| AI system inventory | Use cases, owners, providers, data, users, risk attributes, status, and dependencies | Register and data model | Assess | System and procurement information | AI governance or technology |
| Risk-tiering method | Materiality, impact, autonomy, exposure, data, and regulatory criteria | Method and decision tree | Assess/design | Risk appetite and policy context | Risk and compliance |
| AI control library | Preventive, detective, corrective, technical, procedural, and oversight controls | Control catalogue | Design | Existing policies and tooling | Control owners |
| Governance operating model | Roles, forums, approvals, escalation, exceptions, and segregation of duties | RACI and governance charter | Design | Organisation and decision structure | Executive sponsor |
| Policies and standards | Acceptable use, lifecycle requirements, third-party AI, data, monitoring, and incidents | Policy suite | Design/implement | Legal and policy review | Policy owners |
| Assessment and evidence toolkit | Questionnaires, checklists, test records, approvals, logs, exceptions, and attestations | Templates and workflow requirements | Implement | Process and tool access | Governance operations |
| Remediation roadmap | Priorities, dependencies, owners, sequencing, acceptance criteria, and risks | Roadmap and backlog | Implement | Resources and delivery constraints | Programme leadership |
| Monitoring and reporting pack | KPIs, KRIs, exceptions, incidents, overdue actions, portfolio trends, and decisions | Dashboard and governance pack | Operate | Reliable source data | AI governance office |
| Training and handover | Role-based guidance, operating procedures, walkthroughs, and support model | Materials and sessions | Transition | Named operational owners | Client capability leads |