Implementation Kit
AI Governance Disclosure Templates and Evidence Checklist
Turning an internal maturity picture into something you can say to investors and regulators without overclaiming. An investor-facing disclosure template, a regulatory examination evidence package structure, an ESG metrics sheet, and an internal-to-external translation guide.
Who this is for: The governance lead working with IR, Legal, and the CFO on external statements about AI governance.
1. AI governance disclosure template (investor-facing)
DocumentA short, defensible summary of the governance program for an annual report, prospectus, or investor deck.
Template
Short. Every claim traceable to internal evidence. Reviewed by Legal.
- Governance structure: the body that owns AI risk, its authority, and board reporting cadence
- Scope: what the program covers (all AI systems, or a defined subset)
- Risk approach: how systems are classified and what high-risk systems require
- Independent assurance: internal audit or third-party review, and its frequency
- Regulatory posture: the main regimes you are subject to and your readiness stance, without predicting outcomes
- Progress: direction of travel with a metric or two, no vanity numbers
- What we do not claim: be explicit about limits (for example, "governance is maturing; not all controls are automated")
Worked example
"AI risk is overseen by the AI Governance Committee, chaired by the Chief Risk Officer, which reports to the Audit Committee quarterly. The program covers all systems that use machine learning to generate content, predictions, or actions. Each system is risk-classified; high-risk systems require a documented assessment, human oversight, bias testing where individuals are affected, and monitoring. Internal Audit performs an independent review of the program annually; the most recent review concluded the program is effective with identified improvements underway. We are subject to the EU AI Act, US federal and state AI and anti-discrimination law, and sector rules; our high-risk systems are on a remediation plan toward the applicable deadlines. Governance maturity improved from an internal score of 2.4 to 2.6 (of 4) over the year. We do not represent that all controls are automated or that every system has reached the target maturity."
Acceptance criteria
- ✓Every sentence maps to internal evidence a regulator could ask to see.
- ✓The disclosure states what is not claimed, not only what is.
- ✓Legal and IR have signed off, and the language is reused consistently across documents.
2. Regulatory examination response package
SpreadsheetThe structure of the evidence binder, organised by control domain, so a request can be answered fast.
Template
| Domain | Evidence held | Location | Owner | Last refreshed |
|---|---|---|---|---|
| Governance and accountability | charter, RACI, committee minutes, board reports | |||
| Inventory and classification | register, classification method, sample assessments | |||
| Risk management | risk assessments, risk register, treatment plans | |||
| Data governance | provenance records, DPIAs, PII assessments | |||
| Bias and fairness | test protocol, results, remediation logs | |||
| Human oversight | design docs, reviewer records, override monitoring | |||
| Monitoring | metrics specs, dashboards, drift responses | |||
| Incident management | register, post-incident reports, notification assessments | |||
| Third-party | vendor DD records, contracts, monitoring | |||
| Independent assurance | audit program, findings, remediation status |
Worked example
Dry run against a request for "your AI governance framework and evidence it operates".
| Domain | Readiness | Gap action |
|---|---|---|
| Governance and accountability | strong | none |
| Inventory and classification | strong | none |
| Bias and fairness | strong | none |
| Incident management | strong | none |
| Human oversight | weak: design docs scattered | consolidate (Risk, 2026-10) |
| Monitoring | weak: no consolidated dashboard export | build an export (Platform, 2026-11) |
Full package assembled from the binder in about 4 hours.
Acceptance criteria
- ✓Every domain has named evidence, a location, and an owner.
- ✓The package has been assembled once as a dry run, with the time recorded.
- ✓Gaps found in the dry run have owners and dates.
3. ESG AI governance metrics sheet
SpreadsheetQuantitative measures by domain for ESG reporting, with the definition and source of each.
Template
| Metric | Definition | Current value | Prior period | Source |
|---|---|---|---|---|
| AI systems under governance | count in the register with an owner and tier | register | ||
| High-risk systems with a signed assessment | % | risk register | ||
| Bias-tested people-affecting systems | % tested in the last cycle | test logs | ||
| Overdue governance reviews | count | review queue | ||
| AI incidents by severity | Sev-1 / Sev-2 in the period | incident register | ||
| Governance maturity (overall) | internal 0-4 score | maturity assessment | ||
| Staff completing AI training | % | training system | ||
| Independent assurance | last audit date and overall conclusion | audit |
Worked example
| Metric | Current | Prior | Source |
|---|---|---|---|
| AI systems under governance | 47 | 43 | register |
| High-risk with signed assessment | 67% (2/3) | 100% | risk register |
| People-affecting systems bias-tested | 100% | 100% | test logs |
| Overdue reviews | 4 | 7 | review queue |
| Incidents (Sev-1 / Sev-2) | 0 / 2 | 0 / 0 | incident register |
| Governance maturity | 2.6 | 2.4 | maturity assessment |
| Staff AI training completion | 94% | 88% | LMS |
| Independent assurance | H1 2026, "effective with improvements" | 2025, "developing" | audit |
Acceptance criteria
- ✓Every metric has a written definition and a named source, so it is reproducible.
- ✓Values are shown against a prior period.
- ✓Metrics that regressed are shown, not dropped.
4. Internal-to-external translation guide
SpreadsheetHow internal maturity scores and control states map to language you can safely say in public.
Template
| Internal state | Safe external statement | Do not say |
|---|---|---|
| Domain maturity 1 (ad hoc) | "practices exist and are being formalised in this area" | "we have a robust X program" |
| Domain maturity 2 (defined) | "documented policies and procedures are in place; implementation is progressing" | "fully implemented" |
| Domain maturity 3 (enforced) | "controls are consistently applied and monitored" | "best in class" without a benchmark |
| Domain maturity 4 (optimized) | "controls are automated, measured, and continuously improved" | claims of zero risk |
| Open audit finding | "internal audit identified improvements, which are being addressed" | omit it if the disclosure implies completeness |
Worked example
Applied to two domains.
| Domain | Internal state | Approved external line | Do not say |
|---|---|---|---|
| Monitoring | maturity 1 | "we are formalising continuous monitoring for production models, with alerting rolling out in Q4" | "we continuously monitor all models" |
| Bias testing | maturity 3 | "systems affecting individuals undergo bias testing each cycle, with results reviewed before release" | "our models are unbiased" |
Acceptance criteria
- ✓Each internal state has an approved external phrasing and an explicit "do not say".
- ✓Public statements are checked against this guide before release.
- ✓Open findings are disclosed where the surrounding text implies completeness.
Governance controls this kit produces evidence for
Completing the artifacts above gives you a head start on the evidence requirements for these controls.
The disclosure template and ESG metrics sheet are the AI governance ESG and investor disclosure record.
The metrics and translation guide are built on the governance maturity assessment.
The examination package structure supports a voluntary governance adequacy standard.
The examination response package is the regulatory audit-readiness evidence binder.
Care with quantitative claims supports accurate AI use in regulatory and investor reporting.
This kit backs one playbook. Read the full guidance for the reasoning behind each artifact.
Decide what to implement next
Assess your governance gaps, then create an action plan with owners and target dates. Build and export without an account; sign in when you want to save your plan.
Start the AI governance assessment →