Free editable template · NIST AI RMF · ISO/IEC 42001
AI Governance Framework Template
An AI governance framework is the operating structure that decides who owns each AI system, which systems are in use, how risky each one is, which controls apply, how often decisions are reviewed and what happens when something goes wrong. This free template gives you all six parts as editable sections, mapped to the NIST AI RMF functions Govern, Map, Measure and Manage, with ISO/IEC 42001 named as the management-system standard.
Edit your AI governance framework
1. Roles and accountability
The Head of Risk owns this framework for [Organization] and keeps it current. The AI review group approves every new AI system and any change that moves a system into the High tier. Every AI system and AI agent has one named system owner who is accountable for its purpose, data, permissions and evidence. Staff who use AI follow the [Organization] AI policy.
2. AI inventory
[Organization] keeps one inventory of every AI system and AI agent in use, including tools bought by a team and features switched on inside existing software. Each entry records: name, system owner, purpose, vendor and model, data classes used, people affected, what it can access and do, risk tier, approval date and next review date. A system that is not in the inventory is not approved.
3. Risk tiers
Every system is placed in one tier before use. Prohibited: Not used. Stop and take legal advice before any further work. High: Affects rights, money, safety or access to services, or acts without a person in the loop. Full assessment, named approver, human oversight, testing and logging before go-live. Medium: Uses internal or confidential data, or its output reaches customers after review. Assessment, named owner, access limited to need and logging. Low: Internal productivity with public or internal data and a person reviewing every output. Inventory entry and yearly review. When in doubt, use the higher tier.
4. Controls
High and Medium systems: access limited to what the purpose needs; a person reviews output before it affects a customer, employee or payment; decisions and actions are logged; accuracy and bias are tested before go-live and after material change; vendor terms cover data use, retention and incident notice. AI agents act only through credentials issued to them, never a person's account. Low systems: inventory entry and the AI policy.
5. Review cadence
The Head of Risk reviews the inventory and every High system every 6 months, and Medium systems at least yearly. A system is also reviewed before a material change: a new model, vendor, data class, user group, tool, or action it can take on its own. Each review records the decision, the reviewer and the next review date.
6. Incident handling
Anyone who sees an AI system cause harm, expose data or act outside its purpose reports it to the Head of Risk within 24 hours. The Head of Risk contains it first (pause the system, revoke its access), records what happened, informs the system owner and the AI review group, meets any legal or contractual notice duty with counsel, and updates the risk tier and controls before the system is used again.
Appendix: NIST AI RMF and ISO/IEC 42001
Govern: 1. Roles and accountability; 5. Review cadence. Map: 2. AI inventory; 3. Risk tiers. Measure: 3. Risk tiers (testing); 5. Review cadence (monitoring). Manage: 4. Controls; 6. Incident handling. ISO/IEC 42001 sets requirements for an AI management system; use its clauses to check this framework before seeking certification. This template is a starting point, not legal advice.
AI governance frameworks: NIST AI RMF and ISO/IEC 42001
The two AI governance frameworks most organizations reach for do different jobs. The NIST AI RMF is voluntary guidance that organizes AI risk work into four functions: Govern, Map, Measure and Manage. ISO/IEC 42001 is the international standard for an AI management system, with requirements an accredited body can certify against.
Use NIST to decide what the work is and ISO/IEC 42001 when a customer or regulator wants a certificate. This template covers the ground both expect you to have: owners, an inventory, risk tiers, controls, reviews and incident records.
Not used. Stop and take legal advice before any further work.
High
Affects rights, money, safety or access to services, or acts without a person in the loop. Full assessment, named approver, human oversight, testing and logging before go-live.
Medium
Uses internal or confidential data, or its output reaches customers after review. Assessment, named owner, access limited to need and logging.
Low
Internal productivity with public or internal data and a person reviewing every output. Inventory entry and yearly review.
Common questions
What is an AI governance framework?
It is the structure that assigns an owner to every AI system, keeps an inventory, sorts systems by risk, sets the controls each tier needs, fixes a review cadence and defines how incidents are handled. A policy states intent; the framework makes someone accountable for carrying it out.
Which AI governance frameworks should we follow?
Most organizations use the NIST AI Risk Management Framework to structure the work and ISO/IEC 42001 when they want a certifiable AI management system, then add the laws that apply to them. They work together rather than compete.
Is the NIST AI RMF mandatory?
No. NIST describes AI RMF 1.0 as intended for voluntary use. Contracts, sector rules or customers may still ask you to show that you follow it.
Does this template make us ISO/IEC 42001 certified?
No. Certification needs an accredited audit of your management system against the standard. The template gives you the roles, inventory, risk tiers, controls and records an auditor will ask about.
Is the download really free?
Yes. You enter an email address to unlock the editable Word file. There is no payment and no card details are asked for.