Skip to main content
Skip to main content
Free downloads — no sign-up

Free AI governance templates and compliance checklists

Most AI governance advice stops at principles. These are the working documents underneath them: 6 templates you can download and fill in today, plus three checklists for the moments that actually matter — before you deploy, when young people are involved, and when a board asks what is running.

Download the templates

CSV files open in Excel, Google Sheets or Numbers. Nothing is tracked and no account is needed — the files are served straight from this site.

  • CSV

    AI controls matrix

    Risks, controls, evidence, testing cadence and framework mapping in one sheet.

    Use it for: Evidencing that each identified AI risk has a named control and a test date.

    Download AI controls matrix
  • CSV

    Roles and RACI matrix

    Decision rights across sponsor, owner, operator, control and audit roles.

    Use it for: Showing who approves an AI use case and who can stop it.

    Download Roles and RACI matrix
  • CSV

    KPI register

    KPI definitions, formulas, targets, RAG thresholds and owners.

    Use it for: Measuring whether an AI deployment actually improved the outcome.

    Download KPI register
  • CSV

    Process register

    Catalogue every process with owner, workflow, systems and service levels.

    Use it for: Finding which processes AI touches before you automate any of them.

    Download Process register
  • CSV

    Data-source inventory

    Systems of record, event logs, extraction methods and refresh cadence.

    Use it for: Knowing exactly what data a model or assistant can reach.

    Download Data-source inventory
  • Markdown

    Strategy card

    One-page outcome, KPIs, roles, controls and framework mapping.

    Use it for: Getting an AI proposal onto a single page a board can approve or reject.

    Download Strategy card

Practical AI compliance checklists

Before you deploy an AI assistant

Work through this before a model touches real people or real records. Every line should have a named owner and a written answer.

  • Write down the decision the assistant supports, and the decision it must never make alone.
  • List the data it can read, where that data lives, and the lawful basis for using it.
  • Record whether personal data is involved and complete a DPIA if it is.
  • Name the human who reviews outputs, and the escalation path when they disagree.
  • Decide what is logged: prompts, outputs, approvals, overrides and retention periods.
  • Test the assistant on your own worst cases, not the vendor's demo cases.
  • Agree how users are told they are talking to AI, in plain language.
  • Set the review date and the conditions that would trigger switching it off.

Safeguarding checklist for AI used with young people

Relevant wherever an AI tool is used by or with under-18s — schools, tutoring, youth services and family use.

  • Confirm the tool states its minimum age and how age is established.
  • Check what happens when a learner discloses harm, and who is alerted.
  • Confirm that a parent, carer or educator can see activity and turn features off.
  • Check whether conversation history is retained, and how it is deleted on request.
  • Confirm the tool refuses to substitute for professional support in a crisis.
  • Record the internal reporting route for concerns raised through the tool.

Board-level AI review checklist

A short agenda for a governance or audit committee reviewing AI already in use.

  • How many AI use cases are live, and who owns each one?
  • Which use cases are high impact on people, and what controls apply?
  • What evidence exists that a human reviewed high-impact outputs?
  • What incidents or near misses were recorded this period?
  • What did we stop doing, and why?
  • Which policies or registers are now out of date?

These checklists are practical guidance from our own governance work, not legal advice. Terms used here are defined in the AI governance glossary.

Questions about the templates

Are these AI governance templates really free?
Yes. Every template on this page is a plain CSV or Markdown file you can download without an account, an email address or a payment. Use them internally, edit them, and keep them.
What format are the templates in?
Five are CSV files that open directly in Excel, Google Sheets or Numbers. The strategy card is a Markdown file you can paste into any document or wiki.
Do the templates map to a recognised standard?
They are structured around the practices those standards expect — documented risks and controls, named decision rights, measurable outcomes and retained evidence. They are working documents, not a certification, and they do not constitute legal advice.
Do I need an ALFI + EDIE account to use them?
No. The templates stand alone. If you later want the assistants to help you fill them in, the framework's Codify tools work from the same structure.
Can I use these to prepare for a UK GDPR or ICO enquiry?
They help you assemble the material such an enquiry asks for — what data you process, why, who decided, and what controls apply. Whether your answers are sufficient is a judgement for your own data protection officer or legal adviser.

Try the demo