AI Governance Pro
Everything in the policy pack, plus the operational layer auditors ask for: an AI register to inventory every system, a vendor-AI assessment checklist to vet third-party tools, and an incident-response addendum for when AI goes wrong — each cross-referenced to ISO 42001 and the Voluntary AI Safety Standard.
An enterprise procurement questionnaire is usually where the gap shows up. You have a written AI policy, so the first question is fine. Then it asks you to list the AI systems in use, name an owner for each, describe how the vendor was assessed before you signed, and set out what happens if one of those systems produces a harmful output. A policy document has no answer to any of that.
AI Governance Pro is A$199 one-off and covers the wider set. The core policy is in there — acceptable use, human oversight, data handling, transparency, accountability roles — along with implementation and rollout guidance and a staff acknowledgement summary. Around it sit three operational documents: an AI register, a vendor-AI assessment checklist and an incident-response addendum, each annotated to ISO 42001 and Australia's Voluntary AI Safety Standard.
Turnaround is roughly 30 to 60 minutes, delivered on your order page with downloads. The speed is the point. Governance documentation is the work businesses postpone until a client, an insurer or an auditor forces the issue, and by then the deadline is usually days away rather than months.
Inventory, vendor vetting, and the bad day
The AI register is a structured table for cataloguing every AI system in use — owner, purpose, risk tier, data types, vendor, review date — and it arrives with completed sample rows, so the expected level of detail is visible before you start filling it in. The vendor-AI assessment checklist is the document you work through before signing with a new AI supplier rather than after: scored questions across security, data residency, training-data use, bias, explainability, human oversight and contractual terms, with a pass/flag/fail rating guide.
The incident-response addendum covers the direction nobody plans for. It sets severity tiers, detection triggers, escalation paths and roles, containment and remediation steps, notification and record-keeping guidance, and a reusable incident log template. All three are templates and written guidance. They do not connect to your systems, scan your tools or raise alerts.
The mapping notes are alignment evidence, not a certificate
Each deliverable is annotated to the relevant ISO 42001 clauses and Voluntary AI Safety Standard guardrails. When a procurement team or a client risk officer asks which control a given document addresses, the answer is written on the page instead of reconstructed from memory under pressure.
The limit is worth stating plainly. These are AI-written mapping notes, not an audit and not an assessment. No assessor has looked at your business, and nothing in the pack makes you certified to ISO 42001 or formally compliant with anything. What you hold is documentation showing how your governance material lines up with the published clauses and guardrails.
Nothing in this pack maintains itself
A register is only worth having while it is current, and the checklist does nothing unless someone actually runs it on the next supplier. Decide who owns that before the documents go out to staff — the accountability roles in the core policy are the natural place to write the name down.
Have the pack reviewed by a qualified professional who knows your industry, your customer contracts and your data obligations before it reaches staff or clients. This is general information and a drafting starting point, not legal or compliance advice, and the incident addendum in particular commits you to a response you then have to be able to deliver.
What you get
- Core AI governance policy covering acceptable use, human oversight, data handling, transparency and accountability roles
- Implementation and rollout guidance with a staff acknowledgement summary
- AI register / inventory template — a structured table to catalogue every AI system in use, with owner, purpose, risk tier, data types, vendor and review-date columns plus completed sample rows
- Vendor-AI assessment checklist — scored questions on security, data residency, training-data use, bias, explainability, human oversight and contractual terms, with a pass/flag/fail rating guide
- AI incident-response addendum — severity tiers, detection triggers, escalation and roles, containment and remediation steps, notification/record-keeping guidance and a reusable incident log template
- ISO 42001 and Australian Voluntary AI Safety Standard mapping notes — each deliverable annotated to the relevant clauses/guardrails so you can show alignment
Turnaround: ~30–60 minutes. Delivery: On-page + downloads.
Frequently asked questions
Does the AI register arrive with our tools already listed in it?
No. It arrives as a structured template with the columns set up — owner, purpose, risk tier, data types, vendor, review date — plus completed sample rows showing the intended level of detail. Nothing connects to your network, browser or accounts, and no system detection happens. You or a nominated owner fills in the real inventory.
We already own the AI Governance Policy Pack. Would buying Pro mean paying twice for the same policy?
Partly, yes. Pro is built on the policy pack and includes it, so a second purchase covers the core policy, the rollout guidance and the staff acknowledgement summary again. If what you want is the register, the vendor checklist, the incident addendum and the standards mapping, get in touch before you order rather than putting the purchase through — we can tell you what your options are before any money moves.
Can the vendor checklist be used on AI tools we have already deployed?
Yes. It is a set of scored questions with a pass/flag/fail rating guide, so it works retrospectively on existing suppliers as well as prospective ones. You supply the answers from vendor documentation, contracts and security pages — the checklist structures the assessment, it does not investigate the vendor for you.
Our board will ask whether this makes us ISO 42001 certified. What is the honest answer?
No, it does not. Certification comes from an accredited certification body after an audit, and this product involves neither. What you receive is mapping notes annotating each deliverable to the relevant ISO 42001 clauses and Voluntary AI Safety Standard guardrails, so you can show how your documentation aligns. Treat it as evidence of structure and effort, not as a certificate.
Is anything recurring, and is every buyer sent the same file?
It is A$199 one-off with nothing recurring. The pack is generated per order from what you provide rather than being a fixed file everyone receives, though the register, checklist and incident log are deliberately left as blank templates for you to populate.