AIPolicyTracker
PolicyFree · no accountISO/IEC 42001NIST AI RMFEU AI Act

AI Governance Policy and RACI

The governance policy an AI management system needs, built from the recorded governance duties, with a RACI matrix over every recorded control.

Formats: DOCX and XLSX · Version v1 · Built from dataset 914895c3103e · CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.

What's inside

  • Document: purpose, principles, roles, the governance duties on record and how each is met, review cycle
  • RACI sheet: every recorded control against eight roles, R/A/C/I dropdowns
  • Controls sheet: what each control is for and which duties it satisfies

Preview

The sheets and sections of version v1, as built. Columns marked ▾ have a dropdown; ƒ is a formula.

Sheet: RACI · 12 columns · 26 rows from the records
First rows of the RACI sheet
ControlKindBoard ▾Executive sponsor ▾AI governance lead ▾Product owner ▾Engineering lead ▾Legal and compliance ▾Security ▾Data protection ▾Accountable count ƒRecord
AI governance policy and accountability structurePolicy=https://aipolicytracker.org/controls/ai-governance-policy-and-accountability
AI impact and fundamental-rights impact assessmentProcess=https://aipolicytracker.org/controls/ai-impact-assessment
AI incident management and regulatory reportingProcess=https://aipolicytracker.org/controls/ai-incident-management-and-reporting
AI interaction and use disclosure noticesProcess=https://aipolicytracker.org/controls/ai-interaction-and-use-disclosure
AI literacy and role-based training programmeTraining=https://aipolicytracker.org/controls/ai-literacy-and-role-based-training
AI risk assessment and lifecycle risk registerProcess=https://aipolicytracker.org/controls/ai-risk-assessment

R responsible, A accountable, C consulted, I informed. A control with no A, or two, turns red.

