PolicyFree · no accountISO/IEC 42001NIST AI RMFEU AI Act
AI Governance Policy and RACI
The governance policy an AI management system needs, built from the recorded governance duties, with a RACI matrix over every recorded control.
What's inside
- Document: purpose, principles, roles, the governance duties on record and how each is met, review cycle
- RACI sheet: every recorded control against eight roles, R/A/C/I dropdowns
- Controls sheet: what each control is for and which duties it satisfies
Preview
The sheets and sections of version v1, as built. Columns marked ▾ have a dropdown; ƒ is a formula.
Sheet: RACI
| Control | Kind | Board ▾ | Executive sponsor ▾ | AI governance lead ▾ | Product owner ▾ | Engineering lead ▾ | Legal and compliance ▾ | Security ▾ | Data protection ▾ | Accountable count ƒ | Record |
|---|---|---|---|---|---|---|---|---|---|---|---|
| AI governance policy and accountability structure | Policy | = | https://aipolicytracker.org/controls/ai-governance-policy-and-accountability | ||||||||
| AI impact and fundamental-rights impact assessment | Process | = | https://aipolicytracker.org/controls/ai-impact-assessment | ||||||||
| AI incident management and regulatory reporting | Process | = | https://aipolicytracker.org/controls/ai-incident-management-and-reporting | ||||||||
| AI interaction and use disclosure notices | Process | = | https://aipolicytracker.org/controls/ai-interaction-and-use-disclosure | ||||||||
| AI literacy and role-based training programme | Training | = | https://aipolicytracker.org/controls/ai-literacy-and-role-based-training | ||||||||
| AI risk assessment and lifecycle risk register | Process | = | https://aipolicytracker.org/controls/ai-risk-assessment |
R responsible, A accountable, C consulted, I informed. A control with no A, or two, turns red.
Sheet: Controls
| Control | Kind | Purpose | Typical owner | Frequency | Duties it satisfies | Duties it supports | Evidence it produces | ISO/IEC 42001 | NIST AI RMF | Record |
|---|---|---|---|---|---|---|---|---|---|---|
| AI governance policy and accountability structure | Policy | Gives the organisation a single approved statement of how it will develop, buy and use AI, and names the people who are answerable for it, so that every other A | Executive sponsor for AI | annual | 9 | 7 | AI policy; Board or executive approval of the AI policy; AI governance forum minutes; AI responsibility map | Clause 5.1, 5.2, 5.3, 9.3; Annex A.2, A.3 | GOVERN 1.1, 1.2, 1.3, 2.1, 3.1 | https://aipolicytracker.org/controls/ai-governance-policy-and-accountability |
| AI impact and fundamental-rights impact assessment | Process | Examines how a planned AI use will affect the people, groups and communities it touches, with particular attention to discrimination and rights, and records the | AI system owner | per_system | 4 | 7 | AI impact assessment; Impact assessment approval; Impact assessment procedure and template | Clause 6.1.4, 8.4; Annex A.5 | MAP 5.1, 5.2; MEASURE 2.11 | https://aipolicytracker.org/controls/ai-impact-assessment |
| AI incident management and regulatory reporting | Process | Ensures that harm or near-harm caused by an AI system is detected, contained, investigated and, where a rule requires it, reported to the right authority and af | Incident coordinator | continuous | 9 | 5 | AI incident response playbook; AI incident record; Incident report to an authority | Clause 10.2; Annex A.8.3, A.8.4 | MANAGE 4.1, 4.3; GOVERN 4.3, 6.2 | https://aipolicytracker.org/controls/ai-incident-management-and-reporting |
| AI interaction and use disclosure notices | Process | Tells people, in plain language and at the right moment, that they are interacting with an AI system, that AI is being used in a decision about them or that the | Product owner | on_material_change | 14 | 3 | AI interaction or use notice; Notice catalogue; Notice wording approval | Annex A.8.2, A.8.5 | MEASURE 2.8; GOVERN 5.1 | https://aipolicytracker.org/controls/ai-interaction-and-use-disclosure |
| AI literacy and role-based training programme | Training | Gives everyone who builds, buys, operates or is overseen by AI systems the knowledge they need for their role, from general awareness to the specific skills of | Learning and development lead | annual | 1 | 3 | AI training completion records; Role-to-curriculum training matrix; AI training curriculum and materials | Clause 7.2, 7.3; Annex A.4.6 | GOVERN 2.2, 4.1 | https://aipolicytracker.org/controls/ai-literacy-and-role-based-training |
| AI risk assessment and lifecycle risk register | Process | Identifies, rates and treats the risks that a specific AI system poses to health, safety, rights and the organisation itself, and keeps that analysis alive from | AI system owner | per_system | 7 | 5 | AI system risk assessment; Per-system AI risk register; Residual-risk acceptance | Clause 6.1.2, 6.1.3, 8.2, 8.3 | MAP 3, MAP 4, MANAGE 1.2, 1.3, 2.1 | https://aipolicytracker.org/controls/ai-risk-assessment |
