AI Governance Institute
All governance templates →How do we disclose AI governance maturity to investors and regulators?

Implementation Kit

AI Governance Disclosure Templates and Evidence Checklist

Turning an internal maturity picture into something you can say to investors and regulators without overclaiming. An investor-facing disclosure template, a regulatory examination evidence package structure, an ESG metrics sheet, and an internal-to-external translation guide.

Who this is for: The governance lead working with IR, Legal, and the CFO on external statements about AI governance.

Download the kit (Markdown) ↓4 artifacts. Every table also copies as CSV.

1. AI governance disclosure template (investor-facing)

Document

A short, defensible summary of the governance program for an annual report, prospectus, or investor deck.

Template

Short. Every claim traceable to internal evidence. Reviewed by Legal.

  • Governance structure: the body that owns AI risk, its authority, and board reporting cadence
  • Scope: what the program covers (all AI systems, or a defined subset)
  • Risk approach: how systems are classified and what high-risk systems require
  • Independent assurance: internal audit or third-party review, and its frequency
  • Regulatory posture: the main regimes you are subject to and your readiness stance, without predicting outcomes
  • Progress: direction of travel with a metric or two, no vanity numbers
  • What we do not claim: be explicit about limits (for example, "governance is maturing; not all controls are automated")

Worked example

"AI risk is overseen by the AI Governance Committee, chaired by the Chief Risk Officer, which reports to the Audit Committee quarterly. The program covers all systems that use machine learning to generate content, predictions, or actions. Each system is risk-classified; high-risk systems require a documented assessment, human oversight, bias testing where individuals are affected, and monitoring. Internal Audit performs an independent review of the program annually; the most recent review concluded the program is effective with identified improvements underway. We are subject to the EU AI Act, US federal and state AI and anti-discrimination law, and sector rules; our high-risk systems are on a remediation plan toward the applicable deadlines. Governance maturity improved from an internal score of 2.4 to 2.6 (of 4) over the year. We do not represent that all controls are automated or that every system has reached the target maturity."

Acceptance criteria

  • Every sentence maps to internal evidence a regulator could ask to see.
  • The disclosure states what is not claimed, not only what is.
  • Legal and IR have signed off, and the language is reused consistently across documents.

2. Regulatory examination response package

Spreadsheet

The structure of the evidence binder, organised by control domain, so a request can be answered fast.

Template

DomainEvidence heldLocationOwnerLast refreshed
Governance and accountabilitycharter, RACI, committee minutes, board reports
Inventory and classificationregister, classification method, sample assessments
Risk managementrisk assessments, risk register, treatment plans
Data governanceprovenance records, DPIAs, PII assessments
Bias and fairnesstest protocol, results, remediation logs
Human oversightdesign docs, reviewer records, override monitoring
Monitoringmetrics specs, dashboards, drift responses
Incident managementregister, post-incident reports, notification assessments
Third-partyvendor DD records, contracts, monitoring
Independent assuranceaudit program, findings, remediation status

Worked example

Dry run against a request for "your AI governance framework and evidence it operates".

DomainReadinessGap action
Governance and accountabilitystrongnone
Inventory and classificationstrongnone
Bias and fairnessstrongnone
Incident managementstrongnone
Human oversightweak: design docs scatteredconsolidate (Risk, 2026-10)
Monitoringweak: no consolidated dashboard exportbuild an export (Platform, 2026-11)

Full package assembled from the binder in about 4 hours.

Acceptance criteria

  • Every domain has named evidence, a location, and an owner.
  • The package has been assembled once as a dry run, with the time recorded.
  • Gaps found in the dry run have owners and dates.

3. ESG AI governance metrics sheet

Spreadsheet

Quantitative measures by domain for ESG reporting, with the definition and source of each.

Template

MetricDefinitionCurrent valuePrior periodSource
AI systems under governancecount in the register with an owner and tierregister
High-risk systems with a signed assessment%risk register
Bias-tested people-affecting systems% tested in the last cycletest logs
Overdue governance reviewscountreview queue
AI incidents by severitySev-1 / Sev-2 in the periodincident register
Governance maturity (overall)internal 0-4 scorematurity assessment
Staff completing AI training%training system
Independent assurancelast audit date and overall conclusionaudit

Worked example

MetricCurrentPriorSource
AI systems under governance4743register
High-risk with signed assessment67% (2/3)100%risk register
People-affecting systems bias-tested100%100%test logs
Overdue reviews47review queue
Incidents (Sev-1 / Sev-2)0 / 20 / 0incident register
Governance maturity2.62.4maturity assessment
Staff AI training completion94%88%LMS
Independent assuranceH1 2026, "effective with improvements"2025, "developing"audit

Acceptance criteria

  • Every metric has a written definition and a named source, so it is reproducible.
  • Values are shown against a prior period.
  • Metrics that regressed are shown, not dropped.

4. Internal-to-external translation guide

Spreadsheet

How internal maturity scores and control states map to language you can safely say in public.

Template

Internal stateSafe external statementDo not say
Domain maturity 1 (ad hoc)"practices exist and are being formalised in this area""we have a robust X program"
Domain maturity 2 (defined)"documented policies and procedures are in place; implementation is progressing""fully implemented"
Domain maturity 3 (enforced)"controls are consistently applied and monitored""best in class" without a benchmark
Domain maturity 4 (optimized)"controls are automated, measured, and continuously improved"claims of zero risk
Open audit finding"internal audit identified improvements, which are being addressed"omit it if the disclosure implies completeness

Worked example

Applied to two domains.

DomainInternal stateApproved external lineDo not say
Monitoringmaturity 1"we are formalising continuous monitoring for production models, with alerting rolling out in Q4""we continuously monitor all models"
Bias testingmaturity 3"systems affecting individuals undergo bias testing each cycle, with results reviewed before release""our models are unbiased"

Acceptance criteria

  • Each internal state has an approved external phrasing and an explicit "do not say".
  • Public statements are checked against this guide before release.
  • Open findings are disclosed where the surrounding text implies completeness.

Governance controls this kit produces evidence for

Completing the artifacts above gives you a head start on the evidence requirements for these controls.

BRD-004
BRD-004

The disclosure template and ESG metrics sheet are the AI governance ESG and investor disclosure record.

BRD-005
BRD-005

The metrics and translation guide are built on the governance maturity assessment.

BRD-008
BRD-008

The examination package structure supports a voluntary governance adequacy standard.

ALC-005
ALC-005

The examination response package is the regulatory audit-readiness evidence binder.

CMP-010
CMP-010

Care with quantitative claims supports accurate AI use in regulatory and investor reporting.

This kit backs one playbook. Read the full guidance for the reasoning behind each artifact.

Decide what to implement next

Assess your governance gaps, then create an action plan with owners and target dates. Build and export without an account; sign in when you want to save your plan.

Start the AI governance assessment →