Governance Templates
Ready-to-use document templates for every policy, assessment, checklist, and report referenced across the 20 controls. Copy, customize, and implement.
Rules for classifying data before submission to AI tools, including AI-specific classification levels and decision matrices.
Defines retention periods, consent requirements, and deletion procedures for AI prompts, responses, and interaction metadata.
Adversarial testing procedures for AI systems covering prompt injection, jailbreaking, data extraction, and agentic attack scenarios.
Incident response procedures tailored for AI-specific incidents including model compromise, prompt injection exploitation, and data leakage through AI systems.
Defines approved AI tools, prohibited activities, and data handling rules for all personnel interacting with AI systems.
Pre-deployment gate checklist covering security, performance, bias, privacy, and rollback planning for AI systems.
Periodic maturity and risk assessment questionnaire covering governance, data protection, model security, and operational monitoring of AI systems.
Template for cataloging all AI assets across the organization including models, tools, integrations, and shadow AI discovery processes.
Scoring rubric for evaluating the security, transparency, and contractual posture of AI vendors and third-party AI services.