AIPolicyTracker
KitFree · sent to your work emailISO/IEC 42001NIST AI RMF

AI Governance Board Reporting Pack

Formats: XLSX and DOCX · Version v1 · Built from dataset bb068ecd9dad · CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.

In brief

The AI Governance Board Reporting Pack is a free XLSX and DOCX kit for ISO/IEC 42001 and NIST AI RMF. A quarterly board report on AI: a dashboard of eight measures, the regulatory deadlines ahead from the records, and a report outline ending in the decisions the board is asked to take.

Format
XLSX and DOCX · Kit
Version
v1, built 28 Sep 2026
Duties cited
19 from 10 instruments
Rows from the records
57
Written for
Provider / developer, Deployer / user organisation, Public authority / government body
Price and licence
Free · CC BY 4.0

What's inside

  • Dashboard sheet: eight measures with quarter-on-quarter trend
  • Upcoming deadlines sheet built from the recorded dates
  • Report document: summary, AI in use, risks and incidents, regulatory outlook, decisions

Preview

The sheets and sections of version v1, as built. Columns marked ▾ have a dropdown; ƒ is a formula.

Sheet: Dashboard · 5 columns · 8 rows from the records
First rows of the Dashboard sheet
MeasureThis quarterLast quarterTrend ▾Comment
AI systems in the inventory
High-risk systems
Systems with a completed impact assessment
Open high and critical risks
Serious incidents this quarter
Staff trained (AI literacy coverage)
Sheet: Upcoming deadlines · 9 columns · 30 rows from the records
First rows of the Upcoming deadlines sheet
DateMilestoneInstrumentJurisdictionSource referenceStatusConfidenceNoteRecord
2022-01-02Law in forceUAE PDPLUnited Arab EmiratespassedhighEntry into force.https://aipolicytracker.org/policies/uae-personal-data-protection-law
2023-06-21Consultation closedUK AI regulation frameworkUnited KingdompassedhighEnd of the white paper consultation period.https://aipolicytracker.org/policies/uk-ai-regulation-white-paper
2023-08-11Presidential assentIndia DPDP ActIndiapassedhighAct No. 22 of 2023.https://aipolicytracker.org/policies/india-dpdp-act
2024-02-06Government response publishedUK AI regulation frameworkUnited KingdompassedhighConfirmed the principles-based approach and asked regulators to publish AI plans.https://aipolicytracker.org/policies/uk-ai-regulation-white-paper
2024-08-01Entry into forceEU AI ActEuropean UnionArticle 113passedhighTwentieth day after publication in the Official Journal.https://aipolicytracker.org/policies/eu-ai-act
2024-09-05Opened for signatureFramework Convention on AI (CETS 225)Council of EuropepassedhighSigning conference in Vilnius, Lithuania.https://aipolicytracker.org/policies/council-of-europe-framework-convention-on-ai
Sheet: Governance duties · 14 columns · 19 rows from the records
First rows of the Governance duties sheet
DutyCategoryInstrumentJurisdictionWho it bindsNatureSource referenceApplies fromWhat it requiresEvidence a reviewer expectsISO/IEC 42001NIST AI RMFVerificationRecord
Establish accountability processes and a risk-management process (guardrails 1 and 2)Governance and accountabilityAustralian Voluntary AI Safety StandardAustraliaDeployer / user organisation, Provider / developerVoluntaryGuardrails 1 and 2Guardrail 1 asks organisations to set up accountability processes including governance, internal capability and a strategy for regulatory compliance; guardrail AI accountability and risk-management documentationClauses 5 and 6GOVERN and MAPSource-linkedhttps://aipolicytracker.org/obligations/australia-vaiss-accountability-and-risk-management
Frontier developers must protect employees who report catastrophic-risk concernsGovernance and accountabilityCalifornia SB 53California (United States)General-purpose AI model provider, Provider / developerLegal requirementLabor Code Section 1107 (as added by SB 53)2026-01-01A frontier developer must not adopt rules or take action that prevent or retaliate against a covered employee for disclosing to the Attorney General, a federal Whistleblower policy and employee notice; Anonymous reporting channel recordsClause 5.1, 7.4; Annex A.3.2GOVERN 4.1, GOVERN 4.3Verified against the official source 26 Sep 2026https://aipolicytracker.org/obligations/us-california-sb-53-whistleblower-protections
Use high-risk AI as instructed, monitor it and inform affected peopleGovernance and accountabilityEU AI ActEuropean UnionDeployer / user organisation, Public authority / government bodyLegal requirementArticle 262027-12-02Deployers of high-risk AI must take technical and organisational measures to use systems according to the instructions, assign human oversight, ensure input datDeployment checklist and oversight assignment; Worker and affected-person noticesAnnex A controls on responsible use of AI systemsMANAGE 3.x, GOVERN 5.xSource-linkedhttps://aipolicytracker.org/obligations/eu-ai-act-deployer-obligations
Providers must meet the full set of provider duties for high-risk AIGovernance and accountabilityEU AI ActEuropean UnionProvider / developerLegal requirementArticle 162027-12-02Article 16 lists what a provider of a high-risk AI system owes: compliance with the Section 2 requirements, its name and contact details on the system or its doProvider compliance matrixClause 5.3; Annex A.3.2GOVERN 1.1, GOVERN 2.1Verified against the official source 26 Sep 2026https://aipolicytracker.org/obligations/eu-ai-act-art-16-provider-obligations
Providers must supply conformity evidence and log access to authorities on requestGovernance and accountabilityEU AI ActEuropean UnionProvider / developerLegal requirementArticle 212027-12-02On a reasoned request from a national competent authority, a provider of a high-risk AI system must supply all the information and documentation needed to show Regulator request handling procedure; Log of authority requests and responsesClause 7.5; Annex A.8.3GOVERN 1.4, GOVERN 4.2Verified against the official source 26 Sep 2026https://aipolicytracker.org/obligations/eu-ai-act-art-21-cooperation-with-authorities
Non-EU providers must appoint an EU authorised representative for high-risk AIGovernance and accountabilityEU AI ActEuropean UnionProvider / developer, Authorised representativeLegal requirementArticle 222027-12-02Before making a high-risk AI system available in the Union, a provider established outside the EU must appoint, by written mandate, an authorised representativeWritten mandate of authorised representative; Representative's documentation checklistClause 5.3; Annex A.10.2GOVERN 2.1, GOVERN 6.1Verified against the official source 26 Sep 2026https://aipolicytracker.org/obligations/eu-ai-act-art-22-authorised-representative

