AI Governance Institute
All governance templates →What are our obligations under emerging AI regulations?

Implementation Kit

AI Regulatory Applicability Matrix and Compliance Calendar

The base layer for tracking what applies to you: an applicability matrix of systems against jurisdictions and regulations, a deadline calendar, and a monitoring subscription list so a new rule does not arrive as a surprise.

Who this is for: The compliance owner building the first structured view of the organization's AI regulatory exposure.

Download the kit (Markdown) ↓3 artifacts. Every table also copies as CSV.

1. Regulatory applicability matrix

Spreadsheet

AI systems down one axis, regulations across the other, with the applicability trigger and current status in each cell.

Template

SystemJurisdiction(s)RegulationApplicability triggerApplies?Key obligationsStatus
<system><what makes it in scope>Yes / No / MonitoringNot started / In progress / Compliant

Worked example

SystemJurisdiction(s)RegulationApplicability triggerApplies?Key obligationsStatus
Resume ScreenerEUEU AI Act (high-risk)Annex III employment use; affects EU applicantsYesrisk mgmt, tech docs, human oversight, FRIA, registrationIn progress
Resume ScreenerUS-NYCLocal Law 144automated employment decision tool used on NYC candidatesYesannual bias audit; candidate noticeCompliant
Support CopilotEUEU AI Act (limited risk)AI interacting with peopleYestransparency: users told they interact with AICompliant
Fraud ScoringUSstate UDAP + fair lending analoguesconsumer impactMonitoringdisparate impact reviewIn progress

Acceptance criteria

  • Every AI system is assessed against every regulation that could apply, with the trigger written down.
  • "No" and "Monitoring" verdicts have a one-line reason, not just a blank.
  • Each applicable cell links to where the obligation detail and evidence live.

2. Compliance calendar

Spreadsheet

Deadlines by jurisdiction and system, so the next obligation is always visible.

Template

DateJurisdictionRegulationObligationSystems affectedOwnerStatus
YYYY-MM-DDon track / at risk / done

Worked example

DateJurisdictionRegulationObligationSystems affectedOwnerStatus
2026-12-31US-NYCLL144annual bias audit publishedResume ScreenerPeople Opson track
2027-12-02EUEU AI Actstand-alone Annex III high-risk obligations applyResume ScreenerComplianceat risk (FRIA pending)
2028-08-02EUEU AI Actproduct-embedded high-risk obligations apply(none currently)Compliancemonitoring

Acceptance criteria

  • Every applicable obligation with a date is on the calendar.
  • Each entry has an owner and a status that is reviewed on a set cadence.
  • Dates are kept current as deadlines shift (the EU AI Act high-risk dates moved once already).

3. Regulatory monitoring subscription list

Spreadsheet

The feeds that would tell you about a new or changed obligation, with an owner per source.

Template

SourceTypeWhat it coversCheck cadenceOwner
<agency feed / newsletter / registry>official / secondarydaily / weekly / monthly<name>

Worked example

SourceTypeCoversCadenceOwner
EUR-Lex + EU AI Office updatesofficialEU AI Act delegated acts, guidanceweeklyEU Compliance
US state legislature trackerssecondarystate AI bills (CO, CA, TX, ...)weeklyUS Compliance
Sector regulator bulletins (banking, health)officialsupervisory guidance on AIweeklySector leads
National standards bodiesofficialISO/IEC and national AI standardsmonthlyAI Gov Lead

Acceptance criteria

  • Every jurisdiction where the organization operates has at least one monitored source.
  • Each source has an owner and a check cadence.
  • A relevant finding from monitoring opens a calendar entry and, if needed, a review task.

Governance controls this kit produces evidence for

Completing the artifacts above gives you a head start on the evidence requirements for these controls.

CMP-001
CMP-001

The applicability matrix is the multi-jurisdiction regulatory compliance mapping.

CMP-004
CMP-004

The matrix and calendar together track non-legislative and soft-law obligations alongside binding ones.

CMP-002
CMP-002

The monitoring subscription list is the international standards and regulatory monitoring workflow.

HOC-001
HOC-001

Applicability assessment depends on a per-system risk classification.

CMP-007
CMP-007

Rows flagging EU AI Act high-risk status feed the conformity assessment process.

This kit backs one playbook. Read the full guidance for the reasoning behind each artifact.

Decide what to implement next

Assess your governance gaps, then create an action plan with owners and target dates. Build and export without an account; sign in when you want to save your plan.

Start the AI governance assessment →