Templates
AI governance templates, generated from the law on record
Summary
18 free AI governance templates in XLSX and DOCX, generated from the 117 recorded duties, 26 controls and 187 instruments on this site and rebuilt when the records change. Every row that cites a duty links to its record; each file carries its version, dataset hash, date and licence on a README page. No account is needed.
Last built · CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.
Registers
-
Register XLSX and DOCX EU AI ActISO/IEC 42001NIST AI RMFAI System Inventory
One row per AI system: purpose, role under the law, jurisdictions, risk tier, data, owner and review dates, with the recorded duties for each role on a reference sheet.
-
Register XLSX NIST AI RMFISO/IEC 42001EU AI ActAI Risk Register (MIT AI Risk Repository taxonomy)
A risk register whose domain and subdomain dropdowns are the MIT AI Risk Repository taxonomy, with inherent and residual scoring, control lookup and colour-coded thresholds.
-
Register XLSX and DOCX EU AI ActNIST AI RMFAI Agent Registry and Permission Matrix
A register for agents that act — with tools, credentials and autonomy — and a permission matrix stating what each may do alone, with approval, or never.
Checklists
-
Checklist XLSX EU AI ActEU AI Act Role and Risk Classifier
Answer six questions per system and the sheet returns the role, the risk tier and the date its duties apply, looked up from the dated milestones on the EU AI Act record.
-
Checklist XLSX and DOCX EU AI ActISO/IEC 42001NIST AI RMFAI Vendor Due-Diligence Questionnaire
Questions to put to an AI vendor, grouped by governance, data, model, security, transparency, incidents, and insurance and indemnity, scored automatically.
Assessments
-
Assessment DOCX and XLSX EU AI ActFundamental Rights Impact Assessment (FRIA)
The assessment Article 27 of the EU AI Act requires of deployers of high-risk AI: one section per element the article names, with placeholders, plus a register to track completed assessments.
-
Assessment DOCX and XLSX NIST AI RMFISO/IEC 42001Colorado ADMT law (SB 26-189)AI Impact Assessment
A general impact assessment for any AI system: purpose, affected people, harms by risk domain, mitigations and the decision, with the impact-assessment duties recorded across jurisdictions as the checklist.
-
Assessment XLSX ISO/IEC 42001ISO/IEC 42001 Gap Assessment and Statement of Applicability
Every ISO/IEC 42001 clause and control the records map to, with the legal duties behind each, applicability, implementation status and evidence, in the form a Statement of Applicability takes.
-
Assessment DOCX and XLSX NIST AI RMFAI Workforce Impact Assessment
An assessment of what an AI deployment does to jobs: roles affected, tasks automated, timeline, consultation, reskilling and disclosure, with a role inventory sheet.
Policies
-
Policy DOCX EU AI ActISO/IEC 42001AI Acceptable Use Policy
A policy for staff use of AI tools: permitted and prohibited uses, data handling, disclosure and reporting, with the prohibited practices drawn from the law.
-
Policy DOCX and XLSX ISO/IEC 42001NIST AI RMFEU AI ActAI Governance Policy and RACI
The governance policy an AI management system needs, built from the recorded governance duties, with a RACI matrix over every recorded control.
Procedures
-
Procedure DOCX and XLSX EU AI ActColorado ADMT law (SB 26-189)Human Oversight Procedure
A procedure for the humans who oversee an AI system: what they must be able to do, when they intervene, how an override is recorded, drawn from every recorded oversight duty.
-
Procedure DOCX and XLSX EU AI ActNIST AI RMFAI Incident Response Playbook and Log
Detect, contain, report and learn: a playbook built from the recorded incident-handling duties, with the reporting deadlines they set, and a log that computes them.
Kits
-
Kit DOCX and XLSX EU AI ActEU AI Act Article 50 Transparency Kit
Notice texts and a checklist for the transparency duties of Article 50: chatbot disclosure, synthetic content marking, deepfake and emotion-recognition notices, with the application date from the record.
-
Kit DOCX and XLSX Colorado ADMT law (SB 26-189)Colorado AI Act Notices
The notices the Colorado AI Act requires of developers and deployers of high-risk AI: consumer notice, adverse-decision explanation, developer disclosure, Attorney General notification, each built from the recorded duty.
-
Kit DOCX and XLSX EU AI ActISO/IEC 42001AI System Technical Documentation
The technical file a high-risk system needs: one section per element the recorded documentation duties name, with placeholders, plus a document register.
Crosswalks
-
Crosswalk XLSX NIST AI RMFEU AI ActISO/IEC 42001NIST AI RMF ↔ EU AI Act ↔ ISO/IEC 42001 Crosswalk
Every recorded legal duty against the NIST AI RMF and ISO/IEC 42001 references it maps to, with the confidence of each mapping, so what is done for one counts for the others.
-
Crosswalk XLSX EU AI ActColorado ADMT law (SB 26-189)Global AI Regulatory Applicability Matrix
Every binding AI instrument on record, by jurisdiction, with status, application date, who it binds and the use cases it covers, as a matrix to mark which apply to you.
How the templates are made
Each template is described as data: which duties it covers, which sheets and sections it has, and how the records fill them. A daily job turns the obligations, controls, deadlines, framework crosswalks and the MIT AI Risk Repository taxonomy into the files. Every row that cites a duty links to its record, and the record links to the official source and states its verification status. The methodology page explains the trust model behind every record.
When the records change, a template that is affected gets the next version with a changelog; the old address keeps working and the page lists every version. Rebuilds appear in the AI policy updates hub and in the templates feed.
Frequently asked questions
- Are the templates free?
- Yes. Every template downloads without an account or a form, under CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.
- Where does the content come from?
- From the records on this site: obligations, controls, deadlines, framework mappings and the MIT AI Risk Repository taxonomy. Nothing in a file is written by hand; the catalogue says what each template is, and the builder turns the records into sheets and pages.
- What happens when a law changes?
- The library is rebuilt daily. A template whose content changed gets the next version number, a changelog on its page, an entry in the updates hub and in the templates feed, and a line in the weekly digest for subscribers who chose the templates topic.
- Does completing a template make us compliant?
- No. A template is an informational resource, not legal advice. It helps produce the evidence a regulator, customer or auditor asks for; whether a duty applies, and whether it is met, is a judgement the template cannot make.
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.
Frequently asked questions
- Are the templates free?
- Yes. Every template downloads without an account or a form, under CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.
- Where does the content come from?
- From the records on this site: obligations, controls, deadlines, framework mappings and the MIT AI Risk Repository taxonomy. Nothing in a file is written by hand; the catalogue says what each template is, and the builder turns the records into sheets and pages.
- What happens when a law changes?
- The library is rebuilt daily. A template whose content changed gets the next version number, a changelog on its page, an entry in the updates hub and in the templates feed, and a line in the weekly digest for subscribers who chose the templates topic.
- Does completing a template make us compliant?
- No. A template is an informational resource, not legal advice. It helps produce the evidence a regulator, customer or auditor asks for; whether a duty applies, and whether it is met, is a judgement the template cannot make.