Document outline (DOCX)

  1. AI governance report to the board
  2. 1. Summary
  3. 2. AI in use
  4. 3. Risks and incidents
  5. 4. Regulatory outlook
  6. 5. Decisions requested

How to use it

  1. 1Request the files. Enter your name, company and work email in the form on this page. The XLSX and DOCX download links arrive by email and work for 7 days.
  2. 2Read the README page. It states the version (v1), the dataset it was built from and the licence, so anyone reviewing your copy knows which records it reflects.
  3. 3Fill in your rows. Complete the "Dashboard" sheet for your own systems. Dropdowns, formulas and colour rules are already set.
  4. 4Check the duties against your situation. The "Dashboard", "Upcoming deadlines" and "Governance duties" sheets list the recorded duties with their source references. Mark which apply to you and follow each link to the official text.
  5. 5Complete the document. Work through the DOCX sections (AI governance report to the board) and replace each placeholder with your organisation's answer.
  6. 6Keep the evidence and watch for new versions. Link each completed row to the evidence that supports it. When the law on record changes, this template gets a new version and a changelog on this page.

Duties this template covers (19)

Each is cited in the file with its source reference and a link back to the record.

See all 19 duties →

Legal basis

Version history

Versions of AI Governance Board Reporting Pack
VersionBuiltDatasetWhat changed
v1bb068ecd9dadFirst version, built from dataset bb068ecd9dad.

Only the latest version is served. A rebuild that changes the content adds a version; a rebuild that does not is skipped.

Frequently asked questions

What is in the AI Governance Board Reporting Pack?

Dashboard sheet: eight measures with quarter-on-quarter trend. Upcoming deadlines sheet built from the recorded dates. Report document: summary, AI in use, risks and incidents, regulatory outlook, decisions.

Which duties does it cite?

19 recorded duties from Australian Voluntary AI Safety Standard, California SB 53, EU AI Act and India AI Governance Guidelines, including Guardrails 1 and 2, Labor Code Section 1107 (as added by SB 53), Article 26, Article 16, Article 21 and Article 22. Each row links to the record, and the record to the official source.

Who is it for?

The duties it cites fall on provider / developer, deployer / user organisation and public authority / government body. Whoever owns AI governance for those roles usually completes it, with the system owner supplying the facts.

Is it free?

Yes. Request the XLSX and DOCX with your work email on this page; the download links arrive by email, valid for 7 days. No account and no charge. Licensed CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.

How will I know when it changes?

Version v1 was built on 28 September 2026. The library is rebuilt daily; when a change to the records reaches this template it gets the next version, a changelog below and an entry in the templates feed.

Does completing it make us compliant?

No. It is an informational resource, not legal advice; it helps produce the evidence a regulator, customer or auditor asks for. Whether a duty applies to you is a judgement the template cannot make.

Disclaimer: informational only, not legal advice. Verify every claim against the linked official sources and consult a qualified lawyer before acting.