FREE AI GOVERNANCE STARTER KIT
Seven editable files. One practical first pass. No signup.
Download the Excel inventory, vendor assessment, risk register, NIST AI RMF gap assessment, AI literacy evidence tracker, EU AI Act risk classification decision record, and Word AI use policy together in one ZIP. Build a reviewable baseline without buying a platform, joining a mailing list, or uploading governance information.
- 6 Excel workbooks
- 1 Word policy
- Start Here guide
- No signup
- No upload
WHAT IS INCLUDED
Start with the records that expose ownership, evidence, risk, and rules.
Every file is editable and designed to work locally. Use only the fields that apply, name accountable owners, link current evidence, and record authorized decisions separately.
AI system inventory
Track up to 50 systems and use cases across owners, people, data, models, integrations, actions, decisions, approvals, evidence, gaps, and reviews.
AI vendor assessment
Review one exact product across 50 questions, eight domains, weighted priorities, critical gaps, evidence, owners, target dates, and exit readiness.
AI risk register
Start with 12 editable risk prompts and track inherent exposure, controls, residual exposure, treatment, actions, evidence, owners, and review dates.
NIST AI RMF gap assessment
Review 40 original practices across GOVERN, MAP, MEASURE, and MANAGE with status, evidence, owners, actions, dates, priorities, and a dashboard.
EU AI Act AI literacy tracker
Map people and roles, assign proportionate literacy paths, record training and assessments, index evidence, track due dates and refreshers, and review a formula-driven dashboard.
EU AI Act risk classification record
Preserve Article 5 screening, Article 6 routes, Annex III mapping, Article 6(3) facts, profiling, evidence, rationale, owners, decisions, and reassessment triggers.
Workplace AI use policy
Adapt a cautious Word policy starter for approved tools, restricted uses, data handling, human review, incidents, exceptions, training, and revision control.
A 15-MINUTE START
Make one narrow operating record before expanding the program.
- 1
Inventory what is already happening
List active tools and workflows first. Name the product, use case, owner, users, data, affected people, outputs, integrations, actions, and review date.
- 2
Prioritize the highest-impact use
Choose the workflow with the most sensitive data, consequential output, automation, uncertainty, or dependence. Record plausible risk events and current controls.
- 3
Ask the vendor for evidence
Assess the exact product, plan, models, regions, configuration, data flow, integrations, contract, and exit path. Do not average critical unknowns into a reassuring score.
- 4
Turn framework gaps into owned work
Use the NIST AI RMF worksheet to organize current evidence and improvement actions across GOVERN, MAP, MEASURE, and MANAGE without treating it as an official checklist.
- 5
Record AI literacy measures
Map roles to proportionate learning paths, record assignments and completion, link evidence, track assessment follow-up, and review overdue records.
- 6
Document the EU AI Act classification route
Preserve the intended purpose, Article 5 screen, Article 6 routes, Annex III mapping, evidence, rationale, owner, decision, and reassessment trigger without treating the workbook as a legal classifier.
- 7
Adapt the policy to reality
Make the rules match approved tools, actual data, accountable owners, human review, incident routes, exceptions, training, and qualified review requirements.
IMPORTANT LIMITS
A starter kit creates structure, not a compliance conclusion.
- A completed field does not prove the underlying control exists, works, remains current, or covers the exact operating conditions.
- A score cannot decide whether a system is lawful, safe, secure, fair, accessible, approved, or fit for the intended use.
- A generic policy cannot identify every jurisdiction, contract, employment rule, professional duty, affected person, or industry requirement.
- Use qualified legal, privacy, security, employment, accessibility, procurement, audit, and leadership review where the organization and use require it.
WHEN THE SEPARATE FILES BECOME A SYSTEM
Connect the records for $19 once.
The AI Policy Operations Kit combines inventory, 30 starter risks, approvals, incidents, a dashboard, and a scoring guide in one Excel governance workbook. It also includes five coordinated Word documents, a PDF implementation guide, and lifetime BrandQuill Solo publishing.
Compare BrandQuill with other current toolkits →COMMON QUESTIONS
Download now, then adapt carefully.
What is in the free AI governance starter kit?
The ZIP contains six editable Excel workbooks, one editable Word policy starter, and a concise Start Here guide. The workbooks cover system inventory, vendor assessment, risk tracking, an original NIST AI RMF gap assessment, an EU AI Act AI literacy evidence tracker, and an EU AI Act risk classification decision record.
Is an email address or account required?
No. The ZIP is a direct download. BrandQuill does not ask for an email address, create an account, or upload the files.
Can I use the templates at work?
Yes. You may adapt and use completed versions within your organization and with its professional advisers. You may not resell, repackage, publish, sublicense, or distribute the blank BrandQuill templates as another product.
Do these templates make an organization compliant?
No. They are educational starting points, not legal or professional advice. A completed record or score cannot prove compliance, approval, safety, security, fairness, accessibility, or fitness.
What does the $19 AI Policy Operations Kit add?
The paid kit connects inventory, 30 starter risks, approvals, incidents, a dashboard, and a scoring guide in one larger Excel workbook. It also includes five coordinated Word files, a PDF implementation guide, and lifetime BrandQuill Solo publishing.