# AI Governance Program Charter and 90-Day Plan Templates

The starting set for standing up an AI governance program: a program charter, a maturity self-assessment to find your starting point, a policy library checklist in build order, a 90-day launch plan, and a quarterly board dashboard.

**Who this is for:** The person told to build AI governance and given a blank page.

Source playbook: https://aigovernance.com/playbook/ai-governance-program-from-scratch

---

## AI governance program charter template

_The mandate for the program itself, distinct from a committee charter._

### Template

> One to two pages. Approved by the executive sponsor.

- **Purpose and scope of the program**
- **Objectives for the first year:** concrete and measurable
- **Operating model:** which function hosts it, how it connects to Risk, Legal, Security, Data, Product
- **Roles:** program lead, executive sponsor, committee, contributors
- **Decision rights:** what the program can require, approve, and halt
- **Resourcing:** headcount and budget, or the ask
- **Success measures:** how you will know it is working
- **Review date**

### Worked example

- **Purpose:** establish and run AI governance so the company can deploy AI responsibly and meet its regulatory obligations.
- **Year-one objectives:** complete inventory with tiers (month 2); core policy set approved (month 4); all High-tier systems with a signed risk assessment (month 9); first external-facing governance statement (month 12).
- **Operating model:** hosted in Risk; the AI Governance Committee is the decision body; 0.2 FTE each from Legal, Security, Data.
- **Decision rights:** require assessments and controls; approve High-tier deployments; pause any AI system.
- **Resourcing:** 1 dedicated lead; ~$40k external counsel budget.
- **Success measures:** 100% of High-tier systems assessed; zero overdue reviews by month 12; clean first internal audit.
- **Review:** 2027-03.

### Acceptance criteria

- Year-one objectives are measurable with dates.
- The charter states what the program can halt and who sponsors it.
- Resourcing is a real number or a specific ask.

---

## AI governance maturity self-assessment

_A quick read of where you are today, by domain, so the plan targets the real gaps._

### Template

| Domain | 0 None | 1 Ad hoc | 2 Defined | 3 Enforced | 4 Optimized | Current | Target (12 mo) |
|---|---|---|---|---|---|---|---|
| Inventory and classification | | | | | | | |
| Risk assessment | | | | | | | |
| Human oversight | | | | | | | |
| Data governance | | | | | | | |
| Third-party / vendor | | | | | | | |
| Monitoring | | | | | | | |
| Incident response | | | | | | | |
| Regulatory tracking | | | | | | | |
| Board reporting | | | | | | | |

### Worked example

| Domain | Current | Target (12 mo) |
|---|---|---|
| Inventory and classification | 1 (a partial list exists) | 3 |
| Risk assessment | 0 | 3 |
| Human oversight | 1 | 2 |
| Data governance | 2 | 3 |
| Third-party / vendor | 1 | 2 |
| Monitoring | 0 | 2 |
| Incident response | 0 | 2 |
| Regulatory tracking | 1 | 3 |
| Board reporting | 0 | 2 |
Overall: ~0.7 today, target ~2.4.

### Acceptance criteria

- Each domain has a concrete definition per level, not just a number.
- Current scores are honest and evidenced.
- Targets are set for 12 months and feed the launch plan.

---

## Policy library checklist

_Which policies to write, in what order. Do not start with the 40-page framework._

### Template

| Order | Policy | Why this order | Owner | Status |
|---|---|---|---|---|
| 1 | AI acceptable use policy | fastest risk reduction; everyone needs it | | |
| 2 | AI system inventory and classification standard | everything else depends on knowing what you have | | |
| 3 | AI risk assessment procedure | gates deployment | | |
| 4 | Human oversight standard | for consequential decisions | | |
| 5 | Third-party AI / vendor standard | contracts in flight now | | |
| 6 | AI incident response procedure | before you need it | | |
| 7 | Monitoring standard | once models are in production | | |
| 8 | Data governance for AI | often extends existing privacy policy | | |
| 9 | Board reporting standard | once there is something to report | | |

### Worked example

| Order | Policy | Status |
|---|---|---|
| 1 | AI acceptable use | approved, month 1 |
| 2 | Inventory + classification standard | approved, month 2 |
| 3 | Risk assessment procedure | draft, month 3 |
| 4 | Human oversight standard | draft, month 3 |
| 5-9 | ... | scheduled months 4-6 |

### Acceptance criteria

- Policies are sequenced by risk reduction and dependency, not alphabetically.
- Each has an owner and a target month.
- Early policies are short; the framework document comes later, if at all.

---

## 90-day governance launch plan

_The first quarter, week by week, so the program has visible momentum._

### Template

| Weeks | Milestone | Owner | Depends on |
|---|---|---|---|
| 1-2 | Charter drafted and sponsor secured; maturity self-assessment done | program lead | exec time |
| 3-6 | Inventory: run discovery, build the register, assign owners | program lead + IT + procurement | |
| 5-8 | AI acceptable use policy approved and communicated | program lead + Legal | |
| 7-10 | Classification method agreed; tier every system | program lead + Risk | inventory |
| 9-12 | Risk assessments started on High-tier systems; first committee meeting; first board update drafted | program lead | classification |

### Worked example

> Day 90 status against the plan.

| Milestone | Status |
|---|---|
| Charter approved and sponsor secured | done |
| Inventory built, owners assigned | done (44 systems, all tiered and owned) |
| AUP approved and communicated | done (acknowledged by 96% of staff) |
| Every system tiered | done |
| Risk assessments on High-tier systems started | in progress (3 of 3 underway) |
| First committee meeting; first board update | done (committee met twice; update delivered) |
| Monitoring standard | behind: moved to Q2 |

### Acceptance criteria

- The plan produces an inventory and an approved AUP inside 90 days.
- Each milestone has an owner and its dependencies.
- A day-90 status is captured against the plan.

---

## Governance controls this kit produces evidence for

- **BRD-002**: The program and committee charters are the governance committee charter and decision rights.
- **BRD-005**: The maturity self-assessment is the first governance maturity assessment and baseline.
- **MGV-003**: The 90-day plan and year-one objectives are the governance program milestone framework.
- **HOC-007**: The board dashboard is the board reporting mechanism from day one.
- **MGV-002**: The inventory and classification milestones establish the intake and approval workflow.
