The first entry in the GovernIQ template library, published from a completed GovernIQ engagement: a six-section reusable deliverable covering scope, AI system inventory, a risk-assessment framework, plain-language disclosure templates, and a quarterly / annual / 90-day monitoring cadence. Drop it into your compliance program as a working draft. One section per anchor — clear, copy-paste-usable, derived from a real client engagement.
Generic reusable template · Personalize with a $299 Compliance Action Plan · No subscription
This is the working artifact form of an engagement deliverable. Every line below is the template form of an actual section from a completed GovernIQ engagement, with the company-specific identifiers removed and the placeholders generalized for reuse.
It is published for one reason: most mid-market companies facing AI compliance obligations do not need a strategy deck — they need a clean, copy-paste-usable starting artifact that a compliance lead, outside counsel, or internal audit team can pick up and run with. The GovernIQ assessment identifies gaps; the template is the working paper that closes them. A $299 Compliance Action Plan personalizes the gaps; this template personalizes the structure.
Three caveats before you reuse it. First, this template is framework-agnostic by design — it does not commit you to NIST AI RMF, ISO/IEC 42001, or any particular regulator. Pick the framework that fits your jurisdiction and overlay it on the risk-assessment section (§4). Second, the disclosure language in (§5) is plain-language starting text. Run it through qualified counsel familiar with your jurisdiction before publishing it as binding disclosure. Third, the cadence in (§6) is the binding part — a template that does not get re-run on the cadence is a document, not a program.
Who it is for: financial advisory firms with model portfolios or AI-assisted planning workflows. Law firms using AI for document review or research. Healthcare practices with AI-assisted scheduling, triage, or coding. SaaS companies with AI features that touch EU or Colorado consumers in covered contexts. Compliance leads at any of those organizations who need a working draft by Monday.
Scope decides what enters the inventory, which risks get assessed, and which disclosures must be published. Get scope wrong and the rest of the program is working on the wrong systems. This section is short on purpose — it is a placeholder, not a strategy.
Systems in scope. Any AI system — third-party vendor product, open-source model deployed in-house, internally built model, or API service — that materially interacts with a natural person in a consequential or regulated context. "Materially interacts" is the test: if the system's output drives or substantially influences a decision affecting a customer, employee, patient, applicant, or claimant, it is in scope. Pure internal analytics with no consumer touchpoint is out of scope of this template, but may still be in scope of your broader AI registry.
Data in scope. Any personal data — including inferences derived from personal data — that flows into or out of an in-scope AI system. This includes training data shipped with the vendor model, real-time consumer data fed at inference, third-party data enrichment layers, and prompt logs retained for evaluation. Free-text prompts containing personal data are in scope. Outputs that are themselves personal data are in scope.
Use cases in scope. Use this template when deploying AI for at least one of: customer-facing decision support (eligibility, pricing, routing), employment screening or evaluation, financial-services decisions (credit, insurance, claims), healthcare access or coverage decisions, legal or compliance review, content moderation or trust-and-safety decisions, or any other process where an AI output drives or substantially influences an action against a natural person.
Out of scope for this template (clearly). Internal productivity AI (meeting summarizers, code copilots, knowledge search) that does not materially influence any person-facing decision. Investigational or proof-of-concept deployments not yet exposed to natural persons. Models running purely on synthetic data. Even where out of scope of this template, an AI registry should still record these systems; they often graduate into scope.
