Frameworks

Structured frameworks, working instruments, and reference guides for AI governance professionals, compliance teams, and the organisations building and deploying autonomous AI systems in regulated environments.

For Product Teams

Structured audit frameworks built exclusively for evaluating how AI agents behave in use.

AI Agent Experience (AX) Audit Toolkit

The first systematic UX evaluation framework built exclusively for AI agents. 66 heuristic criteria, 50+ test scenarios across conversational, voice, multimodal and multi-agent systems. Includes auto-scoring spreadsheet and complete example audit.

What your team needs to know and do before shipping an AI feature in Europe. High-risk classification in plain language, what to build in before launch, what documentation you need. No legal jargon. Built for builders, not lawyers.

AI Feature Risk Scorecard

Score any AI feature before you ship it. Assess autonomy level, reversibility, user impact, and regulatory exposure using a simple structured scoring model.
A quick 20-minute evaluation that tells you whether the feature requires governance review before launch.

Know the Landscape

Reference guides for AI governance professionals to understand the frameworks, the failures, and the regulatory exposure before you begin.

AI Governance Frameworks Reference Guide

The four frameworks shaping AI governance – EU AI Act, ISO 42001, NIST AI RMF, and the UK approach, explained in plain language and mapped against each other. What each one covers, where they overlap, which applies to your system, and the key obligations practitioners need to understand. The starting point for any serious AI governance engagement.

AI Failure Patterns & Governance Mapping Guide

55+ failure patterns across conversational agents, embedded AI systems, and dynamic architectures – each mapped to governance implications, oversight requirements, and regulatory obligations under EU AI Act, ISO 42001, and NIST AI RMF. The reference document you reach for when something looks wrong and you need to name it, evidence it, and remediate it.

AI Governance Risk & Regulatory Mapping Guide

Industry-by-industry AI governance and regulatory risk mapping across healthcare, finance, insurance, cybersecurity, legal, and HR. Maps AI activities to governance risks, specific regulatory articles, and required controls across EU AI Act, ISO 42001, GDPR, FCA Consumer Duty, and sector frameworks. Includes the working risk matrix spreadsheet.

Assess the System

Working instruments for scoring, gap-assessing, and auditing governance controls in AI and agentic systems.

AI Governance & Risk Assessment Toolkit

A complete toolkit for assessing governance risk in autonomous and agentic AI systems. Built around the 15-criteria Containment Risk Assessment Framework, scoring autonomy level, reversibility, third-party impact, failure detection, and regulatory exposure. Includes the live scoring spreadsheet, failure pattern library, and industry regulatory mapping to evaluate systems consistently.

ISO 42001 Gap Assessment Workbook

A structured working spreadsheet for assessing organisational readiness against ISO 42001 – the AI Management System Standard. Maps every control clause to current state, gap identification, risk level, and remediation actions. Designed for practitioners conducting or preparing for an ISO 42001 audit. Open it on day one of an engagement and start working.

EU AI Act Compliance Checklist

A practical working checklist for organisations assessing their obligations under the EU AI Act. Covers system classification, high-risk determination, conformity assessment requirements, transparency obligations, human oversight controls, and required documentation. Built for practitioners translating regulation into operational compliance steps.

Govern the System

Ready-to-adapt policies, templates, and playbooks for organisations deploying AI in regulated environments.

AI Governance Policy Templates

Three governance policies for organisations deploying AI: AI Acceptable Use, AI Risk Management, and AI Ethics Governance. Structured to align with EU AI Act and ISO 42001, including governance roles, approval thresholds, and risk classification logic. Annotated guidance explains how to adapt each policy to your organisation’s AI systems and regulatory requirements.

DPIA Template for AI Systems

A Data Protection Impact Assessment template designed specifically for AI systems, not adapted from a generic DPIA. Structured to address risks created by automated decision-making, profiling, bias, and data governance in AI deployments. Aligned with ICO guidance and GDPR Article 35, including worked examples for common high-risk AI systems.

AI Incident Response Playbook

A practical incident response playbook for AI systems, covering what to do when an AI system causes harm or triggers a regulatory breach. Includes decision trees for incident classification, escalation paths, evidence preservation, and regulator notification. Built for governance teams responding to incidents under EU AI Act and UK regulatory frameworks.

Scroll to Top