Governance & Operations

AI Governance Starter

Policies, templates, and workflows to govern how your organization uses AI.

A starting set of policies and workflows for governing AI. It covers acceptable use, risk assessment, an inventory of models and agents, and ongoing monitoring. We fit it to your risk tolerance and connect it to how your teams already release work.

GIST stepGroundTrust
Download the PDF
What you get

Documented answers when a regulator, customer, or board asks how you govern AI.

Free download · PDF · 10 pages

Get the AI Governance Starter overview

The problem it solves, what is included, how it works, the technical components, and how we adapt it with you.

The problem

The board asks how you govern AI. The answer is scattered.

AI is already in use: vendor features, pilots, models, and agents. Policies are drafts, the inventory is a spreadsheet nobody updates, and every customer security questionnaire starts from scratch.

What this accelerator does

The AI Governance Starter gives you working governance records on day one, a risk tier for every system, and a check that fails when records fall out of date.

What's included

Governance records that stay current.

Four parts, each adapted to your data, platforms, and controls. What we adapt for you is yours to keep.

01

AI policy and acceptable use

A governance policy and a staff acceptable-use standard, fitted to your position and reviewed by your counsel.

02

Risk assessment and inventory

A questionnaire with scoring and controls per tier, and an inventory of models, vendor AI features, and agents.

03

Evaluation Cards and Control Register

A card per live system and a register of 18 starting controls with owners and evidence.

04

Evidence packs

Generated on request for auditors, customer security questionnaires, and board reports.

How it works

Setting it up.

  1. Records folder

    Inventory, control register, assessments, and cards in your repository, reviewed like code.

  2. Adapt the policies

    Roles, approved tools, and prohibited uses to match your position and the law where you operate.

  3. Tune the questionnaire

    Scores, thresholds, and controls per tier, approved by your AI governance committee.

  4. Fill the register

    An owner, enforcement method, evidence, and honest status for each control.

  5. Register what exists

    Every AI system in use today, assessed, with its gaps listed.

  6. Check in CI

    Any change that leaves a production system without a current review, card, or control fails.

Technical detail

What the check looks for.

Vendor-neutral Python and configuration, Azure first, with tests included from the start.

Inventory
Required fields, different owner and backup, reviews not overdue
Risk assessments
One per system past intake; inventory tier not lower than assessed
Evaluation Cards
Present and current for every live system
Agents
A scope file that matches the inventory's agent and owner
Control register
Owners and evidence for controls in place; tests not overdue
Coverage
Every control a live system's tier requires is in place
Proof in the package

Worked example: three AI systems, fully documented.

A demand forecast model, a support-answers assistant, and an invoice-triage agent, each assessed and carded.

One command builds an evidence pack from
  • The AI inventory and each system's risk tier
  • Risk assessments and Evaluation Cards
  • The Control Register, with owners and evidence
  • Test results and audit logs from the other accelerators
Result

The pack can cover every system, or only the ones a given customer uses. A coverage gap on a production system fails the check.

How we run it with you

Adapted in the first cycles, handed over at the end.

  1. 01

    Adapt

    Policies and questionnaire fitted to your risk tolerance, with review by your counsel.

  2. 02

    Inventory

    Every system, model, vendor AI feature, and agent listed and assessed.

  3. 03

    Connect

    Records tied to how your teams already release work, and checked in CI.

  4. 04

    Answer

    Evidence packs for audits, customer questionnaires, and board reports.

You keep the policies, the records, and the check, in plain CSV, YAML, and Markdown that open in Excel and import into a GRC tool later.

Where it fits

Platforms, related accelerators, and limits.

We state the limits up front, and we recommend tools based on fit. We do not resell platforms.

Works with

  • Your version control and existing CI
  • Excel for the CSV records
  • GRC tools through CSV import

Pairs with

  • AI Agent Controls enforce controls AIG-06, 07, 08, and 10
  • MLOps Templates write Evaluation Cards
  • Evaluation results and agent audit logs serve as evidence

Assumptions and limits

  • Policies are starting drafts, not legal advice; your counsel reviews them
  • The NIST AI RMF and ISO/IEC 42001 crosswalk is informal; your auditor checks it

Take the overview with you.

Get the 10-page PDF to share with your team, or tell us the decision you want to improve and we will tell you whether the AI Governance Starter fits.