The inventory is the foundation. Without a complete inventory, every downstream obligation (impact assessment, disclosure, vendor management, monitoring) is built on guesswork. Use the per-system checklist below as the structural minimum; adapt column names to your tooling but do not drop fields.
| Field | What to capture | Why it matters |
|---|---|---|
| System name & internal ID | Display name plus a stable internal identifier that does not change with vendor renames or version bumps. | Stability of references across inventory reviews, impact assessments, and disclosure language. |
| Vendor & developer | Vendor name, contract reference, and developer if different from vendor (e.g. open-source model from foundation lab deployed by integrator). | Establishes who holds vendor-management obligations and who holds deployer obligations. |
| Model name & version | Model identifier, version string, and date acquired or deployed. Include any sub-models or routing layers. | Triggers change-triggered re-assessment when versions change materially. |
| Training data provenance | Training data sources, last refresh date, known limitations declared by vendor, and any data categories that should be excluded downstream. | Input side of bias and disparate-impact analysis. |
| Deployment surface | Where the AI meets a natural person — web form, email, in-app, phone (with speech-to-text), internal CRM, etc. | Determines which disclosure channel and which consumer is reached. |
| Covered contexts | Which Colorado / EU / industry contexts the system operates in (employment, credit, healthcare, etc.). | Drives which legal obligations apply — SB 26-189 covered context, EU high-risk category, industry rule. |
| Personal data categories | Categories of personal data flowing in (prompt + context) and out (response), including inferred attributes. | Drives data-protection impact assessment and notification obligations. |
| Business owner | Named accountable executive with sign-off authority for inventory entry, impact assessment, and incident reports. | Accountability — without a named owner, the inventory has no one to escalate to. |
| Last impact assessment date | Most recent completed impact assessment for this system and its expiry (annual + 90 days). | Calendar trigger for the next impact assessment. |
| Next scheduled review | Date of the next quarterly inventory check and the date of the next annual impact assessment. | Drives the monitoring cadence reminders (§6). |
| Risk tier (from §4) | Low / medium / high as assigned by the risk-assessment framework in §4. | Sets the depth of monitoring and the speed of disclosure publication. |
| Incident log link | Pointer (URL or ticket reference) to the live incident log for this system, including disparate-impact reports. | Connects operational events back to the regulatory record. |
Cadence: quarterly review of every entry, with the entire inventory updated within 30 days of any new deployment or substantial modification. A new system without an inventory entry is a compliance event in itself.
Use the 2×2 matrix to score each in-scope system on likelihood of harm × severity of harm if it occurs. Then overlay the result on the four NIST AI RMF 1.0 functions to produce the per-system remediation sequence. The framework is framework-agnostic — drop in ISO/IEC 42001 if that is your adopted framework.
Score is likelihood-weighted impact. Low/minor combos (scores 1–3) run on annual review. Mid-range (4–5) gets quarterly review. High-severity (6–9) gets monthly or continuous monitoring. The numeric score is the operational trigger; the impact assessment is the document that justifies the score.
For each system, map the score above onto the four NIST AI RMF 1.0 functions. The mapping below is the per-system remediation checklist that comes out of every impact assessment:
Documented AI policy, named accountable executive, escalation path, and an approved use-case boundary for the system. Every high-score system gets a single-throat-to-choke owner with sign-off authority.
Documented deployment context, affected populations, foreseeable harms, and an explicit mapping of the system to the covered contexts (Colorado SB 26-189 covered contexts, EU AI Act risk categories, industry-specific obligations).
Quantitative bias testing across protected classes, accuracy and hallucination rate benchmarks, drift detection on input distribution and output distribution. Stored results compared across assessments.
Documented incident response runbook with 90-day reporting trigger where applicable, vendor change-of-version notifications, and rollback authority for the deployer. Pre-approved rollback playbook for any regulated system.
The 2×2 score drives the cadence in §6. The NIST overlay drives the per-system remediation priorities in the personalized Compliance Action Plan. Both are inputs to the §5 disclosures — the disclosure language for a "Score 7" system should be more prominent than for a "Score 2" system.
The two disclosure moments are pre-interaction (announcing the AI's involvement before the decision is made or materially influenced) and post-decision (explaining the AI's role after an adverse outcome). Both must be in plain language, at the point of decision, and not buried in a privacy policy. Copy, adapt to your channel mix, and have counsel review before publication.
