Template Reusable From a Real Engagement

The AI Audit & Policy Template — Reusable for Mid-Market SMBs

The first entry in the GovernIQ template library, published from a completed GovernIQ engagement: a six-section reusable deliverable covering scope, AI system inventory, a risk-assessment framework, plain-language disclosure templates, and a quarterly / annual / 90-day monitoring cadence. Drop it into your compliance program as a working draft. One section per anchor — clear, copy-paste-usable, derived from a real client engagement.

Generic reusable template · Personalize with a $299 Compliance Action Plan · No subscription

TL;DR — Three Things You Should Know
  • Reusable, not one-size-fits-all: This is a generic SMB template derived from a real engagement — copy it, replace the placeholders, and you have a working draft of your audit + policy packet in under an hour. Personalization for your actual AI stack lives in the $299 Compliance Action Plan.
  • Six sections, six obligations: The template mirrors the operational obligations shared by Colorado SB 26-189, Colorado SB 24-205, and the EU AI Act's deployer rules — scope, inventory, risk, disclosures, monitoring. Each section is legally intelligible and regulator-defensible.
  • Cadence is the program: The template is inert without the monitoring cadence. Quarterly inventory reviews + annual impact assessments + 90-day change-triggered re-assessment are the difference between a document and a working compliance posture.
Introduction

What this template is, who it is for, and why it was published

This is the working artifact form of an engagement deliverable. Every line below is the template form of an actual section from a completed GovernIQ engagement, with the company-specific identifiers removed and the placeholders generalized for reuse.

It is published for one reason: most mid-market companies facing AI compliance obligations do not need a strategy deck — they need a clean, copy-paste-usable starting artifact that a compliance lead, outside counsel, or internal audit team can pick up and run with. The GovernIQ assessment identifies gaps; the template is the working paper that closes them. A $299 Compliance Action Plan personalizes the gaps; this template personalizes the structure.

Three caveats before you reuse it. First, this template is framework-agnostic by design — it does not commit you to NIST AI RMF, ISO/IEC 42001, or any particular regulator. Pick the framework that fits your jurisdiction and overlay it on the risk-assessment section (§4). Second, the disclosure language in (§5) is plain-language starting text. Run it through qualified counsel familiar with your jurisdiction before publishing it as binding disclosure. Third, the cadence in (§6) is the binding part — a template that does not get re-run on the cadence is a document, not a program.

Who it is for: financial advisory firms with model portfolios or AI-assisted planning workflows. Law firms using AI for document review or research. Healthcare practices with AI-assisted scheduling, triage, or coding. SaaS companies with AI features that touch EU or Colorado consumers in covered contexts. Compliance leads at any of those organizations who need a working draft by Monday.

Scope

Defining which systems, data, and AI use cases this template covers

Scope decides what enters the inventory, which risks get assessed, and which disclosures must be published. Get scope wrong and the rest of the program is working on the wrong systems. This section is short on purpose — it is a placeholder, not a strategy.

Systems in scope. Any AI system — third-party vendor product, open-source model deployed in-house, internally built model, or API service — that materially interacts with a natural person in a consequential or regulated context. "Materially interacts" is the test: if the system's output drives or substantially influences a decision affecting a customer, employee, patient, applicant, or claimant, it is in scope. Pure internal analytics with no consumer touchpoint is out of scope of this template, but may still be in scope of your broader AI registry.

Data in scope. Any personal data — including inferences derived from personal data — that flows into or out of an in-scope AI system. This includes training data shipped with the vendor model, real-time consumer data fed at inference, third-party data enrichment layers, and prompt logs retained for evaluation. Free-text prompts containing personal data are in scope. Outputs that are themselves personal data are in scope.

Use cases in scope. Use this template when deploying AI for at least one of: customer-facing decision support (eligibility, pricing, routing), employment screening or evaluation, financial-services decisions (credit, insurance, claims), healthcare access or coverage decisions, legal or compliance review, content moderation or trust-and-safety decisions, or any other process where an AI output drives or substantially influences an action against a natural person.

Out of scope for this template (clearly). Internal productivity AI (meeting summarizers, code copilots, knowledge search) that does not materially influence any person-facing decision. Investigational or proof-of-concept deployments not yet exposed to natural persons. Models running purely on synthetic data. Even where out of scope of this template, an AI registry should still record these systems; they often graduate into scope.

