Resource module

AI Governance Policy Starter Kit

Four editable Word templates that give your organization defensible AI governance in weeks instead of quarters. Built from real engagements, written for executives and adapted easily for regulated and government contracting environments.

AI Acceptable Use Policy

The document auditors, primes, and insurers ask for first. Defines approved tools, permitted and prohibited use, data classification rules, human review, disclosure, and consequences.

  • Approved tool register with data-class columns
  • Prohibited use list covering CUI, PHI, PCI and personal accounts
  • Data classification-to-AI-use rule table
  • Employee acknowledgment block
Download template (.docx)

AI Approval Process

A lightweight intake-to-decision path so new AI tools get reviewed in days, not months - with evidence you can show later.

  • Roles and responsibilities matrix
  • Seven-step process from intake to annual review
  • Low / Medium / High risk triage criteria
  • Intake form, decision record, and AI tool register
Download template (.docx)

Employee AI Guidelines

The plain-language companion your team will actually read. Turns the policy into five rules, real examples, and a verification habit.

  • The five rules and a pre-prompt checklist
  • How to recognize and verify hallucinations
  • Good uses vs. uses that require approval
  • Incident reporting and contact table
Download template (.docx)

Vendor Review Checklist

Score any AI vendor before it touches company data. Built around the questions that actually determine risk, not the ones in the sales deck.

  • Critical data handling questions with evidence columns
  • Security controls, certifications, and logging
  • Compliance fit: CMMC, NIST 800-171, HIPAA, PCI, SOC 2, GDPR
  • Model transparency, operations, and reviewer recommendation
Download template (.docx)
How to use the kit

Adopt them in this order.

  1. 1

    Start with the Acceptable Use Policy - it is the anchor document everything else references.

  2. 2

    Stand up the Approval Process so new tools stop arriving unreviewed.

  3. 3

    Roll out the Employee Guidelines with a short training session and acknowledgment.

  4. 4

    Apply the Vendor Review Checklist to every AI tool already in use, highest-risk first.

Every template uses bracketed fields - replace them with your organization's names, contacts, and obligations before adoption. These are starting points, not legal advice; have counsel review anything that flows into a contract.

Not sure where you stand?

Score your readiness first.

The Executive AI Adoption Readiness Assessment scores your organization across ten pillars - including governance - and returns a phased roadmap so you know which of these templates to deploy first.

Disclaimer

Nothing on this page or in any accompanying template, assessment, checklist, or report constitutes legal, financial, or compliance advice. These materials are general-purpose starting points drawn from professional experience. Review all information thoroughly against your own internal needs, company structure, contractual obligations, and regulatory environment, and have your legal counsel review anything you adopt before you rely on it.