| Responsible AI learning pathway | Audience groups, objectives, modules, scenarios, exercises, and reinforcement plan | Curriculum and materials | Educate | Role profiles and priorities | Learning lead |
| AI system and use-case inventory | Owner, purpose, users, data, vendor, lifecycle, decisions, and status | Register and taxonomy | Assess | System and vendor information | AI governance owner |
| Risk classification method | Impact, autonomy, data sensitivity, affected people, criticality, and review depth | Method and decision tree | Assess | Risk appetite and obligations | Risk and compliance |
| Governance charter and RACI | Forums, decision rights, approvals, escalation, exceptions, and reporting | Operating-model pack | Design | Organisation and committee structure | Executive sponsor |
| Responsible AI policy and standards | Principles, acceptable use, prohibited use, lifecycle controls, documentation, monitoring | Policy suite | Design | Existing policies and legal review | Policy owner |
| Impact-assessment and review toolkit | Questionnaires, evidence checklist, review workflow, decision log, exception record | Templates and workflow | Implement | Pilot use cases and reviewers | Governance team |
| Evaluation and monitoring plan | Quality, safety, reliability, bias, privacy, security, human oversight, and drift considerations | Test and reporting plan | Implement | Technical access and test data | AI product owner |
| Implementation roadmap | Priorities, dependencies, owners, milestones, controls, training, and reporting | Roadmap and backlog | Transition | Capacity, budget, and decisions | Programme sponsor |