Inventory

The AI system inventory checklist — per-system capabilities every record must capture

The inventory is the foundation. Without a complete inventory, every downstream obligation (impact assessment, disclosure, vendor management, monitoring) is built on guesswork. Use the per-system checklist below as the structural minimum; adapt column names to your tooling but do not drop fields.

Field What to capture Why it matters
System name & internal ID Display name plus a stable internal identifier that does not change with vendor renames or version bumps. Stability of references across inventory reviews, impact assessments, and disclosure language.
Vendor & developer Vendor name, contract reference, and developer if different from vendor (e.g. open-source model from foundation lab deployed by integrator). Establishes who holds vendor-management obligations and who holds deployer obligations.
Model name & version Model identifier, version string, and date acquired or deployed. Include any sub-models or routing layers. Triggers change-triggered re-assessment when versions change materially.
Training data provenance Training data sources, last refresh date, known limitations declared by vendor, and any data categories that should be excluded downstream. Input side of bias and disparate-impact analysis.
Deployment surface Where the AI meets a natural person — web form, email, in-app, phone (with speech-to-text), internal CRM, etc. Determines which disclosure channel and which consumer is reached.
Covered contexts Which Colorado / EU / industry contexts the system operates in (employment, credit, healthcare, etc.). Drives which legal obligations apply — SB 26-189 covered context, EU high-risk category, industry rule.
Personal data categories Categories of personal data flowing in (prompt + context) and out (response), including inferred attributes. Drives data-protection impact assessment and notification obligations.
Business owner Named accountable executive with sign-off authority for inventory entry, impact assessment, and incident reports. Accountability — without a named owner, the inventory has no one to escalate to.
Last impact assessment date Most recent completed impact assessment for this system and its expiry (annual + 90 days). Calendar trigger for the next impact assessment.
Next scheduled review Date of the next quarterly inventory check and the date of the next annual impact assessment. Drives the monitoring cadence reminders (§6).
Risk tier (from §4) Low / medium / high as assigned by the risk-assessment framework in §4. Sets the depth of monitoring and the speed of disclosure publication.
Incident log link Pointer (URL or ticket reference) to the live incident log for this system, including disparate-impact reports. Connects operational events back to the regulatory record.

Cadence: quarterly review of every entry, with the entire inventory updated within 30 days of any new deployment or substantial modification. A new system without an inventory entry is a compliance event in itself.

Risk Framework

Risk-assessment framework — likelihood × impact, with a NIST AI RMF overlay

Use the 2×2 matrix to score each in-scope system on likelihood of harm × severity of harm if it occurs. Then overlay the result on the four NIST AI RMF 1.0 functions to produce the per-system remediation sequence. The framework is framework-agnostic — drop in ISO/IEC 42001 if that is your adopted framework.

Low likelihood
Medium likelihood
High likelihood
Critical impact
Score 4 — Quarterly review
Score 6 — Monthly review
Score 9 — Continuous
Material impact
Score 2 — Annual
Score 5 — Quarterly
Score 7 — Monthly
Minor impact
Score 1 — Annual
Score 3 — Annual
Score 5 — Quarterly

Score is likelihood-weighted impact. Low/minor combos (scores 1–3) run on annual review. Mid-range (4–5) gets quarterly review. High-severity (6–9) gets monthly or continuous monitoring. The numeric score is the operational trigger; the impact assessment is the document that justifies the score.

NIST AI RMF Overlay

For each system, map the score above onto the four NIST AI RMF 1.0 functions. The mapping below is the per-system remediation checklist that comes out of every impact assessment:

GOVERN

Govern — policies, roles, accountability

Documented AI policy, named accountable executive, escalation path, and an approved use-case boundary for the system. Every high-score system gets a single-throat-to-choke owner with sign-off authority.

MAP

Map — context, stakeholders, impact

Documented deployment context, affected populations, foreseeable harms, and an explicit mapping of the system to the covered contexts (Colorado SB 26-189 covered contexts, EU AI Act risk categories, industry-specific obligations).

MEASURE

Measure — evaluation, bias analysis, monitoring

Quantitative bias testing across protected classes, accuracy and hallucination rate benchmarks, drift detection on input distribution and output distribution. Stored results compared across assessments.

MANAGE

Manage — incident response, change control

Documented incident response runbook with 90-day reporting trigger where applicable, vendor change-of-version notifications, and rollback authority for the deployer. Pre-approved rollback playbook for any regulated system.

