AI Governance Institute
All governance templates →Should we hire an AI governance consultant, or build the program in-house?

Implementation Kit

AI Governance Consulting RFP and Build-vs-Buy Templates

Deciding whether to hire an AI governance consultant or build in-house, and running the engagement so the program survives the handoff. A build-vs-buy matrix, an RFP template, a scope-of-work with handoff milestones, and reference-check questions focused on what happens after the consultant leaves.

Who this is for: The leader weighing external help against internal build for an AI governance program.

Download the kit (Markdown) ↓4 artifacts. Every table also copies as CSV.

1. Build-vs-buy decision matrix

Spreadsheet

Score the decision on capability, urgency, and budget rather than instinct.

Template

FactorPoints to building in-housePoints to hiring a consultant
Internal capabilitysomeone can lead this credibly todayno one with the mix of legal, technical, and risk knowledge
Urgencymonths of runway before an obligation bitesa deadline in weeks or a live regulator interaction
Budgetheadcount budget availableproject budget easier to get than a hire
Scope clarityyou know what program you needyou need help defining the program
Longevity needmust be run forever internallyneed a jump-start, then internalise
Decision:
If hiring: what stays in-house regardless:

Worked example

FactorAssessment
Internal capabilityone strong lead, thin on EU AI Act specifics
UrgencyEU high-risk deadline ~15 months; a US state deadline in 6
Budgetproject budget available; a senior hire would take 4+ months
Scope clarityprogram shape is clear; execution capacity is the gap
Longevitymust run internally long-term
DecisionHire a consultant for a time-boxed build (inventory, classification, EU AI Act gap analysis), with the internal lead owning the program throughout
Stays in-houseprogram ownership, board reporting, all decisions and risk acceptance

Acceptance criteria

  • The decision is scored against the factors, with the reasoning recorded.
  • If hiring, the matrix names what stays in-house no matter what (ownership, decisions, board reporting).
  • The decision has a review point.

2. AI governance consulting RFP template

Document

What to ask for, so proposals are comparable and handoff is built in from the start.

Template

Send to 3-4 firms. Weight the handoff criteria heavily.

  • Context: the company, its AI footprint, and what triggered this
  • Scope of work: the specific deliverables (not "advise on AI governance")
  • Explicitly out of scope: decisions, risk acceptance, board representation stay with us
  • Deliverables: each as an artifact we will own and maintain (templates, register, gap analysis, roadmap)
  • Handoff criteria: what "done" means; a knowledge-transfer plan; our team demonstrably able to run each deliverable
  • Timeline and milestones
  • Team: named individuals and their relevant experience, not just the firm
  • References: clients 12+ months post-engagement who still run the program
  • Pricing: fixed-fee by deliverable preferred
  • Conflicts: disclose any AI tools, audit, or assurance services the firm would later sell us

Worked example

Scope of work excerpt:

  1. AI system inventory: run discovery, deliver a populated register and the method doc; our team completes the last 20% with you.
  2. Risk classification: deliver the method and worksheet; classify all systems jointly.
  3. EU AI Act gap analysis for the 3 High-tier systems: deliver the gap analysis and a dated remediation roadmap.
  4. Policy set: deliver drafts of the 6 priority policies; we own final approval. Handoff: by the end, our lead can independently run classification and update the roadmap, demonstrated in a working session. All artifacts in our systems, in editable form.

Acceptance criteria

  • Deliverables are concrete artifacts the company will own, not advice.
  • Handoff criteria and a knowledge-transfer plan are part of the scope, not an afterthought.
  • The RFP asks for conflicts (downstream tool or assurance sales) to be disclosed.

3. Engagement scope-of-work with handoff milestones

Spreadsheet

The engagement broken into milestones, each with a deliverable and a handoff test.

Template

MilestoneDeliverable (we own)Handoff test (our team can...)DuePayment
<milestone>YYYY-MM-DD%

Worked example

MilestoneDeliverableHandoff testDuePayment
M1 Inventorypopulated register + method docrun a discovery cycle unaided2026-10-3125%
M2 Classificationmethod, worksheet, all systems tieredclassify a new system correctly in a session2026-11-3025%
M3 EU gap analysisgap analysis + remediation roadmapupdate the roadmap after a scope change2026-12-2025%
M4 Policy drafts + transfer6 policy drafts; KT sessions completemaintain and update each policy2027-01-3125%

Acceptance criteria

  • Every milestone has a deliverable the company owns and a concrete handoff test.
  • Payment is tied to milestones, with a meaningful portion at the final transfer.
  • The final milestone is knowledge transfer, not a document drop.

4. Vendor reference-check question set

Document

Questions for past clients, aimed at whether the program survived after the consultant left.

Template

Call references who are 12+ months past the engagement.

  • What exactly did they deliver, and do you still use it?
  • After they left, could your team run the program without calling them back?
  • What did they build that has since fallen into disuse, and why?
  • Did they push decisions and risk acceptance to you, or take them on?
  • How did the knowledge transfer actually work?
  • Did they later try to sell you tools, audits, or ongoing retainer work?
  • Anything you would insist on in the contract if you did it again?
  • Would you hire them again for a defined-scope build?

Worked example

Reference call summary (Firm B, client 14 months post-engagement):

  • Delivered inventory, classification method, EU gap analysis, 5 policies. Still using all of it.
  • Team runs it independently; called the firm once, for a paid half-day on a new regulation.
  • Nothing has fallen into disuse; the register is maintained.
  • Decisions stayed with the client throughout.
  • KT was 4 working sessions plus a recorded walkthrough of each artifact.
  • No upsell pressure; offered a retainer, took no for an answer.
  • Would insist on fixed-fee-by-milestone again. Would rehire.

Acceptance criteria

  • References are 12+ months post-engagement, not current clients.
  • Questions focus on post-handoff program survival, not satisfaction during the project.
  • The reference is asked directly about downstream sales pressure.

Governance controls this kit produces evidence for

Completing the artifacts above gives you a head start on the evidence requirements for these controls.

MGV-003
MGV-003

The SOW milestones map to the governance program milestone framework.

PRC-001
PRC-001

The RFP and reference-check set are due diligence on the consulting vendor.

PRC-005
PRC-005

The build-vs-buy matrix is a procurement-stage risk assessment for the engagement.

MGV-004
MGV-004

Keeping assurance and decisions in-house preserves an independent assurance function.

This kit backs one playbook. Read the full guidance for the reasoning behind each artifact.

Decide what to implement next

Assess your governance gaps, then create an action plan with owners and target dates. Build and export without an account; sign in when you want to save your plan.

Start the AI governance assessment →