AI Governance Board Reporting Pack
In brief
The AI Governance Board Reporting Pack is a free XLSX and DOCX kit for ISO/IEC 42001 and NIST AI RMF. A quarterly board report on AI: a dashboard of eight measures, the regulatory deadlines ahead from the records, and a report outline ending in the decisions the board is asked to take.
- Format
- XLSX and DOCX · Kit
- Version
- v1, built 28 Sep 2026
- Duties cited
- 19 from 10 instruments
- Rows from the records
- 57
- Frameworks
- ISO/IEC 42001, NIST AI RMF
- Written for
- Provider / developer, Deployer / user organisation, Public authority / government body
- Price and licence
- Free · CC BY 4.0
What's inside
- Dashboard sheet: eight measures with quarter-on-quarter trend
- Upcoming deadlines sheet built from the recorded dates
- Report document: summary, AI in use, risks and incidents, regulatory outlook, decisions
Preview
The sheets and sections of version v1, as built. Columns marked ▾ have a dropdown; ƒ is a formula.
Sheet: Dashboard
| Measure | This quarter | Last quarter | Trend ▾ | Comment |
|---|---|---|---|---|
| AI systems in the inventory | ||||
| High-risk systems | ||||
| Systems with a completed impact assessment | ||||
| Open high and critical risks | ||||
| Serious incidents this quarter | ||||
| Staff trained (AI literacy coverage) |
Sheet: Upcoming deadlines
| Date | Milestone | Instrument | Jurisdiction | Source reference | Status | Confidence | Note | Record |
|---|---|---|---|---|---|---|---|---|
| 2022-01-02 | Law in force | UAE PDPL | United Arab Emirates | passed | high | Entry into force. | https://aipolicytracker.org/policies/uae-personal-data-protection-law | |
| 2023-06-21 | Consultation closed | UK AI regulation framework | United Kingdom | passed | high | End of the white paper consultation period. | https://aipolicytracker.org/policies/uk-ai-regulation-white-paper | |
| 2023-08-11 | Presidential assent | India DPDP Act | India | passed | high | Act No. 22 of 2023. | https://aipolicytracker.org/policies/india-dpdp-act | |
| 2024-02-06 | Government response published | UK AI regulation framework | United Kingdom | passed | high | Confirmed the principles-based approach and asked regulators to publish AI plans. | https://aipolicytracker.org/policies/uk-ai-regulation-white-paper | |
| 2024-08-01 | Entry into force | EU AI Act | European Union | Article 113 | passed | high | Twentieth day after publication in the Official Journal. | https://aipolicytracker.org/policies/eu-ai-act |
| 2024-09-05 | Opened for signature | Framework Convention on AI (CETS 225) | Council of Europe | passed | high | Signing conference in Vilnius, Lithuania. | https://aipolicytracker.org/policies/council-of-europe-framework-convention-on-ai |
Sheet: Governance duties
| Duty | Category | Instrument | Jurisdiction | Who it binds | Nature | Source reference | Applies from | What it requires | Evidence a reviewer expects | ISO/IEC 42001 | NIST AI RMF | Verification | Record |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Establish accountability processes and a risk-management process (guardrails 1 and 2) | Governance and accountability | Australian Voluntary AI Safety Standard | Australia | Deployer / user organisation, Provider / developer | Voluntary | Guardrails 1 and 2 | Guardrail 1 asks organisations to set up accountability processes including governance, internal capability and a strategy for regulatory compliance; guardrail | AI accountability and risk-management documentation | Clauses 5 and 6 | GOVERN and MAP | Source-linked | https://aipolicytracker.org/obligations/australia-vaiss-accountability-and-risk-management | |
| Frontier developers must protect employees who report catastrophic-risk concerns | Governance and accountability | California SB 53 | California (United States) | General-purpose AI model provider, Provider / developer | Legal requirement | Labor Code Section 1107 (as added by SB 53) | 2026-01-01 | A frontier developer must not adopt rules or take action that prevent or retaliate against a covered employee for disclosing to the Attorney General, a federal | Whistleblower policy and employee notice; Anonymous reporting channel records | Clause 5.1, 7.4; Annex A.3.2 | GOVERN 4.1, GOVERN 4.3 | Verified against the official source 26 Sep 2026 | https://aipolicytracker.org/obligations/us-california-sb-53-whistleblower-protections |
| Use high-risk AI as instructed, monitor it and inform affected people | Governance and accountability | EU AI Act | European Union | Deployer / user organisation, Public authority / government body | Legal requirement | Article 26 | 2027-12-02 | Deployers of high-risk AI must take technical and organisational measures to use systems according to the instructions, assign human oversight, ensure input dat | Deployment checklist and oversight assignment; Worker and affected-person notices | Annex A controls on responsible use of AI systems | MANAGE 3.x, GOVERN 5.x | Source-linked | https://aipolicytracker.org/obligations/eu-ai-act-deployer-obligations |
| Providers must meet the full set of provider duties for high-risk AI | Governance and accountability | EU AI Act | European Union | Provider / developer | Legal requirement | Article 16 | 2027-12-02 | Article 16 lists what a provider of a high-risk AI system owes: compliance with the Section 2 requirements, its name and contact details on the system or its do | Provider compliance matrix | Clause 5.3; Annex A.3.2 | GOVERN 1.1, GOVERN 2.1 | Verified against the official source 26 Sep 2026 | https://aipolicytracker.org/obligations/eu-ai-act-art-16-provider-obligations |
