Home/Documentation/Programme-level documentation

AI Governance Programme

An AI management-system documentation set aligned to ISO/IEC 42001, with the EU AI Act obligations map, model inventory, impact assessment and acceptable-use controls.

New

What this set does

Organisations are deploying AI faster than they are documenting it. ISO/IEC 42001 gives a management-system structure for AI, and the EU AI Act attaches legal obligations by risk tier. This programme covers both, and reuses your existing ISMS structure so AI governance is an extension of what you already have, not a parallel system.

What's inside

  • AI policy and AI management system scope
  • AI system inventory and risk-tier classification workbook
  • AI impact assessment procedure and template (42001 Annex B / AI Act Article 27 informed)
  • Acceptable use standard for generative AI tools
  • Model lifecycle, data governance and human-oversight standards
  • Supplier AI due-diligence questionnaire
  • EU AI Act obligations map by role (provider, deployer, importer)

Who it is for

Organisations deploying or building AI systems that need governance a regulator, customer or board will recognise.

How the documents are structured

Every document opens with its purpose, scope and owner, then the substantive content, then a control cross-reference showing which framework requirements it satisfies. Standards state requirements in testable language ("must", with the parameter). Procedures follow one format: trigger, roles, steps, frequency, records produced. Placeholders are limited to things only you can know: organisation name (which we fill in), system names, role titles, tool names and timelines. There are no "[insert policy here]" sections.

Tailoring effort

Expect to spend a few hours on a policies-and-standards set and longer on procedures, because procedures describe how your team actually works. The document register in each set lists every file with a suggested owner so you can split the work.

Licence

One purchase covers one organisation for internal use, with unlimited users and unlimited edits. Consultancies and MSPs tailoring documents for clients need the multi-client licence; see the terms or ask us.

Related products

Policies & Standards — ISO/IEC 27001:2022

A complete policy and standards set structured to the 93 Annex A controls of ISO/IEC 27002:2022, plus the clause 4–10 management-system requirements.

£495 · 41 documents

Policies & Standards — NIST CSF 2.0

Policies and standards organised by the six CSF 2.0 functions, with standards written at the subcategory level so each one is auditable.

£445 · 36 documents

Procedures Library

Step-by-step operating procedures that show how each control is actually carried out, who does it, how often, and what record it produces.

£595 · 118 documents