The 2×2 score drives the cadence in §6. The NIST overlay drives the per-system remediation priorities in the personalized Compliance Action Plan. Both are inputs to the §5 disclosures — the disclosure language for a "Score 7" system should be more prominent than for a "Score 2" system.

Disclosures

Disclosure templates — pre-interaction and post-decision

The two disclosure moments are pre-interaction (announcing the AI's involvement before the decision is made or materially influenced) and post-decision (explaining the AI's role after an adverse outcome). Both must be in plain language, at the point of decision, and not buried in a privacy policy. Copy, adapt to your channel mix, and have counsel review before publication.

Template 1 — Pre-Interaction Disclosure
"Notice of AI involvement" (web, app, email)

Some parts of this experience use an AI system to help [your company] review and respond. The AI is operated under our AI Acceptable Use Policy, reviewed for accuracy, and supervised by a human team. What this means for you: this AI helps draft, classify, or triage your [request / application / case / message]. A human reviews the AI's output before any decision that affects you is finalized. You may request human review at any point by contacting [contact channel]. If you would prefer not to interact with an AI system, you may [alternative channel: opt out, request a human-only path, etc.]. Questions about how this AI is used? Email [contact channel].

Template 2 — Post-Decision Disclosure (Adverse Outcome)
"Notice of AI-assisted decision" (decision letter, email, portal)

This decision was made with the assistance of an AI system operated by [your company]. The AI reviewed [the inputs — e.g. the application, the case file, the eligibility data] and produced a recommendation. A human reviewer with authority to override the AI made the final call. How the AI contributed: [plain-language description of what the AI did]. What it did not do: [plain-language description of decisions reserved for the human]. Your right to human review: you may request a full human review of this decision. To request human review, contact [contact channel] within [time window — match your policy and applicable law]. We will respond within [response window]. If you believe this decision was incorrect or that the AI made an error, contact [contact channel]. Complaints are reviewed under our AI Incident Response Policy.

Template 3 — Internal-Only Notice (employee-facing systems)
"AI-assisted review" (intranet, Slack, internal app)

This tool uses an AI system to [draft / triage / classify] internal work product. Outputs are advisory; final decisions affecting employees, candidates, or contractors are made by a named human reviewer. The AI is logged. Every interaction is recorded for audit under our [policy reference]. You may flag any output for review by [contact channel]. Flagged outputs are reviewed within [response window].

Disclosure wording has regulatory consequences under both Colorado and EU law. These templates are starting points only — have qualified counsel review and adapt them to your jurisdiction, your channel mix, and your risk tier before publication.

Monitoring

Monitoring cadence — quarterly reviews, annual re-assessment, 90-day change triggers

The cadence is what converts the five sections above from a document into a working program. Without it, the template is inert. The three layers below are independent — they run on different schedules but feed the same evidence record.

Cadence What runs Trigger conditions Evidence record
Quarterly Full inventory review across every in-scope system. Risk-tier re-check for systems whose score may have drifted. Calendar — 1st business week of each calendar quarter. Also within 30 days of any new deployment or substantial modification. Inventory diff log. Reviewed-and-signed entry per system. Changes flagged for impact-assessment re-run.
Annual Full impact assessment re-run for every in-scope system. NIST AI RMF Govern/Map/Measure/Manage checklist refreshed. Disclosure language spot-checked. Calendar — within 90 days of each system's anniversary deployment date (not all on the same day). Signed impact assessment per system. Bias testing results compared year-over-year. Disclosure language changelog.
90-day trigger Targeted impact assessment re-run for the affected system. Vendor management re-engagement if the trigger is a model update. Incident report evaluation. Material vendor model update. Protected-class performance drift above threshold. Internal incident or near-miss. New covered context entered by the system. Regulatory change affecting the deployment. Trigger event log. Targeted impact assessment completed within 90 days. 90-day incident report filed if applicable.
Continuous (Score 6+) Output distribution drift monitoring. Bias-metric dashboards reviewed weekly. Incident tickets flagged for AI causality. Risk score 6 or higher from §4. Any system in a high-risk EU category. Any system in a Colorado Consequential Decision domain. Drift dashboard snapshots. Bias-metric time-series. Incident tickets marked AI-Review.

If your team cannot hit all three cadences, do not run this template at all — a template that is not re-run is worse than no template, because it creates a documented gap that an investigator can find. The GovernIQ assessment ($0, no account) gives you the personalized gap map; the $299 Compliance Action Plan gives you the company-specific 90-day roadmap. Use this template to keep the doc current once the plan is in place.