| Providers must supply conformity evidence and log access to authorities on request | Governance and accountability | EU AI Act | European Union | Provider / developer | Legal requirement | Article 21 | 2027-12-02 | On a reasoned request from a national competent authority, a provider of a high-risk AI system must supply all the information and documentation needed to show | Regulator request handling procedure; Log of authority requests and responses | Clause 7.5; Annex A.8.3 | GOVERN 1.4, GOVERN 4.2 | Verified against the official source 26 Sep 2026 | https://aipolicytracker.org/obligations/eu-ai-act-art-21-cooperation-with-authorities |
| Non-EU providers must appoint an EU authorised representative for high-risk AI | Governance and accountability | EU AI Act | European Union | Provider / developer, Authorised representative | Legal requirement | Article 22 | 2027-12-02 | Before making a high-risk AI system available in the Union, a provider established outside the EU must appoint, by written mandate, an authorised representative | Written mandate of authorised representative; Representative's documentation checklist | Clause 5.3; Annex A.10.2 | GOVERN 2.1, GOVERN 6.1 | Verified against the official source 26 Sep 2026 | https://aipolicytracker.org/obligations/eu-ai-act-art-22-authorised-representative |
Document outline (DOCX)
- AI governance report to the board
- 1. Summary
- 2. AI in use
- 3. Risks and incidents
- 4. Regulatory outlook
- 5. Decisions requested
How to use it
- 1Request the files. Enter your name, company and work email in the form on this page. The XLSX and DOCX download links arrive by email and work for 7 days.
- 2Read the README page. It states the version (v1), the dataset it was built from and the licence, so anyone reviewing your copy knows which records it reflects.
- 3Fill in your rows. Complete the "Dashboard" sheet for your own systems. Dropdowns, formulas and colour rules are already set.
- 4Check the duties against your situation. The "Dashboard", "Upcoming deadlines" and "Governance duties" sheets list the recorded duties with their source references. Mark which apply to you and follow each link to the official text.
- 5Complete the document. Work through the DOCX sections (AI governance report to the board) and replace each placeholder with your organisation's answer.
- 6Keep the evidence and watch for new versions. Link each completed row to the evidence that supports it. When the law on record changes, this template gets a new version and a changelog on this page.
Duties this template covers (19)
Each is cited in the file with its source reference and a link back to the record.
- Establish accountability processes and a risk-management process (guardrails 1 and 2)
- Frontier developers must protect employees who report catastrophic-risk concerns
- Use high-risk AI as instructed, monitor it and inform affected people
- Providers must meet the full set of provider duties for high-risk AI
- Providers must supply conformity evidence and log access to authorities on request
- Non-EU providers must appoint an EU authorised representative for high-risk AI
- Deployers, distributors and importers must assume provider duties when they rebrand or substantially modify high-risk AI
- Law-enforcement deployers must obtain authorisation for post-remote biometric identification and report annually
- Providers of GPAI models must notify the Commission within two weeks of meeting the systemic-risk threshold
- Non-EU providers of GPAI models must appoint an EU authorised representative
- Adopt the guiding principles and risk-based governance (voluntary)
- Government bodies to promote ethical, responsible and inclusive AI (policy commitment)
Legal basis
Version history
| Version | Built | Dataset | What changed |
|---|---|---|---|
| v1 | bb068ecd9dad | First version, built from dataset bb068ecd9dad. |
Only the latest version is served. A rebuild that changes the content adds a version; a rebuild that does not is skipped.
Frequently asked questions
What is in the AI Governance Board Reporting Pack?
Dashboard sheet: eight measures with quarter-on-quarter trend. Upcoming deadlines sheet built from the recorded dates. Report document: summary, AI in use, risks and incidents, regulatory outlook, decisions.
Which duties does it cite?
19 recorded duties from Australian Voluntary AI Safety Standard, California SB 53, EU AI Act and India AI Governance Guidelines, including Guardrails 1 and 2, Labor Code Section 1107 (as added by SB 53), Article 26, Article 16, Article 21 and Article 22. Each row links to the record, and the record to the official source.
Who is it for?
The duties it cites fall on provider / developer, deployer / user organisation and public authority / government body. Whoever owns AI governance for those roles usually completes it, with the system owner supplying the facts.
Is it free?
Yes. Request the XLSX and DOCX with your work email on this page; the download links arrive by email, valid for 7 days. No account and no charge. Licensed CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.
How will I know when it changes?
Version v1 was built on 28 September 2026. The library is rebuilt daily; when a change to the records reaches this template it gets the next version, a changelog below and an entry in the templates feed.
Does completing it make us compliant?
No. It is an informational resource, not legal advice; it helps produce the evidence a regulator, customer or auditor asks for. Whether a duty applies to you is a judgement the template cannot make.
Disclaimer: informational only, not legal advice. Verify every claim against the linked official sources and consult a qualified lawyer before acting.