Some parts of this experience use an AI system to help [your company] review and respond. The AI is operated under our AI Acceptable Use Policy, reviewed for accuracy, and supervised by a human team. What this means for you: this AI helps draft, classify, or triage your [request / application / case / message]. A human reviews the AI's output before any decision that affects you is finalized. You may request human review at any point by contacting [contact channel]. If you would prefer not to interact with an AI system, you may [alternative channel: opt out, request a human-only path, etc.]. Questions about how this AI is used? Email [contact channel].
This decision was made with the assistance of an AI system operated by [your company]. The AI reviewed [the inputs — e.g. the application, the case file, the eligibility data] and produced a recommendation. A human reviewer with authority to override the AI made the final call. How the AI contributed: [plain-language description of what the AI did]. What it did not do: [plain-language description of decisions reserved for the human]. Your right to human review: you may request a full human review of this decision. To request human review, contact [contact channel] within [time window — match your policy and applicable law]. We will respond within [response window]. If you believe this decision was incorrect or that the AI made an error, contact [contact channel]. Complaints are reviewed under our AI Incident Response Policy.
This tool uses an AI system to [draft / triage / classify] internal work product. Outputs are advisory; final decisions affecting employees, candidates, or contractors are made by a named human reviewer. The AI is logged. Every interaction is recorded for audit under our [policy reference]. You may flag any output for review by [contact channel]. Flagged outputs are reviewed within [response window].
Disclosure wording has regulatory consequences under both Colorado and EU law. These templates are starting points only — have qualified counsel review and adapt them to your jurisdiction, your channel mix, and your risk tier before publication.
The cadence is what converts the five sections above from a document into a working program. Without it, the template is inert. The three layers below are independent — they run on different schedules but feed the same evidence record.
| Cadence | What runs | Trigger conditions | Evidence record |
|---|---|---|---|
| Quarterly | Full inventory review across every in-scope system. Risk-tier re-check for systems whose score may have drifted. | Calendar — 1st business week of each calendar quarter. Also within 30 days of any new deployment or substantial modification. | Inventory diff log. Reviewed-and-signed entry per system. Changes flagged for impact-assessment re-run. |
| Annual | Full impact assessment re-run for every in-scope system. NIST AI RMF Govern/Map/Measure/Manage checklist refreshed. Disclosure language spot-checked. | Calendar — within 90 days of each system's anniversary deployment date (not all on the same day). | Signed impact assessment per system. Bias testing results compared year-over-year. Disclosure language changelog. |
| 90-day trigger | Targeted impact assessment re-run for the affected system. Vendor management re-engagement if the trigger is a model update. Incident report evaluation. | Material vendor model update. Protected-class performance drift above threshold. Internal incident or near-miss. New covered context entered by the system. Regulatory change affecting the deployment. | Trigger event log. Targeted impact assessment completed within 90 days. 90-day incident report filed if applicable. |
| Continuous (Score 6+) | Output distribution drift monitoring. Bias-metric dashboards reviewed weekly. Incident tickets flagged for AI causality. | Risk score 6 or higher from §4. Any system in a high-risk EU category. Any system in a Colorado Consequential Decision domain. | Drift dashboard snapshots. Bias-metric time-series. Incident tickets marked AI-Review. |
If your team cannot hit all three cadences, do not run this template at all — a template that is not re-run is worse than no template, because it creates a documented gap that an investigator can find. The GovernIQ assessment ($0, no account) gives you the personalized gap map; the $299 Compliance Action Plan gives you the company-specific 90-day roadmap. Use this template to keep the doc current once the plan is in place.
The GovernIQ assessment identifies which of your AI systems are in scope, maps your current posture against the obligations this template documents, and produces a personalized Compliance Action Plan with company-specific policy language, vendor contract clauses, and a 90-day remediation roadmap. Free to assess — $299 to lock in the plan.
Free assessment · Personalized Compliance Action Plan $299 · No subscription