A complete, ready-to-deploy operating system for enterprise AI governance: policy, risk, security, data, and agent management — mapped to ISO 27001, NIST AI RMF, and the EU AI Act — now covering the Art. 50 transparency obligations for AI-generated content (in force Aug 2026) — built for organizations running on Microsoft 365.
Compliance-only templates leave the actual operating questions unanswered: who approves an agent, what a security baseline looks like, how a risk register actually gets used. This Kit was built to run a governance program, not just pass an audit.
Most frameworks treat AI governance as risk reduction alone. This Kit starts from a different premise: AI and AI agents can only be governed well if the organization's knowledge is classified, owned, and structured for them to use safely. Compliance follows from that foundation — not the other way around.
That's why this Kit pairs standard policy and risk templates with things most kits skip entirely: knowledge product ownership, agent mandates, and a governed enterprise knowledge foundation your AI can actually be trusted to work from.
Data and knowledge products are classified and owned before any AI system touches them.
Every use case is risk-tiered and routed to the right decision-maker — not everything to the CISO.
Agents run on scoped identities, allowlisted tools, and logging proportionate to their risk.
Registers, mappings, and evidence trails mean an audit is a formality, not a fire drill.
Every document is built to be used together — cross-referenced, consistently structured, and ready to put your organization's name on.
Strategy, vision, business case, and investment roadmap for the boardroom.
Policy, charter, RACI, decision framework, escalation, and portfolio management.
Risk register, assessment methodology, DPIA, model & vendor risk, incident procedure.
Secure configuration, prompt injection & data leakage defenses, Copilot baseline, identity, logging.
Classification, metadata standards, knowledge products, ownership, and retention.
Mandates, permissions, human approval gates, and the central agent register.
Copilot, Teams, and SharePoint governance, Purview labels, Fabric, adoption planning.
Acceptable use policy, employee guidelines, training plan, AI champions program.
Vendor assessment, security questionnaire, DPA and exit-strategy checklists.
ISO 27001, NIS2, EU AI Act, SOC 2, and CIS Controls mappings, plus evidence register.
A practical 1/3/6/12/24-month implementation plan with milestones and KPIs.
The central catalogue of all AI agents with their mandate, owner and human approval gate.
Every template ships with the logic behind it, not just a form to fill in. Here's a piece of the Acceptable Risk Matrix — the reference every other document in the Kit points back to.
| Tier | Description | Approval authority |
|---|---|---|
| HIGH | Materially affects rights, safety, employment, or access to services. | AI Steering Committee |
| LIMITED | User-facing AI requiring Art. 50 transparency (disclosure, content labelling, deepfake marking); recoverable, non-systemic risk. | Process Owner + Governance Lead |
| MINIMAL | Internal productivity assistance with no material external impact. | AI/Agent Owner (registered) |
This kit is reviewed regularly against changing regulation. The recent history is below; the kit version is bumped with every change.
| Date | Version | Document | What changed |
|---|---|---|---|
| 2026-08-20 | 2.1 | Module 12 · AI_Agent_Catalog_Template.docx | Module 12 'AI Agent Catalog' added; the kit is now 12 modules / 65 files. |
| 2026-08-19 | 2.0 | Modules 2, 3 & 4 (policy, risk, cybersecurity) | EU AI Act Art. 50 transparency obligations applied (D-2026-002): limited-risk row, decision tree and labelling controls expanded; full kit revision to v2.0 (12 modules / 65 files). |
One-time purchase. Instant digital delivery. Every document is yours to edit, rebrand, and deploy under your own name.
The governance essentials for organizations just formalizing their AI oversight.
The complete governance and security operating model, for organizations actively deploying AI agents.
The full AI-native enterprise system — governance, security, and a scaled agent program.
No. This Kit gives you a rigorous, regulation-aligned starting point — every template that touches legal or regulatory obligations includes a guidance note flagging where your own Legal or DPO should validate before you publish. It replaces weeks of drafting, not your legal function.
Most of the Kit is platform-agnostic. Module 7 is Microsoft 365/Copilot-specific and is most relevant if you run on that stack — the rest of the Kit governs AI regardless of which platforms you use.
Yes. Every document is delivered as an editable Word or Excel file with no attribution required. Rebrand, restructure, and deploy under your organization's name.
Instantly after purchase, as a ZIP download containing every editable document for your selected tier, organized by module — plus a "Start Here" master index with a recommended implementation sequence, so you're not guessing where to begin. All files are editable Word (.docx), Excel (.xlsx), and PowerPoint (.pptx), yours to rebrand and deploy under your own name.
The Kit is for Microsoft 365 organisations that want to take AI governance seriously — regardless of size or sector. The templates scale from a small business to a full enterprise roll-out.
Get the complete, cross-referenced operating model your Steering Committee will actually use.
Get the Kit — from €397