| GenAI system and use-case inventory | Purpose, owner, users, model, vendor, data, integration, impact and lifecycle status | Structured register | Assessment | System, procurement and business information | AI governance lead |
| Risk taxonomy and tiering model | Impact criteria, risk factors, thresholds, escalation and review frequency | Method and scoring guide | Design | Risk appetite and regulatory context | Risk and AI governance |
| Governance charter and decision rights | Forums, roles, approvals, exceptions, risk acceptance and accountability | Charter and RACI | Design | Executive and functional role decisions | Executive sponsor |
| Policy and standards suite | Acceptable use, development, procurement, data, testing, deployment and monitoring requirements | Policies and standards | Design | Existing policies and legal review | Policy owners |
| Control library | Preventive, detective and corrective controls mapped to risk and lifecycle stages | Control matrix | Design | Control environment and technical feasibility | Risk, security and technology |
| Assessment and approval workflow | Intake, triage, assessments, approvals, conditions, exceptions and records | Workflow and templates | Implementation | Process owners and tooling constraints | Governance office |
| Evaluation and monitoring framework | Test dimensions, acceptance criteria, evidence, ongoing indicators and escalation | Evaluation plan and dashboard design | Implementation | Use-case requirements and test access | Model and product owners |
| Implementation roadmap | Priorities, dependencies, work packages, owners, review points and capability needs | Roadmap and backlog | Transition | Resources, budgets and programme constraints | Programme sponsor |
| Training and operating playbooks | Role-based guidance, procedures, checklists, escalation and knowledge transfer | Training and playbooks | Transition | Audience, policies and delivery channels | Governance and learning teams |