Sheet: Governance duties
| Duty | Category | Instrument | Jurisdiction | Who it binds | Nature | Source reference | Applies from | What it requires | Evidence a reviewer expects | ISO/IEC 42001 | NIST AI RMF | Verification | Record |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Establish accountability processes and a risk-management process (guardrails 1 and 2) | Governance and accountability | Australian Voluntary AI Safety Standard | Australia | Deployer / user organisation, Provider / developer | Voluntary | Guardrails 1 and 2 | Guardrail 1 asks organisations to set up accountability processes including governance, internal capability and a strategy for regulatory compliance; guardrail | AI accountability and risk-management documentation | Clauses 5 and 6 | GOVERN and MAP | Source-linked | https://aipolicytracker.org/obligations/australia-vaiss-accountability-and-risk-management | |
| Frontier developers must protect employees who report catastrophic-risk concerns | Governance and accountability | California SB 53 | California (United States) | General-purpose AI model provider, Provider / developer | Legal requirement | Labor Code Section 1107 (as added by SB 53) | 2026-01-01 | A frontier developer must not adopt rules or take action that prevent or retaliate against a covered employee for disclosing to the Attorney General, a federal | Whistleblower policy and employee notice; Anonymous reporting channel records | Clause 5.1, 7.4; Annex A.3.2 | GOVERN 4.1, GOVERN 4.3 | Verified against the official source 26 Sep 2026 | https://aipolicytracker.org/obligations/us-california-sb-53-whistleblower-protections |
| Operate a quality management system | Quality management system | EU AI Act | European Union | Provider / developer | Legal requirement | Article 17 | 2026-08-02 | Providers of high-risk AI systems must put in place a documented quality management system covering regulatory-compliance strategy, design and development proce | QMS manual and procedures | Whole management system (Clauses 4–10) | GOVERN function | Source-linked | https://aipolicytracker.org/obligations/eu-ai-act-quality-management-system |
| Use high-risk AI as instructed, monitor it and inform affected people | Governance and accountability | EU AI Act | European Union | Deployer / user organisation, Public authority / government body | Legal requirement | Article 26 | 2026-08-02 | Deployers of high-risk AI must take technical and organisational measures to use systems according to the instructions, assign human oversight, ensure input dat | Deployment checklist and oversight assignment; Worker and affected-person notices | Annex A controls on responsible use of AI systems | MANAGE 3.x, GOVERN 5.x | Source-linked | https://aipolicytracker.org/obligations/eu-ai-act-deployer-obligations |
| Providers must meet the full set of provider duties for high-risk AI | Governance and accountability | EU AI Act | European Union | Provider / developer | Legal requirement | Article 16 | 2026-08-02 | Article 16 lists what a provider of a high-risk AI system owes: compliance with the Section 2 requirements, its name and contact details on the system or its do | Provider compliance matrix | Clause 5.3; Annex A.3.2 | GOVERN 1.1, GOVERN 2.1 | Verified against the official source 26 Sep 2026 | https://aipolicytracker.org/obligations/eu-ai-act-art-16-provider-obligations |
| Providers must supply conformity evidence and log access to authorities on request | Governance and accountability | EU AI Act | European Union | Provider / developer | Legal requirement | Article 21 | 2026-08-02 | On a reasoned request from a national competent authority, a provider of a high-risk AI system must supply all the information and documentation needed to show | Regulator request handling procedure; Log of authority requests and responses | Clause 7.5; Annex A.8.3 | GOVERN 1.4, GOVERN 4.2 | Verified against the official source 26 Sep 2026 | https://aipolicytracker.org/obligations/eu-ai-act-art-21-cooperation-with-authorities |
Document outline (DOCX)
- 1. Purpose
- 2. Principles
- 3. Roles and accountabilities
- 4. The controls the organisation operates
- 5. Governance duties on record and how each is met
- Establish accountability processes and a risk-management process (guardrails 1 and 2)
- Frontier developers must protect employees who report catastrophic-risk concerns
- Operate a quality management system
- Use high-risk AI as instructed, monitor it and inform affected people
- Providers must meet the full set of provider duties for high-risk AI
