Practical starting points for building AI safety governance into your organisation. Downloadable templates are in development; in the meantime, the frameworks below can be adapted directly.
AI risk register — core fields
A dedicated AI risk register should extend a standard risk register with fields specific to AI failure modes: model/system name and version, training data provenance and known limitations, oversight mechanism and named accountable owner, monitored accuracy-drift indicators (not just uptime), and a defined escalation path when human oversight identifies a problem.
Human oversight checklist
Before relying on an AI system in a safety-relevant decision, confirm: the overseeing person has documented training on this specific system's behaviour and limitations; they have real-time visibility into relevant system outputs; they have the practical time and authority to intervene before harm occurs; and there is a defined process for logging and reviewing every override.
AI incident investigation template — structure
An AI-related incident investigation should capture: a timeline reconstructed from preserved logs and the model version in effect at the time; the specific inputs and outputs involved; contributing factors across data, model, process and human oversight; and corrective actions with named owners and deadlines — the same rigour as any other safety investigation, applied to an AI-involved event.
Vendor AI safety questionnaire — starting questions
When procuring AI systems for safety-relevant use, ask vendors: what governance standards (e.g. ISO/IEC 42001) does the system's development process align with; what oversight and override mechanisms are built in; how is model drift monitored and by whom; and what evidence can they provide of independent testing.
These starting points reflect the competencies validated by our certification programmes. Full downloadable templates are planned for this section — let us know if there's a specific one you need first.
