PRACTICAL AI GOVERNANCE RESOURCES

Start with artifacts your organisation can actually use.

Editable templates, a source-backed control matrix and a dated readiness brief for inventory, supplier review, impact assessment, framework mapping, evidence and AI governance decisions.

FREE RESOURCES

Six foundations for an auditable AI governance workflow.

CSV · Editable

AI System Inventory

Capture purpose, users, data, supplier, model, risk tier, ownership, approvals and next review.

Download CSV
Markdown · Editable

AI Vendor Assessment

Review data use, training, identity, tenant separation, testing, subprocessors, incidents and exit.

Download checklist
Markdown · Editable

AI Impact Assessment Starter

Document affected people, possible harm, human oversight, data quality, controls and residual risk.

Download starter
Matrix · CSV + Web

AI Control Matrix

Map reusable control areas across the EU AI Act, ISO/IEC 42001, ISO/IEC 27001 and NIST AI RMF without claiming legal equivalence.

Open Control Matrix
Report · Source-backed

European AI Governance Readiness Brief 2026

Current regulatory timing, six evidence domains, a 12-question readiness rubric and transparent methodology based on official EU, ISO and NIST sources.

Read the brief
CSV · Self-assessment

AI Governance Readiness Scorecard

Score 12 practical evidence checks from 0–2 and record owner, evidence link and review date. A maturity heuristic, not a compliance score.

Download scorecard

FROM TEMPLATE TO OPERATING PRACTICE

Use one evidence model across governance, security and compliance work.

01

Name an owner

Assign business and technical accountability for each use case.

02

Classify proportionately

Use consequence, data and regulatory relevance to decide review depth.

03

Attach evidence

Link decisions to tests, supplier answers, approvals and controls.

04

Review change

Set triggers for model changes, incidents, renewals and reassessment.

RELATED GUIDANCE & EVIDENCE

Go deeper where the decision needs more context.

AI framework comparison

EU AI Act vs ISO 42001 vs ISO 27001 vs NIST AI RMF.

Read comparison

AI vendor security review

30 practical questions before buying or renewing AI.

Read review guide

Evidence & trust policy

See how SundAI labels verified facts, source-backed guidance, illustrative scenarios and measured outcomes.

Review evidence policy

Illustrative case studies

Delivery scenarios show scope and expected value without presenting examples as client claims.

View scenarios

Methodology

How governance, security, human oversight, evidence and lifecycle review fit together.

Read methodology
Important: Resources are general governance tools and evidence aids, not legal advice, a statistical peer benchmark or a guarantee of EU AI Act compliance. Requirements depend on the system, role, sector, use and applicable law.