Implementation Kit
AI Governance Program Charter and 90-Day Plan Templates
The starting set for standing up an AI governance program: a program charter, a maturity self-assessment to find your starting point, a policy library checklist in build order, a 90-day launch plan, and a quarterly board dashboard.
Who this is for: The person told to build AI governance and given a blank page.
1. AI governance program charter template
DocumentThe mandate for the program itself, distinct from a committee charter.
Template
One to two pages. Approved by the executive sponsor.
- Purpose and scope of the program
- Objectives for the first year: concrete and measurable
- Operating model: which function hosts it, how it connects to Risk, Legal, Security, Data, Product
- Roles: program lead, executive sponsor, committee, contributors
- Decision rights: what the program can require, approve, and halt
- Resourcing: headcount and budget, or the ask
- Success measures: how you will know it is working
- Review date
Worked example
- Purpose: establish and run AI governance so the company can deploy AI responsibly and meet its regulatory obligations.
- Year-one objectives: complete inventory with tiers (month 2); core policy set approved (month 4); all High-tier systems with a signed risk assessment (month 9); first external-facing governance statement (month 12).
- Operating model: hosted in Risk; the AI Governance Committee is the decision body; 0.2 FTE each from Legal, Security, Data.
- Decision rights: require assessments and controls; approve High-tier deployments; pause any AI system.
- Resourcing: 1 dedicated lead; ~$40k external counsel budget.
- Success measures: 100% of High-tier systems assessed; zero overdue reviews by month 12; clean first internal audit.
- Review: 2027-03.
Acceptance criteria
- ✓Year-one objectives are measurable with dates.
- ✓The charter states what the program can halt and who sponsors it.
- ✓Resourcing is a real number or a specific ask.
2. AI governance maturity self-assessment
SpreadsheetA quick read of where you are today, by domain, so the plan targets the real gaps.
Template
| Domain | 0 None | 1 Ad hoc | 2 Defined | 3 Enforced | 4 Optimized | Current | Target (12 mo) |
|---|---|---|---|---|---|---|---|
| Inventory and classification | |||||||
| Risk assessment | |||||||
| Human oversight | |||||||
| Data governance | |||||||
| Third-party / vendor | |||||||
| Monitoring | |||||||
| Incident response | |||||||
| Regulatory tracking | |||||||
| Board reporting |
Worked example
| Domain | Current | Target (12 mo) |
|---|---|---|
| Inventory and classification | 1 (a partial list exists) | 3 |
| Risk assessment | 0 | 3 |
| Human oversight | 1 | 2 |
| Data governance | 2 | 3 |
| Third-party / vendor | 1 | 2 |
| Monitoring | 0 | 2 |
| Incident response | 0 | 2 |
| Regulatory tracking | 1 | 3 |
| Board reporting | 0 | 2 |
| Overall: ~0.7 today, target ~2.4. |
Acceptance criteria
- ✓Each domain has a concrete definition per level, not just a number.
- ✓Current scores are honest and evidenced.
- ✓Targets are set for 12 months and feed the launch plan.
3. Policy library checklist
SpreadsheetWhich policies to write, in what order. Do not start with the 40-page framework.
Template
| Order | Policy | Why this order | Owner | Status |
|---|---|---|---|---|
| 1 | AI acceptable use policy | fastest risk reduction; everyone needs it | ||
| 2 | AI system inventory and classification standard | everything else depends on knowing what you have | ||
| 3 | AI risk assessment procedure | gates deployment | ||
| 4 | Human oversight standard | for consequential decisions | ||
| 5 | Third-party AI / vendor standard | contracts in flight now | ||
| 6 | AI incident response procedure | before you need it | ||
| 7 | Monitoring standard | once models are in production | ||
| 8 | Data governance for AI | often extends existing privacy policy | ||
| 9 | Board reporting standard | once there is something to report |
Worked example
| Order | Policy | Status |
|---|---|---|
| 1 | AI acceptable use | approved, month 1 |
| 2 | Inventory + classification standard | approved, month 2 |
| 3 | Risk assessment procedure | draft, month 3 |
| 4 | Human oversight standard | draft, month 3 |
| 5-9 | ... | scheduled months 4-6 |
Acceptance criteria
- ✓Policies are sequenced by risk reduction and dependency, not alphabetically.
- ✓Each has an owner and a target month.
- ✓Early policies are short; the framework document comes later, if at all.
4. 90-day governance launch plan
SpreadsheetThe first quarter, week by week, so the program has visible momentum.
Template
| Weeks | Milestone | Owner | Depends on |
|---|---|---|---|
| 1-2 | Charter drafted and sponsor secured; maturity self-assessment done | program lead | exec time |
| 3-6 | Inventory: run discovery, build the register, assign owners | program lead + IT + procurement | |
| 5-8 | AI acceptable use policy approved and communicated | program lead + Legal | |
| 7-10 | Classification method agreed; tier every system | program lead + Risk | inventory |
| 9-12 | Risk assessments started on High-tier systems; first committee meeting; first board update drafted | program lead | classification |
Worked example
Day 90 status against the plan.
| Milestone | Status |
|---|---|
| Charter approved and sponsor secured | done |
| Inventory built, owners assigned | done (44 systems, all tiered and owned) |
| AUP approved and communicated | done (acknowledged by 96% of staff) |
| Every system tiered | done |
| Risk assessments on High-tier systems started | in progress (3 of 3 underway) |
| First committee meeting; first board update | done (committee met twice; update delivered) |
| Monitoring standard | behind: moved to Q2 |
Acceptance criteria
- ✓The plan produces an inventory and an approved AUP inside 90 days.
- ✓Each milestone has an owner and its dependencies.
- ✓A day-90 status is captured against the plan.
Governance controls this kit produces evidence for
Completing the artifacts above gives you a head start on the evidence requirements for these controls.
The program and committee charters are the governance committee charter and decision rights.
The maturity self-assessment is the first governance maturity assessment and baseline.
The 90-day plan and year-one objectives are the governance program milestone framework.
The board dashboard is the board reporting mechanism from day one.
The inventory and classification milestones establish the intake and approval workflow.
This kit backs one playbook. Read the full guidance for the reasoning behind each artifact.
Decide what to implement next
Assess your governance gaps, then create an action plan with owners and target dates. Build and export without an account; sign in when you want to save your plan.
Start the AI governance assessment →