Sheet: Controls · 11 columns · 26 rows from the records
First rows of the Controls sheet
ControlKindPurposeTypical ownerFrequencyDuties it satisfiesDuties it supportsEvidence it producesISO/IEC 42001NIST AI RMFRecord
AI governance policy and accountability structurePolicyGives the organisation a single approved statement of how it will develop, buy and use AI, and names the people who are answerable for it, so that every other AExecutive sponsor for AIannual97AI policy; Board or executive approval of the AI policy; AI governance forum minutes; AI responsibility mapClause 5.1, 5.2, 5.3, 9.3; Annex A.2, A.3GOVERN 1.1, 1.2, 1.3, 2.1, 3.1https://aipolicytracker.org/controls/ai-governance-policy-and-accountability
AI impact and fundamental-rights impact assessmentProcessExamines how a planned AI use will affect the people, groups and communities it touches, with particular attention to discrimination and rights, and records theAI system ownerper_system47AI impact assessment; Impact assessment approval; Impact assessment procedure and templateClause 6.1.4, 8.4; Annex A.5MAP 5.1, 5.2; MEASURE 2.11https://aipolicytracker.org/controls/ai-impact-assessment
AI incident management and regulatory reportingProcessEnsures that harm or near-harm caused by an AI system is detected, contained, investigated and, where a rule requires it, reported to the right authority and afIncident coordinatorcontinuous95AI incident response playbook; AI incident record; Incident report to an authorityClause 10.2; Annex A.8.3, A.8.4MANAGE 4.1, 4.3; GOVERN 4.3, 6.2https://aipolicytracker.org/controls/ai-incident-management-and-reporting
AI interaction and use disclosure noticesProcessTells people, in plain language and at the right moment, that they are interacting with an AI system, that AI is being used in a decision about them or that theProduct owneron_material_change143AI interaction or use notice; Notice catalogue; Notice wording approvalAnnex A.8.2, A.8.5MEASURE 2.8; GOVERN 5.1https://aipolicytracker.org/controls/ai-interaction-and-use-disclosure
AI literacy and role-based training programmeTrainingGives everyone who builds, buys, operates or is overseen by AI systems the knowledge they need for their role, from general awareness to the specific skills of Learning and development leadannual13AI training completion records; Role-to-curriculum training matrix; AI training curriculum and materialsClause 7.2, 7.3; Annex A.4.6GOVERN 2.2, 4.1https://aipolicytracker.org/controls/ai-literacy-and-role-based-training
AI risk assessment and lifecycle risk registerProcessIdentifies, rates and treats the risks that a specific AI system poses to health, safety, rights and the organisation itself, and keeps that analysis alive fromAI system ownerper_system75AI system risk assessment; Per-system AI risk register; Residual-risk acceptanceClause 6.1.2, 6.1.3, 8.2, 8.3MAP 3, MAP 4, MANAGE 1.2, 1.3, 2.1https://aipolicytracker.org/controls/ai-risk-assessment
Sheet: Governance duties · 14 columns · 20 rows from the records
First rows of the Governance duties sheet
DutyCategoryInstrumentJurisdictionWho it bindsNatureSource referenceApplies fromWhat it requiresEvidence a reviewer expectsISO/IEC 42001NIST AI RMFVerificationRecord
Establish accountability processes and a risk-management process (guardrails 1 and 2)Governance and accountabilityAustralian Voluntary AI Safety StandardAustraliaDeployer / user organisation, Provider / developerVoluntaryGuardrails 1 and 2Guardrail 1 asks organisations to set up accountability processes including governance, internal capability and a strategy for regulatory compliance; guardrail AI accountability and risk-management documentationClauses 5 and 6GOVERN and MAPSource-linkedhttps://aipolicytracker.org/obligations/australia-vaiss-accountability-and-risk-management
Frontier developers must protect employees who report catastrophic-risk concernsGovernance and accountabilityCalifornia SB 53California (United States)General-purpose AI model provider, Provider / developerLegal requirementLabor Code Section 1107 (as added by SB 53)2026-01-01A frontier developer must not adopt rules or take action that prevent or retaliate against a covered employee for disclosing to the Attorney General, a federal Whistleblower policy and employee notice; Anonymous reporting channel recordsClause 5.1, 7.4; Annex A.3.2GOVERN 4.1, GOVERN 4.3Verified against the official source 26 Sep 2026https://aipolicytracker.org/obligations/us-california-sb-53-whistleblower-protections
Operate a quality management systemQuality management systemEU AI ActEuropean UnionProvider / developerLegal requirementArticle 172026-08-02Providers of high-risk AI systems must put in place a documented quality management system covering regulatory-compliance strategy, design and development proceQMS manual and proceduresWhole management system (Clauses 4–10)GOVERN functionSource-linkedhttps://aipolicytracker.org/obligations/eu-ai-act-quality-management-system
Use high-risk AI as instructed, monitor it and inform affected peopleGovernance and accountabilityEU AI ActEuropean UnionDeployer / user organisation, Public authority / government bodyLegal requirementArticle 262026-08-02Deployers of high-risk AI must take technical and organisational measures to use systems according to the instructions, assign human oversight, ensure input datDeployment checklist and oversight assignment; Worker and affected-person noticesAnnex A controls on responsible use of AI systemsMANAGE 3.x, GOVERN 5.xSource-linkedhttps://aipolicytracker.org/obligations/eu-ai-act-deployer-obligations
Providers must meet the full set of provider duties for high-risk AIGovernance and accountabilityEU AI ActEuropean UnionProvider / developerLegal requirementArticle 162026-08-02Article 16 lists what a provider of a high-risk AI system owes: compliance with the Section 2 requirements, its name and contact details on the system or its doProvider compliance matrixClause 5.3; Annex A.3.2GOVERN 1.1, GOVERN 2.1Verified against the official source 26 Sep 2026https://aipolicytracker.org/obligations/eu-ai-act-art-16-provider-obligations
Providers must supply conformity evidence and log access to authorities on requestGovernance and accountabilityEU AI ActEuropean UnionProvider / developerLegal requirementArticle 212026-08-02On a reasoned request from a national competent authority, a provider of a high-risk AI system must supply all the information and documentation needed to show Regulator request handling procedure; Log of authority requests and responsesClause 7.5; Annex A.8.3GOVERN 1.4, GOVERN 4.2Verified against the official source 26 Sep 2026https://aipolicytracker.org/obligations/eu-ai-act-art-21-cooperation-with-authorities

