Your organization is already using AI, the only question is whether anyone is keeping score. This kit governs it the way the rest of your risk program works: deterministic scoring, explicit oversight requirements, and a policy people can actually follow.
Most AI governance is either a prohibition memo nobody follows or a vendor questionnaire nobody scores. This kit treats AI like any other risk the program manages: every use case gets inventoried, scored by a transparent formula (how autonomous is it, how sensitive is the data, how consequential are the decisions) and assigned the oversight and review cadence its band demands. A use case that acts without review on consequential decisions doesn't get a debate; it gets a flag.
200 rows, 10 worked examples across the lifecycle, including a rejected use case and an oversight gap, so you see the flags fire before you rely on them.
Autonomy, data sensitivity, and decision impact on written 1–5 anchors; the composite lands on the same Low/Moderate/High/Critical bands as your risk register.
Human-in-the-loop, on-the-loop, or out-of-the-loop, declared per use case, checked against the band, flagged when inadequate.
Band distribution, lifecycle grid, oversight-gap list, and overdue reviews, the AI portfolio on one page.
Approved-use tiers tied to the workbook's bands, prohibited uses, what may never enter a third-party model, vendor AI rules, and time-bound exceptions.
NIST AI RMF functions, EU AI Act articles (5, 6 & Annex III, 14, 50), ISO/IEC 42001 clauses, cited at the level that stays accurate.
The thinking: AI in GRC: What's Actually Useful and AI Agents for GRC.
An Excel workbook (.xlsx, no macros, opens in Google Sheets/LibreOffice) and a Word policy (.docx) with a PDF reference version.
No. The workbook gives you the category options with plain-language guidance and a place to record your determination, the determination itself belongs to you and your counsel, and the workbook keeps it documented.
Yes, internally or in client engagements. You can't resell the kit itself as a template.
If you want the scoring anchors or policy adapted to your sector or regulator, get in touch.
Inventoried, scored, overseen, and reviewed, like everything else your program governs.