Implementation Kit
AI Governance Consulting RFP and Build-vs-Buy Templates
Deciding whether to hire an AI governance consultant or build in-house, and running the engagement so the program survives the handoff. A build-vs-buy matrix, an RFP template, a scope-of-work with handoff milestones, and reference-check questions focused on what happens after the consultant leaves.
Who this is for: The leader weighing external help against internal build for an AI governance program.
1. Build-vs-buy decision matrix
SpreadsheetScore the decision on capability, urgency, and budget rather than instinct.
Template
| Factor | Points to building in-house | Points to hiring a consultant |
|---|---|---|
| Internal capability | someone can lead this credibly today | no one with the mix of legal, technical, and risk knowledge |
| Urgency | months of runway before an obligation bites | a deadline in weeks or a live regulator interaction |
| Budget | headcount budget available | project budget easier to get than a hire |
| Scope clarity | you know what program you need | you need help defining the program |
| Longevity need | must be run forever internally | need a jump-start, then internalise |
| Decision: | ||
| If hiring: what stays in-house regardless: |
Worked example
| Factor | Assessment |
|---|---|
| Internal capability | one strong lead, thin on EU AI Act specifics |
| Urgency | EU high-risk deadline ~15 months; a US state deadline in 6 |
| Budget | project budget available; a senior hire would take 4+ months |
| Scope clarity | program shape is clear; execution capacity is the gap |
| Longevity | must run internally long-term |
| Decision | Hire a consultant for a time-boxed build (inventory, classification, EU AI Act gap analysis), with the internal lead owning the program throughout |
| Stays in-house | program ownership, board reporting, all decisions and risk acceptance |
Acceptance criteria
- ✓The decision is scored against the factors, with the reasoning recorded.
- ✓If hiring, the matrix names what stays in-house no matter what (ownership, decisions, board reporting).
- ✓The decision has a review point.
2. AI governance consulting RFP template
DocumentWhat to ask for, so proposals are comparable and handoff is built in from the start.
Template
Send to 3-4 firms. Weight the handoff criteria heavily.
- Context: the company, its AI footprint, and what triggered this
- Scope of work: the specific deliverables (not "advise on AI governance")
- Explicitly out of scope: decisions, risk acceptance, board representation stay with us
- Deliverables: each as an artifact we will own and maintain (templates, register, gap analysis, roadmap)
- Handoff criteria: what "done" means; a knowledge-transfer plan; our team demonstrably able to run each deliverable
- Timeline and milestones
- Team: named individuals and their relevant experience, not just the firm
- References: clients 12+ months post-engagement who still run the program
- Pricing: fixed-fee by deliverable preferred
- Conflicts: disclose any AI tools, audit, or assurance services the firm would later sell us
Worked example
Scope of work excerpt:
- AI system inventory: run discovery, deliver a populated register and the method doc; our team completes the last 20% with you.
- Risk classification: deliver the method and worksheet; classify all systems jointly.
- EU AI Act gap analysis for the 3 High-tier systems: deliver the gap analysis and a dated remediation roadmap.
- Policy set: deliver drafts of the 6 priority policies; we own final approval. Handoff: by the end, our lead can independently run classification and update the roadmap, demonstrated in a working session. All artifacts in our systems, in editable form.
Acceptance criteria
- ✓Deliverables are concrete artifacts the company will own, not advice.
- ✓Handoff criteria and a knowledge-transfer plan are part of the scope, not an afterthought.
- ✓The RFP asks for conflicts (downstream tool or assurance sales) to be disclosed.
3. Engagement scope-of-work with handoff milestones
SpreadsheetThe engagement broken into milestones, each with a deliverable and a handoff test.
Template
| Milestone | Deliverable (we own) | Handoff test (our team can...) | Due | Payment |
|---|---|---|---|---|
| <milestone> | YYYY-MM-DD | % |
Worked example
| Milestone | Deliverable | Handoff test | Due | Payment |
|---|---|---|---|---|
| M1 Inventory | populated register + method doc | run a discovery cycle unaided | 2026-10-31 | 25% |
| M2 Classification | method, worksheet, all systems tiered | classify a new system correctly in a session | 2026-11-30 | 25% |
| M3 EU gap analysis | gap analysis + remediation roadmap | update the roadmap after a scope change | 2026-12-20 | 25% |
| M4 Policy drafts + transfer | 6 policy drafts; KT sessions complete | maintain and update each policy | 2027-01-31 | 25% |
Acceptance criteria
- ✓Every milestone has a deliverable the company owns and a concrete handoff test.
- ✓Payment is tied to milestones, with a meaningful portion at the final transfer.
- ✓The final milestone is knowledge transfer, not a document drop.
4. Vendor reference-check question set
DocumentQuestions for past clients, aimed at whether the program survived after the consultant left.
Template
Call references who are 12+ months past the engagement.
- What exactly did they deliver, and do you still use it?
- After they left, could your team run the program without calling them back?
- What did they build that has since fallen into disuse, and why?
- Did they push decisions and risk acceptance to you, or take them on?
- How did the knowledge transfer actually work?
- Did they later try to sell you tools, audits, or ongoing retainer work?
- Anything you would insist on in the contract if you did it again?
- Would you hire them again for a defined-scope build?
Worked example
Reference call summary (Firm B, client 14 months post-engagement):
- Delivered inventory, classification method, EU gap analysis, 5 policies. Still using all of it.
- Team runs it independently; called the firm once, for a paid half-day on a new regulation.
- Nothing has fallen into disuse; the register is maintained.
- Decisions stayed with the client throughout.
- KT was 4 working sessions plus a recorded walkthrough of each artifact.
- No upsell pressure; offered a retainer, took no for an answer.
- Would insist on fixed-fee-by-milestone again. Would rehire.
Acceptance criteria
- ✓References are 12+ months post-engagement, not current clients.
- ✓Questions focus on post-handoff program survival, not satisfaction during the project.
- ✓The reference is asked directly about downstream sales pressure.
Governance controls this kit produces evidence for
Completing the artifacts above gives you a head start on the evidence requirements for these controls.
The SOW milestones map to the governance program milestone framework.
The RFP and reference-check set are due diligence on the consulting vendor.
The build-vs-buy matrix is a procurement-stage risk assessment for the engagement.
Keeping assurance and decisions in-house preserves an independent assurance function.
This kit backs one playbook. Read the full guidance for the reasoning behind each artifact.
Decide what to implement next
Assess your governance gaps, then create an action plan with owners and target dates. Build and export without an account; sign in when you want to save your plan.
Start the AI governance assessment →