Document outline (DOCX)

  1. 1. Purpose
  2. 2. Principles
  3. 3. Roles and accountabilities
  4. 4. The controls the organisation operates
  5. 5. Governance duties on record and how each is met
  6. Establish accountability processes and a risk-management process (guardrails 1 and 2)
  7. Frontier developers must protect employees who report catastrophic-risk concerns
  8. Operate a quality management system
  9. Use high-risk AI as instructed, monitor it and inform affected people
  10. Providers must meet the full set of provider duties for high-risk AI
  11. Providers must supply conformity evidence and log access to authorities on request
  12. Non-EU providers must appoint an EU authorised representative for high-risk AI
  13. Deployers, distributors and importers must assume provider duties when they rebrand or substantially modify high-risk AI
  14. Law-enforcement deployers must obtain authorisation for post-remote biometric identification and report annually
  15. Providers of GPAI models must notify the Commission within two weeks of meeting the systemic-risk threshold
  16. Non-EU providers of GPAI models must appoint an EU authorised representative
  17. Adopt the guiding principles and risk-based governance (voluntary)
  18. Government bodies to promote ethical, responsible and inclusive AI (policy commitment)
  19. Establish internal governance structures and measures for AI
  20. Operators of high-impact AI must prepare user-protection measures and keep records of their safety and trust measures
  21. Foreign AI business operators above the threshold must designate a domestic representative in Korea
  22. Government commitment to AI ethics, governance and regulation (strategy objective)
  23. Use AI in ways that are fair and do not discriminate unlawfully
  24. Establish accountability and governance for AI
  25. Establish AI governance policies, roles and accountability (Govern)
  26. 6. Review

Duties this template covers (20)

Each is cited in the file with its source reference and a link back to the record.

See all 20 duties →

Legal basis

Version history

Versions of AI Governance Policy and RACI
VersionBuiltDatasetWhat changed
v1914895c3103eFirst version, built from dataset 914895c3103e.

Only the latest version is served. A rebuild that changes the content adds a version; a rebuild that does not is skipped.

Frequently asked questions

Is the AI Governance Policy and RACI free?
Yes. Download the DOCX and XLSX without an account, under CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.
What is it generated from?
Version v1 was built on 26 September 2026 from dataset 914895c3103e: 92 recorded duties are cited in it, drawn from 10 instruments. Every row that cites a duty links to the record, and the record links to the official source.
How will I know when it changes?
The library is rebuilt daily. When a change to the records reaches this template it gets the next version, a changelog in the version history below, an entry in the AI policy updates hub and the templates feed, and a line in the weekly digest for subscribers of the templates topic.
Does completing it make us compliant?
No. It is an informational resource, not legal advice; it helps produce the evidence a regulator, customer or auditor asks for. Whether a duty applies to you is a judgement the template cannot make.

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.

Frequently asked questions

Is the AI Governance Policy and RACI free?
Yes. Download the DOCX and XLSX without an account, under CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.
What is it generated from?
Version v1 was built on 26 September 2026 from dataset 914895c3103e: 92 recorded duties are cited in it, drawn from 10 instruments. Every row that cites a duty links to the record, and the record links to the official source.
How will I know when it changes?
The library is rebuilt daily. When a change to the records reaches this template it gets the next version, a changelog in the version history below, an entry in the AI policy updates hub and the templates feed, and a line in the weekly digest for subscribers of the templates topic.
Does completing it make us compliant?
No. It is an informational resource, not legal advice; it helps produce the evidence a regulator, customer or auditor asks for. Whether a duty applies to you is a judgement the template cannot make.