Document catalogue · Written by an LL.B, CISA, CIPP-certified advisor
The paperwork, already written.
Policies, registers, and assessments drafted by a practising GRC advisor — then adapted to your sector, size, and risk appetite. Editable Word and Excel files you own outright.
Start with the document you need now
Buy a single policy today, or have a full kit tailored and delivered with an implementation plan.
$150
Instant download
AI Acceptable Use Policy
For organizations rolling out generative AI to staff and needing one clear rulebook.
- Approved and prohibited uses
- Data classification rules
- Tool request and approval flow
- Human review requirements
- Editable .docx, 12 pages
From $1,500
Tailored · 1–2 weeks
AI Governance Starter Kit
Launch a governance program with five documents that work together, tailored to your organization.
- AI Governance Policy
- Acceptable Use Policy
- AI system inventory template
- AI risk assessment
- AI vendor questionnaire
- Intake call, one revision round, walkthrough call
From $4,500
Tailored · 2–4 weeks
EU AI Act & ISO 42001 Toolkit
For organizations preparing for EU AI Act obligations and ISO/IEC 42001 alignment.
- EU AI Act gap assessment
- ISO/IEC 42001 gap assessment
- AI impact assessment
- System classification worksheet
- Everything in the Starter Kit
Using AI in hiring, lending, housing, or insurance decisions? California’s ADMT rules and Colorado’s AI Act apply from January 1, 2027. The 2027 AI Deadline Sprint gets your notices, opt-out or appeal workflows, and risk assessments done in three weeks.
Working with CUI or preparing for CMMC? AI policies for defense contractors — including AI + CUI handling standards and NIST 800-171 control mapping — are delivered through our sister practice at cyberdsc.com.
Not a template pack
Written for your context
Sector, headcount, regulator, and risk appetite change the wording. We make those edits before delivery.
Mapped to frameworks
Each clause references the NIST AI RMF function, ISO 42001 clause, or EU AI Act article it supports.
Includes the rollout
A one-page implementation note tells you who approves it, who communicates it, and what to review first.
When documents aren’t enough
Policies are the start. When you need them running, tested, and ready for an auditor or a customer review, move up to an advisory engagement.
Readiness Assessment
Know where you stand against the EU AI Act, ISO/IEC 42001, or NIST AI RMF, with a 90-day plan.
ISO/IEC 42001 Implementation
Build an AI management system ready for its certification audit.
Fractional AI Governance Lead
A senior AI governance owner who keeps your program running month to month.
Every document is guidance, not legal advice. Have your counsel review policies before adoption.
Not sure which one
Tell us what you’re being asked for.
A customer questionnaire, a board request, an audit finding, a procurement blocker — we will point you to the smallest thing that solves it.
