one does not make an organisation compliant with any law or standard.
-
Template Free download EU AI ActISO/IEC 42001NIST AI RMFAI System Inventory Template
Track your AI systems, owners, models, vendors, data use, risk level, review dates and governance evidence in one register.
-
Register Free download NIST AI RMFISO/IEC 42001EU AI ActAI Risk Register Template
Record AI-specific risks per system with likelihood, impact, owner, controls and review dates, mapped to the MIT AI Risk Repository domains.
-
Checklist Free download EU AI ActEU AI Act Readiness Checklist
A dated checklist from inventory and role to high-risk workstreams, general-purpose AI duties and evidence, tied to the obligations recorded on this site.
-
Register Free download EU AI ActISO/IEC 42001NIST AI RMFGlobal AI Regulatory Applicability Matrix
One row per jurisdiction you sell into or operate in: which AI instruments apply, in what role, from when, who supervises, and what evidence each expects.
-
Checklist Free download EU AI ActISO/IEC 42001NIST AI RMFAI Vendor Due Diligence Questionnaire
Questions to send an AI vendor before signature, with the obligation each answer supports and the evidence to request.
-
Checklist Free download EU AI ActNIST AI RMFISO/IEC 42001AI Incident Response Checklist
Detect, triage, contain, report and learn from AI incidents, including the serious-incident reporting duties in the EU AI Act.
-
Guide Free download NIST AI RMFISO/IEC 42001AI Governance 30-Day Starter Plan
A week-by-week plan for a small team to stand up AI governance: inventory, roles, policy, risk register, incident process and first evidence pack.
-
Template Free download EU AI ActISO/IEC 42001AI System Technical Documentation Template
Section-by-section skeleton for the technical documentation regulators and auditors expect for a high-risk or business-critical AI system.
-
Template Free download EU AI ActNIST AI RMFAI Impact Assessment Template (fundamental rights and human rights)
A structured impact assessment for a single AI use: context, affected people, rights at stake, likelihood and severity, mitigations and sign-off, aligned with the EU AI Act FRIA and the Council of Europe HUDERIA method.
-
Template Free download ISO/IEC 42001NIST AI RMFAI Policy Statement Template
A two-page organisational AI policy: scope, principles, acceptable use, approval, oversight, vendors, incidents and review, ready to adapt and sign.