- Providers must supply conformity evidence and log access to authorities on request
- Non-EU providers must appoint an EU authorised representative for high-risk AI
- Deployers, distributors and importers must assume provider duties when they rebrand or substantially modify high-risk AI
- Law-enforcement deployers must obtain authorisation for post-remote biometric identification and report annually
- Providers of GPAI models must notify the Commission within two weeks of meeting the systemic-risk threshold
- Non-EU providers of GPAI models must appoint an EU authorised representative
- Adopt the guiding principles and risk-based governance (voluntary)
- Government bodies to promote ethical, responsible and inclusive AI (policy commitment)
- Establish internal governance structures and measures for AI
- Operators of high-impact AI must prepare user-protection measures and keep records of their safety and trust measures
- Foreign AI business operators above the threshold must designate a domestic representative in Korea
- Government commitment to AI ethics, governance and regulation (strategy objective)
- Use AI in ways that are fair and do not discriminate unlawfully
- Establish accountability and governance for AI
- Establish AI governance policies, roles and accountability (Govern)
- 6. Review
Duties this template covers (20)
Each is cited in the file with its source reference and a link back to the record.
- Establish accountability processes and a risk-management process (guardrails 1 and 2)
- Frontier developers must protect employees who report catastrophic-risk concerns
- Operate a quality management system
- Use high-risk AI as instructed, monitor it and inform affected people
- Providers must meet the full set of provider duties for high-risk AI
- Providers must supply conformity evidence and log access to authorities on request
- Non-EU providers must appoint an EU authorised representative for high-risk AI
- Deployers, distributors and importers must assume provider duties when they rebrand or substantially modify high-risk AI
- Law-enforcement deployers must obtain authorisation for post-remote biometric identification and report annually
- Providers of GPAI models must notify the Commission within two weeks of meeting the systemic-risk threshold
- Non-EU providers of GPAI models must appoint an EU authorised representative
- Adopt the guiding principles and risk-based governance (voluntary)
Legal basis
Version history
| Version | Built | Dataset | What changed |
|---|---|---|---|
| v1 | 914895c3103e | First version, built from dataset 914895c3103e. |
Only the latest version is served. A rebuild that changes the content adds a version; a rebuild that does not is skipped.
Frequently asked questions
- Is the AI Governance Policy and RACI free?
- Yes. Download the DOCX and XLSX without an account, under CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.
- What is it generated from?
- Version v1 was built on 26 September 2026 from dataset 914895c3103e: 92 recorded duties are cited in it, drawn from 10 instruments. Every row that cites a duty links to the record, and the record links to the official source.
- How will I know when it changes?
- The library is rebuilt daily. When a change to the records reaches this template it gets the next version, a changelog in the version history below, an entry in the AI policy updates hub and the templates feed, and a line in the weekly digest for subscribers of the templates topic.
- Does completing it make us compliant?
- No. It is an informational resource, not legal advice; it helps produce the evidence a regulator, customer or auditor asks for. Whether a duty applies to you is a judgement the template cannot make.
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.
Frequently asked questions
- Is the AI Governance Policy and RACI free?
- Yes. Download the DOCX and XLSX without an account, under CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.
- What is it generated from?
- Version v1 was built on 26 September 2026 from dataset 914895c3103e: 92 recorded duties are cited in it, drawn from 10 instruments. Every row that cites a duty links to the record, and the record links to the official source.
- How will I know when it changes?
- The library is rebuilt daily. When a change to the records reaches this template it gets the next version, a changelog in the version history below, an entry in the AI policy updates hub and the templates feed, and a line in the weekly digest for subscribers of the templates topic.
- Does completing it make us compliant?
- No. It is an informational resource, not legal advice; it helps produce the evidence a regulator, customer or auditor asks for. Whether a duty applies to you is a judgement the template cannot make.