Free Pack · AI Governance

AI Governance & Risk Pack

Make AI governable before regulators or incidents do it for you: a 24-question governance questionnaire, a 20-point controls checklist, an operating-model decision matrix, a rollout plan, and a controls validation plan — mapped to risk-tiered thinking.

24governance questions
4risk tiers
3operating models

01 — Inside the pack

What’s inside

Four working artifacts. The checklist and the architecture diagram download instantly; the questionnaire and the decision workbook — the high-value bundle — are free with a work email.

PDF · multi-page

Discovery questionnaire

24 scored discovery questions across 6 sections with evidence prompts, response scales, and a scoring guide — the workshop instrument for honest scoping.

Full pack · free with work emailUnlock in the full pack →

XLSX · 4 sheets

Decision workbook

Excel workbook: decision matrix with auto-weighted scoring and 1–5 rating validation, phased project plan with owners and deliverables, and a validation test plan with result tracking.

Full pack · free with work emailUnlock in the full pack →

PDF · 20 checks

Readiness checklist

20-point readiness checklist across 5 categories with sign-off blocks — use as phase entry criteria and go/no-go gates.

Instant downloadDownload PDF

SVG · one page

Architecture diagram

One-page blueprint-style architecture diagram — print it for the workshop wall or drop it into your deck.

Instant downloadDownload SVG

02 — Architecture at a glance

Risk-tiered governance loop

INVENTORY AI inventory Use-case register TIER Risk tiering Impact assessment CONTROL Policy & controls Approval gates MONITOR Monitoring Incident response ASSURE Audit & reporting Board updates

Inventory everything, tier by risk, apply proportional controls, monitor continuously, and audit the loop itself.

03 — Who it’s for

Built for the people doing the work

  • Risk, compliance, and legal leaders asked to 'do something about AI' without slowing the business
  • AI program owners who need a defensible governance story for the board
  • Engineering leaders shipping models and agents into regulated or customer-facing surfaces

04 — How to use it

Run it like a program, not a download

  1. Inventory first, policy second

    Complete sections 1–2 to build the AI inventory with risk tiers. Policy written before inventory is fiction.

  2. Tier the controls

    Apply the checklist's controls proportionally: light touch for low-risk internal tools, full gates for high-risk customer-facing systems. Governance that treats a meeting-summarizer like a credit model will be ignored.

  3. Pick the operating model deliberately

    Use the decision matrix to choose centralized, federated, or platform-embedded governance — matched to your organization's actual decision culture.

  4. Validate controls like controls

    The validation plan tests each control the way an auditor would: with evidence, not assertions.

  5. Review on a cadence

    Risk tiers drift as use cases evolve. Quarterly re-tiering keeps the inventory honest.

05 — Get the full pack

Unlock the questionnaire + decision workbook

Free for practitioners. We ask for a work email so an architect — not a drip campaign — can follow up if your scores raise flags.

No spam, no SDR sequence. If you bring a completed questionnaire to a discovery call, an architect reads it first. Your details are used to deliver the pack and follow up on your interest only — Privacy Policy. No marketing without consent.

06 — Keep going

Pair the pack with an assessment

Recommended next step

AI Readiness Assessment

Run the interactive assessment, then compare its output against your pack scores — the two together scope an engagement honestly.

Start the assessment →

Related

Agentic AI hub

Open →

Related

Pattern: enterprise RAG

Open →

Talk to an Architect

Bring a completed pack to your discovery call

It compresses weeks of fact-finding into one working session — and the scoring shows us both where the risks are.