Skip to content

Free editable template · NIST AI RMF · ISO/IEC 42001

AI Governance Framework Template

An AI governance framework is the operating structure that decides who owns each AI system, which systems are in use, how risky each one is, which controls apply, how often decisions are reviewed and what happens when something goes wrong. This free template gives you all six parts as editable sections, mapped to the NIST AI RMF functions Govern, Map, Measure and Manage, with ISO/IEC 42001 named as the management-system standard.

Edit your AI governance framework

1. Roles and accountability

The Head of Risk owns this framework for [Organization] and keeps it current. The AI review group approves every new AI system and any change that moves a system into the High tier. Every AI system and AI agent has one named system owner who is accountable for its purpose, data, permissions and evidence. Staff who use AI follow the [Organization] AI policy.

2. AI inventory

[Organization] keeps one inventory of every AI system and AI agent in use, including tools bought by a team and features switched on inside existing software. Each entry records: name, system owner, purpose, vendor and model, data classes used, people affected, what it can access and do, risk tier, approval date and next review date. A system that is not in the inventory is not approved.

3. Risk tiers

Every system is placed in one tier before use. Prohibited: Not used. Stop and take legal advice before any further work. High: Affects rights, money, safety or access to services, or acts without a person in the loop. Full assessment, named approver, human oversight, testing and logging before go-live. Medium: Uses internal or confidential data, or its output reaches customers after review. Assessment, named owner, access limited to need and logging. Low: Internal productivity with public or internal data and a person reviewing every output. Inventory entry and yearly review. When in doubt, use the higher tier.

4. Controls

High and Medium systems: access limited to what the purpose needs; a person reviews output before it affects a customer, employee or payment; decisions and actions are logged; accuracy and bias are tested before go-live and after material change; vendor terms cover data use, retention and incident notice. AI agents act only through credentials issued to them, never a person's account. Low systems: inventory entry and the AI policy.

5. Review cadence

The Head of Risk reviews the inventory and every High system every 6 months, and Medium systems at least yearly. A system is also reviewed before a material change: a new model, vendor, data class, user group, tool, or action it can take on its own. Each review records the decision, the reviewer and the next review date.

6. Incident handling

Anyone who sees an AI system cause harm, expose data or act outside its purpose reports it to the Head of Risk within 24 hours. The Head of Risk contains it first (pause the system, revoke its access), records what happened, informs the system owner and the AI review group, meets any legal or contractual notice duty with counsel, and updates the risk tier and controls before the system is used again.

Appendix: NIST AI RMF and ISO/IEC 42001

Govern: 1. Roles and accountability; 5. Review cadence. Map: 2. AI inventory; 3. Risk tiers. Measure: 3. Risk tiers (testing); 5. Review cadence (monitoring). Manage: 4. Controls; 6. Incident handling. ISO/IEC 42001 sets requirements for an AI management system; use its clauses to check this framework before seeking certification. This template is a starting point, not legal advice.

Get the editable Word file — free

Enter your email to unlock the download. We store it with your request so we know who is using the template.

See our privacy notice.

How the template maps to NIST AI RMF

NIST AI RMF functionFramework sections
Govern1. Roles and accountability; 5. Review cadence
Map2. AI inventory; 3. Risk tiers
Measure3. Risk tiers (testing); 5. Review cadence (monitoring)
Manage4. Controls; 6. Incident handling

Source: NIST, AI Risk Management Framework (AI RMF 1.0, NIST AI 100-1, January 2023, doi.org/10.6028/NIST.AI.100-1).

AI governance frameworks: NIST AI RMF and ISO/IEC 42001

The two AI governance frameworks most organizations reach for do different jobs. The NIST AI RMF is voluntary guidance that organizes AI risk work into four functions: Govern, Map, Measure and Manage. ISO/IEC 42001 is the international standard for an AI management system, with requirements an accredited body can certify against.

Use NIST to decide what the work is and ISO/IEC 42001 when a customer or regulator wants a certificate. This template covers the ground both expect you to have: owners, an inventory, risk tiers, controls, reviews and incident records.

Sources: nist.gov — AI Risk Management Framework; iso.org — ISO/IEC 42001:2023.

The four risk tiers

TierWhat it means and what it needs
ProhibitedNot used. Stop and take legal advice before any further work.
HighAffects rights, money, safety or access to services, or acts without a person in the loop. Full assessment, named approver, human oversight, testing and logging before go-live.
MediumUses internal or confidential data, or its output reaches customers after review. Assessment, named owner, access limited to need and logging.
LowInternal productivity with public or internal data and a person reviewing every output. Inventory entry and yearly review.

Common questions

What is an AI governance framework?
It is the structure that assigns an owner to every AI system, keeps an inventory, sorts systems by risk, sets the controls each tier needs, fixes a review cadence and defines how incidents are handled. A policy states intent; the framework makes someone accountable for carrying it out.
Which AI governance frameworks should we follow?
Most organizations use the NIST AI Risk Management Framework to structure the work and ISO/IEC 42001 when they want a certifiable AI management system, then add the laws that apply to them. They work together rather than compete.
Is the NIST AI RMF mandatory?
No. NIST describes AI RMF 1.0 as intended for voluntary use. Contracts, sector rules or customers may still ask you to show that you follow it.
Does this template make us ISO/IEC 42001 certified?
No. Certification needs an accredited audit of your management system against the standard. The template gives you the roles, inventory, risk tiers, controls and records an auditor will ask about.
Is the download really free?
Yes. You enter an email address to unlock the editable Word file. There is no payment and no card details are asked for.

Related: What an AI governance framework is · AI policy template · AI risk assessment template