The Template Set
The primary records as fill-in forms. Six pages, grouped by where in the lifecycle the record is created.
The framework's artifact set exists because each record supports a decision that would be materially weaker without it (Chapter 24). These templates are the operational form of those records: what the fields are, which are mandatory at which tier, who owns it, what triggers an update, and how long it is kept.
How to use them
- Copy the fields, not the page. Each template has a plain-text block for pasting into a wiki template, a form builder, an issue template or a repository schema. The HTML here is documentation; your tooling holds the record.
- Delete what your tier does not require. Mandatory fields are marked by tier. A Tier 1 record that fills every Tier 4 field is governance theatre and will stop being filled honestly.
- Keep one owner and one location per record. This is the non-duplication rule, and it is the single rule that determines whether your governance data stays true.
- Never author a derived view. The AI System Card, Assurance Dashboard, Benefit Map and Capability Map are compiled from primary records. If you cannot compile them, do not create them.
- Preserve history. Scores, decisions and boundaries are re-recorded, never overwritten. The previous value is evidence.
The pages
Intake and classification →
AI Use-Case Canvas, Risk Classification Record, and the initiative qualification record that keeps portfolio intake honest.
Architecture and data →
AI-extended Architecture Decision Record, Data Lineage and Sensitivity Record, grounding source register and pattern library entry.
Assurance and authorization →
AI Assurance Summary, Control Matrix and the Deployment Authorization Record that every later drift comparison refers back to.
Agents and autonomy →
Agent Card, machine-readable authority boundary, kill-switch condition record and the human oversight design note.
Runtime, change and retirement →
Drift/Alert Record, AI Change Record with delta assurance scope, incident note and the retirement record.
Governance and exceptions →
Architecture Exception, gate decision minute, Regulatory Overlay Reference, Benefit Record and a governance body terms of reference.
Download the set
The records above as fill-in files, generated from these pages so the two cannot drift apart. Word for the records a person writes and a body reads; Excel where the record is really a register, or where a calculation belongs in the sheet rather than in someone's head.
[Practice recommendation] Treat these as a starting shape, not a house standard. Delete the fields your tier does not require, put the result in whatever tooling your organization already reads, and keep one owner and one location per record.
Intake and classification
| Template | What it is | File |
|---|---|---|
| AI Use-Case Canvas | The S1 record, with the fields marked by tier. | DOCX · 13 KB |
| Risk Classification Record | The scoring record, for the file. | DOCX · 13 KB |
| Risk scoring worksheet | Enter D1–D5; the two axes, the matrix tier, the override floor and the final tier calculate themselves. Includes an estate register and the anchors. | XLSX · 18 KB |
Architecture and data
| Template | What it is | File |
|---|---|---|
| AI-extended ADR | Decision, options, grounding, failure behaviour, vendor fields. | DOCX · 13 KB |
| Data Lineage Record | Per-source record with staleness and derived stores. | DOCX · 12 KB |
| Source register | The same fields as a register, one row per source. | XLSX · 8 KB |
Assurance and authorization
| Template | What it is | File |
|---|---|---|
| AI Assurance Summary | Scope, criteria, results, and what was not tested. | DOCX · 12 KB |
| Control Matrix | Risk to control to evidence, for one system. | DOCX · 12 KB |
| Control matrix register | The same, as a filterable sheet with a worked row. | XLSX · 8 KB |
| Deployment Authorization Record | The G3 decision and the authorized configuration. | DOCX · 13 KB |
Agents, change and governance
| Template | What it is | File |
|---|---|---|
| Agent Card | Identity, tools, boundaries, kill-switch, named human owner. | DOCX · 13 KB |
| AI Change Record | Classification, dimensions touched, delta assurance scope. | DOCX · 12 KB |
| Architecture Exception | Time-boxed, owned, with compensating controls. | DOCX · 12 KB |
| Gate checklists | G1 to G5, one sheet each, with a status summary. | XLSX · 16 KB |
The scoring worksheet is the one to open first. It carries the anchors, the tier matrix and the safety-override floor, so a scoring session can be run from the sheet itself — though the session still needs two people, one of whom does not carry the delivery date.
Every record, and who owns it
The sixteen primary records from Chapter 24, with the template that covers each. Ownership is the field people get wrong: the owner is accountable for the record being true, not for typing it.
| Record | Owner | Created at | Template |
|---|---|---|---|
| Capability Record | Sponsor with Architect | T1 | Governance records |
| AI Use-Case Canvas | Business Sponsor | S1 | Intake |
| Initiative Qualification Record (TG0) | PMO with architecture input | T2 | Intake |
| Architecture Decision Record | Architect | S3 | Architecture |
| Reference Pattern Library entry | Architect | On proposal | Architecture |
| Data Lineage and Sensitivity Record | Data Owner | S4 | Architecture |
| Risk Classification Record | Risk Lead | S2 | Intake |
| Control Matrix | Risk Lead | S6 | Assurance |
| AI Assurance Summary | System Owner | S6 | Assurance |
| Agent Card | System Owner with Security | S3 | Agents |
| Deployment Authorization Record | System Owner or AI Governance Body | S7 | Assurance |
| AI Change Record | System Owner | S9 | Runtime |
| Architecture Exception | Requester | Any point | Governance records |
| Benefit Record | Sponsor | T6 | Governance records |
| Drift/Alert Record | System-generated | On detection | Runtime |
| Regulatory Overlay Reference | Risk Lead | On adoption | Governance records |