L · Templates

The Template Set

The primary records as fill-in forms. Six pages, grouped by where in the lifecycle the record is created.

The framework's artifact set exists because each record supports a decision that would be materially weaker without it (Chapter 24). These templates are the operational form of those records: what the fields are, which are mandatory at which tier, who owns it, what triggers an update, and how long it is kept.

S0–S2 Intake and classification AI Use-Case Canvas Risk Classification Record Initiative Qualification G1 S3–S4 Architecture and data AI-extended ADR Data Lineage Record Pattern Library entry G2 S5–S7 Assurance and authorization Assurance Summary Control Matrix Deployment Authorization G3 S8–S9 Runtime and change Drift/Alert Record AI Change Record Incident note G4 S10 Retirement Retirement Record Evidence archive G5 Every gate decision is taken on records that already exist. No record exists only to be reviewed.
Where each record is created. Records are created once, at the stage that produces the information, and read at every gate that needs it. A gate that asks for a document written for the gate is a gate producing paperwork rather than a decision.

How to use them

  • Copy the fields, not the page. Each template has a plain-text block for pasting into a wiki template, a form builder, an issue template or a repository schema. The HTML here is documentation; your tooling holds the record.
  • Delete what your tier does not require. Mandatory fields are marked by tier. A Tier 1 record that fills every Tier 4 field is governance theatre and will stop being filled honestly.
  • Keep one owner and one location per record. This is the non-duplication rule, and it is the single rule that determines whether your governance data stays true.
  • Never author a derived view. The AI System Card, Assurance Dashboard, Benefit Map and Capability Map are compiled from primary records. If you cannot compile them, do not create them.
  • Preserve history. Scores, decisions and boundaries are re-recorded, never overwritten. The previous value is evidence.

The pages

Download the set

The records above as fill-in files, generated from these pages so the two cannot drift apart. Word for the records a person writes and a body reads; Excel where the record is really a register, or where a calculation belongs in the sheet rather than in someone's head.

[Practice recommendation] Treat these as a starting shape, not a house standard. Delete the fields your tier does not require, put the result in whatever tooling your organization already reads, and keep one owner and one location per record.

Intake and classification

TemplateWhat it isFile
AI Use-Case CanvasThe S1 record, with the fields marked by tier.DOCX · 13 KB
Risk Classification RecordThe scoring record, for the file.DOCX · 13 KB
Risk scoring worksheetEnter D1–D5; the two axes, the matrix tier, the override floor and the final tier calculate themselves. Includes an estate register and the anchors.XLSX · 18 KB

Architecture and data

TemplateWhat it isFile
AI-extended ADRDecision, options, grounding, failure behaviour, vendor fields.DOCX · 13 KB
Data Lineage RecordPer-source record with staleness and derived stores.DOCX · 12 KB
Source registerThe same fields as a register, one row per source.XLSX · 8 KB

Assurance and authorization

TemplateWhat it isFile
AI Assurance SummaryScope, criteria, results, and what was not tested.DOCX · 12 KB
Control MatrixRisk to control to evidence, for one system.DOCX · 12 KB
Control matrix registerThe same, as a filterable sheet with a worked row.XLSX · 8 KB
Deployment Authorization RecordThe G3 decision and the authorized configuration.DOCX · 13 KB

Agents, change and governance

TemplateWhat it isFile
Agent CardIdentity, tools, boundaries, kill-switch, named human owner.DOCX · 13 KB
AI Change RecordClassification, dimensions touched, delta assurance scope.DOCX · 12 KB
Architecture ExceptionTime-boxed, owned, with compensating controls.DOCX · 12 KB
Gate checklistsG1 to G5, one sheet each, with a status summary.XLSX · 16 KB

The scoring worksheet is the one to open first. It carries the anchors, the tier matrix and the safety-override floor, so a scoring session can be run from the sheet itself — though the session still needs two people, one of whom does not carry the delivery date.

Every record, and who owns it

The sixteen primary records from Chapter 24, with the template that covers each. Ownership is the field people get wrong: the owner is accountable for the record being true, not for typing it.

Record Owner Created at Template
Capability RecordSponsor with ArchitectT1Governance records
AI Use-Case CanvasBusiness SponsorS1Intake
Initiative Qualification Record (TG0)PMO with architecture inputT2Intake
Architecture Decision RecordArchitectS3Architecture
Reference Pattern Library entryArchitectOn proposalArchitecture
Data Lineage and Sensitivity RecordData OwnerS4Architecture
Risk Classification RecordRisk LeadS2Intake
Control MatrixRisk LeadS6Assurance
AI Assurance SummarySystem OwnerS6Assurance
Agent CardSystem Owner with SecurityS3Agents
Deployment Authorization RecordSystem Owner or AI Governance BodyS7Assurance
AI Change RecordSystem OwnerS9Runtime
Architecture ExceptionRequesterAny pointGovernance records
Benefit RecordSponsorT6Governance records
Drift/Alert RecordSystem-generatedOn detectionRuntime
Regulatory Overlay ReferenceRisk LeadOn adoptionGovernance records