Frequently Asked Questions

Template reuse — the questions we hear most

What is the first GovernIQ template?
The first published GovernIQ template is the AI Audit & Policy Template — a six-section reusable deliverable derived from a completed GovernIQ engagement. It includes an AI system inventory checklist (§3), a risk-assessment framework built around likelihood × impact with NIST AI RMF Govern/Map/Measure/Manage overlay (§4), plain-language pre- and post-interaction disclosure templates plus an internal-only notice (§5), and a monitoring cadence covering quarterly reviews, annual re-assessment, change-triggered re-assessment, and continuous monitoring for high-scoring systems (§6).
Who is this template designed for?
Mid-market companies deploying AI systems in regulated or consequential contexts — financial advisory firms, law firms, healthcare practices, and SaaS companies selling to enterprise or regulated buyers. It fits organizations that have completed (or are about to complete) a GovernIQ assessment and need a clean, copy-paste-usable starting artifact to hand to a compliance lead, outside counsel, or an internal audit team. It does not replace a NIST AI RMF program, vendor-specific model cards, or legal review of disclosure language.
How was this template derived?
This template is a sanitized, anonymized rendering of the working artifacts used in a real GovernIQ engagement. The engagement produced a personalized Compliance Action Plan with concrete policy language and a deliverables packet. Every section here is the template form of the actual artifact delivered to that client, with company-specific identifiers removed. The structure was chosen because it is the smallest set of documents that, taken together, satisfies the operational obligations under Colorado SB 26-189, SB 24-205, and the EU AI Act for a typical mid-market deployer.
Can I reuse this template in my own AI compliance program?
Yes — that is the point. The template is published under a permissive reuse posture: copy it, fill in your identifiers, run it through a single legal review, and adopt it as your working draft. We recommend pairing it with a GovernIQ assessment (free, 5 minutes) so the gaps and priorities are mapped to your actual AI stack rather than a generic SMB baseline. The disclosures in §5 are written to be plain-language and adjustable to your channel mix; the risk framework is intentionally framework-agnostic so it sits cleanly over NIST AI RMF or ISO/IEC 42001.
What obligations does this template help satisfy?
The template covers the operational record-keeping obligations shared by Colorado SB 26-189, Colorado SB 24-205, and the EU AI Act's deployer requirements. Concretely, the inventory checklist (§3) satisfies the system-record obligation; the risk framework (§4) satisfies the impact-assessment obligation at a structural level; the disclosure templates (§5) satisfy the consumer-disclosure obligation; and the monitoring cadence (§6) satisfies the ongoing-monitoring, annual-review, and change-trigger obligations. It does not, by itself, satisfy safe-harbor programs under any single regulation — adoption must be paired with framework-specific sign-off (NIST AI RMF adoption for Colorado; conformity assessment for EU high-risk systems).
Is this template a substitute for legal advice?
No. The template is a starting artifact and a documentation pattern. It is not legal advice. Before adopting it as a binding policy or before relying on it as evidence in a regulator interaction, run it through qualified counsel familiar with your jurisdiction, your industry, and your AI deployment footprint. The disclosure language in §5 should be reviewed before publication — disclosure wording has regulatory consequences under both Colorado and EU law.
How often should the template be re-run?
Quarterly for the inventory review (with updates within 30 days of any new deployment or substantial modification). Annually for every system-level impact assessment. Within 90 days of any change-triggering event — a material vendor model update, a protected-class performance drift, or an internal incident. A deployer with a working template that does not actually re-run it on this cadence does not have a working compliance program; the cadence is the program.
How do I get a downloadable copy of this template?
Email hello@governiq.com with subject "GovernIQ template download request" from the link in the hero CTA. We send back a clean Markdown copy of the template plus a JSON-LD version of the inventory checklist so you can drop the structure directly into a GRC tool. For deeper engagement, take the free GovernIQ assessment first — the personalized Compliance Action Plan ($299) extends this generic template with company-specific policy language, vendor contract clauses, and remediation sequencing for your actual AI stack.

Turn this generic template into a plan specific to your AI stack.

The GovernIQ assessment identifies which of your AI systems are in scope, maps your current posture against the obligations this template documents, and produces a personalized Compliance Action Plan with company-specific policy language, vendor contract clauses, and a 90-day remediation roadmap. Free to assess — $299 to lock in the plan.

Create a workspace → Guided intake → See the Engagement Offer → Email Me a Downloadable Copy

Free assessment · Personalized Compliance Action Plan $299 · No subscription