Two files, different jobs
The guide tells you what to do and why. The workbook is where you do it. Most people need both, and the guide is the one to read first.
The reference document. Every control states what it means, the evidence artifact that closes it, and the provision it satisfies.
- Scope determination with a classification decision flow
- Red lines: the eight prohibited practices, including the one that catches ordinary companies
- The convergence crosswalk, 32 capabilities mapped to all four instruments
- Evidence architecture: emission at the enforcement point, completeness, validity conditions
- GPAI, conformity assessment, and 15 jurisdictions beyond the EU
- A 15 policy library, and an ISO/IEC 42001 certification readiness checklist
A connected workbook. Enter a fact once and it flows everywhere it is needed. No macros, nothing phoning home.
- Answer ten questions per system and the risk tier, deadline, control load and GPAI exposure are derived
- Mark your markets and 19 regimes self-flag as applies, monitor or out of scope
- A 260 action checklist, and a gap report that writes itself
- Registers for risk, incidents, vendors, impact assessments, model cards and training
- A ten dimension maturity model and a 21 metric board pack
- A 115 term glossary, so the file stands alone
The accidental provider problem
Version 1.2 adds a test for something most enterprises have not considered.
Did we modify the model?
Fine-tuning, distillation, continued pre-training. Anything that changes the model rather than just calling it.
Did we make it available beyond the team that modified it?
Another business unit counts. A group entity counts. Your own product counts.
Your GPAI exposure
Two yes answers and the row flags red. You may hold provider obligations under Articles 53 and 55 without any procurement or board decision having been taken.
How the workbook talks to you
One visual convention runs through all 27 sheets. Once you can read it you can navigate any of them without instructions.
Your input
A fact only you know: a system name, an owner, a status, a date, a score. Dropdowns appear wherever the answer comes from a fixed set.
Calculated
Derived from what you entered, often on another sheet. Risk tiers, deadlines, completion percentages, ageing flags. Never overtype these.
Status flags
Applied automatically so problems surface without being hunted for.
What is in the 21 chapters
Short framing, then long tables. Explanation appears only where it changes what you do.
The order to work the workbook
Each phase makes the next one possible. Skipping ahead is the most common way these programs fail: controls with no inventory behind them cannot be traced to anything.
Scope: know what you have
Week 1List every AI system, including shadow AI and the AI quietly embedded in tools you already buy. Answer ten questions per system and the workbook derives the risk tier, the compliance deadline, the control load and your GPAI exposure.
Mark the markets you operate in. Each regime flags as Applies, Monitor or Not in scope, with dates, penalty exposure and the crosswalk capabilities that satisfy it. This is where nineteen sets of obligations collapse into one control set.
For a single system when you need a fast answer rather than a portfolio view. It assembles an obligation profile at the bottom.
Map: design one control set
Weeks 2 to 4The master map, and the reason the toolkit exists. Each row is one capability with the single artifact that evidences it across all frameworks at once. Design your controls from this sheet and you build once instead of four times.
Which companion standard fills which gap. Referenced by number, clause and intent only, so you will still need licensed copies to implement against.
The depth the management frameworks deliberately leave out. Prompt injection, excessive agency, model poisoning, each mapped back to the crosswalk row that owns it. Give this sheet to your security team.
If you are in financial services, life sciences, insurance, HR, healthcare or the public sector, this is what stacks on top. Sector rules rarely replace AI law; they add to it.
Operate: do the work
Months 1 to 6Your backlog. Assign an owner, a status and a target date. This one sheet drives most of the dashboard, the gap report and the owner view, so time spent here pays back everywhere else.
Nothing to fill in. Every open P1 foundation appears here automatically, in order, and drops off when you mark it complete. This is what you take to a steering meeting.
Pick a person and see only their outstanding items. Send it to them rather than asking them to search a 260 row sheet.
Where the artifacts the crosswalk names actually live: risk with calculated inherent and residual ratings, impact assessments, statement of applicability, incidents, vendors, training records, model cards, and a RACI that flags any activity without exactly one accountable owner.
Prove: show it works
OngoingThe artifact to control index, and the first sheet an auditor should see. Evidence past its review date is flagged Stale automatically, because governance that was true last year is not evidence today.
Score honestly against the five level model. The radar chart shows your profile against the Level 3 target, which is the point at which a program becomes genuinely defensible.
KPIs and KRIs on one printable page, several pulling automatically from your working sheets. Report the risk indicators every meeting and the performance indicators quarterly.
The 30, 60, 90 and 180 day plan with an exit test for each phase, so you know when you are genuinely finished rather than merely busy.
What updates on its own
You should never type the same fact twice. Enter something once and it flows everywhere it is needed.
The Command Center tells you what to do next
Not only a dashboard. A guidance line changes as you progress: with an empty file it says start with the inventory; once foundations are open it names how many and sends you to the gap report; past Level 3 it moves you on to assurance and conformity preparation.
Keeping it honest
A governance file that is filled in once and never reopened is documentation, not governance. This is the minimum cadence.
Work the gap report
Ten minutes. Move P1 items forward, and add anything new that surfaced.
Sweep for new systems
Shadow AI arrives continuously. Check the inventory against reality, and clear overdue reviews.
Re-verify the Atlas
Re-score maturity, refresh the board pack, and check the jurisdiction dates against primary sources.
Review the whole file
Record it on the version log. Auditors ask when a governance artifact was last reviewed, and by whom.
What people ask
Which one should I read first?
The guide. It tells you whether any of this applies to you, which is Chapter 2, and what you must stop doing, which is Chapter 3. Then open the workbook and start on the AI Systems sheet.
Do I need all 27 sheets?
No. The minimum viable path is four: AI Systems, Jurisdiction Atlas, Checklist and Gap Report. Everything else supports those or proves them. Start there and let the rest earn its way in.
Will the workbook work in Google Sheets or LibreOffice?
Yes. Every formula avoids Excel-only functions for exactly this reason. Charts and conditional formatting may render slightly differently, but nothing breaks and no macros are used.
How many AI systems can it hold?
Sixty in the inventory as shipped, which suits a single team or business unit. Beyond a few hundred systems, or with many people editing at once, you have outgrown a spreadsheet and should move to a GRC platform. Use the workbook as the specification for configuring it.
How current are the regulatory dates?
Every position was verified against primary or official sources in August 2026. Two entries show why that matters: Colorado repealed and replaced its 2024 AI Act, and Canada's AIDA lapsed with Bill C-27 and was never reintroduced. Re-verify before you act, and log the check.
Does either document reproduce the ISO standards?
No, deliberately. ISO/IEC standards are copyrighted. Everything refers to them by number, clause and intent in original words. The certification readiness checklist in Chapter 18 is built around the audit process rather than the structure of the standard, for that reason. You need licensed copies to implement against.
Can I use these with clients, or inside a product?
Use them freely inside your own organization, including on client work you deliver yourself. Reselling, redistributing as your own, or white-labeling into a commercial product needs written permission.