An operational worksheet for translating AI principles into enforceable governance — structured around the Five-Layer Governance Stack and four-tier risk model.
Canonical reference: The Governance Playbook — From Principles to Practice
Principles do not govern. Processes do. A signed AI ethics statement is not governance. Governance is who decides, on what evidence, with what consequences for getting it wrong. The five-layer stack — Policy, Process, Tooling, People, Assurance — is the structure that converts principles into operational discipline.
Every layer needs a named owner. Not a committee. Not a department. A named individual with the authority to decide and the accountability to be wrong. Governance without an owner is theatre. The accountability matrix on this worksheet is the discipline that prevents theatre.
For each principle, write a corresponding testable policy statement.
| AI Principle | Testable Policy Statement | Metric / Threshold | Applies to Tier |
|---|---|---|---|
| Fairness | |||
| Transparency | |||
| Accountability | |||
| Safety | |||
| Privacy | |||
For each policy statement above, confirm it passes this test:
Map each governance gate to its trigger, reviewer, and SLA.
| Gate Name | Trigger / When | Reviewer / Approver | SLA (hours/days) | Exception Process |
|---|---|---|---|---|
| Design Review | ||||
| Data Review | ||||
| Fairness Review | ||||
| Pre-Production | ||||
| Deployment Gate | ||||
| Post-Launch Review | ||||
| Issue Severity | Escalation To | Response Time | Decision Authority |
|---|---|---|---|
| Low (Tier 1-2) | |||
| Medium (Tier 2-3) | |||
| High (Tier 3) | |||
| Critical (Tier 4) |
| AI System | Owner | Decisions Influenced | Risk Tier | EU AI Act Classification | Governance Status |
|---|---|---|---|---|---|
For each system, evaluate these factors to assign a tier:
| Governance Function | Current State | Target Tool / Platform | Priority | Timeline |
|---|---|---|---|---|
| Bias / Fairness Testing | ||||
| Model Card Generation | ||||
| Drift Monitoring | ||||
| Explainability Reporting | ||||
| Data Lineage Tracking | ||||
| CI/CD Gate Enforcement | ||||
| Incident Alerting | ||||
| Audit Trail / Logging |
| Governance Activity | Responsible (Does) | Accountable (Owns) | Consulted | Informed |
|---|---|---|---|---|
| Policy Creation | ||||
| Risk Tier Classification | ||||
| Fairness Review | ||||
| Deployment Approval | ||||
| Incident Response | ||||
| Regulatory Compliance | ||||
| External Audit | ||||
| Governance Framework Review |
| Role | Named Individual | Decision Authority | Escalation To |
|---|---|---|---|
| Chief AI Officer / AI Lead | |||
| AI Governance Owner | |||
| AI Ethics Lead | |||
| Legal / Compliance Lead | |||
| Executive Sponsor | |||
| Category | KPI | Current Value | Target | Review Cadence | Owner |
|---|---|---|---|---|---|
| Prevention | Deployments caught pre-production | ||||
| Prevention | Estimated cost avoidance ($) | ||||
| Efficiency | Avg. time to governed deployment | ||||
| Efficiency | % reviews within SLA | ||||
| Compliance | % AI systems with documentation | ||||
| Compliance | Shadow AI exposure count | ||||
| Trust | Stakeholder confidence score | ||||
| Trust | Governance maturity score |
| Review Type | Frequency | Scope | Reviewer | Next Scheduled |
|---|---|---|---|---|
| Governance Framework Review | Quarterly | |||
| Model Performance Review | Monthly | |||
| Regulatory Alignment Check | Quarterly | |||
| External Audit | Annual | |||
| Executive Governance Report | Quarterly | |||
Honestly assess whether each anti-pattern exists in your organization. Check the box if you recognize the symptom.
Count of anti-patterns present: _____ / 5
0 = Mature governance. 1–2 = Address during next review cycle. 3+ = Governance requires immediate structural intervention.
Rate your organization's current state for each governance layer.
Use this planner to assign owners and deadlines for your governance implementation. Recommended timeline: 12 weeks from kickoff to operational governance.
Definitions used throughout this worksheet. These align with the canonical methodology article.
Five-Layer Governance Stack. Policy → Process → Tooling → People → Assurance. The five operational layers that together convert AI principles into enforceable governance. Skipping any layer creates a gap that compounds.
Risk Tier (Four-Tier Model). Tier 1 Experimental (2 governance touchpoints) → Tier 2 Operational (5) → Tier 3 High-Impact (9) → Tier 4 Critical (14). Risk-proportionate governance: more touchpoints for higher-stakes systems.
Falsifiable Policy. A policy that specifies measurable, auditable conditions for compliance. “Be fair” is not falsifiable. “Demographic parity within 5% across protected classes, audited quarterly” is.
Anti-Pattern. A common governance failure mode that looks like governance but does not function as governance. The five named anti-patterns: Paper Tiger, Bottleneck Board, One-Size-Fits-All, Measurement Mismatch, Set-and-Forget.
RACI (Responsible / Accountable / Consulted / Informed). The accountability matrix for governance decisions. Each AI lifecycle event must have exactly one Accountable party. Multiple Accountables is the same as zero Accountables.
Governance Gate. A mandatory checkpoint in the AI lifecycle (deployment approval, model retirement, incident response) where governance criteria must be met before proceeding. Skipping a gate accumulates governance debt.
SLA (Service Level Agreement) for Governance. A defined response time for governance decisions — e.g., deployment approval within 5 business days, incident response within 1 hour for P1. Without SLAs, governance becomes the bottleneck the business routes around.
EU AI Act Penalty Tiers (Article 99). 7%/€35M turnover for prohibited practices (Art. 99(3)); 3%/€15M for high-risk system non-compliance (Art. 99(4)); 1%/€7.5M for misleading authorities (Art. 99(5)). Calibrate the assurance layer to these exposures.
This worksheet is the operational layer of a published, sourced framework. The methodology, anti-pattern analysis, and external citations live in the canonical article below.
Canonical article: The Governance Playbook — From Principles to Practice — the five-layer stack, four-tier risk model, anti-pattern diagnostic, and 12-week implementation arc.
Companion frameworks:
Key external sources: Pacific AI 2025 Governance Survey · IAPP 2025 AI Governance Report · Gartner 2026 governance platform market analysis · IBM Institute for Business Value — AI Governance Trends · NIST AI Risk Management Framework