Take Assessment

Enterprise AI Control

AI Governance & Risk Control Stack

Board-ready policies and tools for enterprise risk control of AI initiatives.

Get the Full Stack

AI Governance & Risk Control Stack: Complete Walkthrough

 

Features List

8

Governance Components

70+

Pages of Policies & Standards

3

Risk Frameworks Referenced

Why Finance Leaders Use This Bundle

Audit-Ready from Day One

Every document follows the Three Lines of Defense model. Your internal audit team can review these policies and find structured controls, escalation paths, and approval matrices already built in.

Risk Tiering That Scales

The Red, Amber, Green tiering system runs through all five policies and both AI tools. One consistent framework means less confusion as your AI portfolio grows from 5 use cases to 50.

Vendor Due Diligence, Sorted

The Third-Party Comfort Index (TCI) gives you a repeatable scoring method for evaluating AI vendors. No more ad-hoc assessments or inconsistent reviews across procurement teams.

No Blank Page Problem

You don't have to draft governance documents from scratch. Each policy includes version control, approval signatures, regulatory alignment tables, and role-based responsibility matrices.

AI Tools That Do the Work

Two CustomGPT blueprints turn static documents into interactive advisors. Score your GenAI risks automatically or get a personalized AI scaling roadmap based on your maturity assessment.

What's Inside This Kit

  • GenAI Governance Policy v3.0 (PDF, 15 pages)

    Master policy for responsible AI. Sets principles, governance structure, risk tiering, lifecycle gates, and incident response.

  • Model Risk Management Standards v3.0 (PDF, 14 pages)

    Detailed rules for model registration, validation, testing, change control, and ongoing monitoring of GenAI systems.

  • AI Data Classification Policy v4.0 (PDF, 14 pages)

    Data handling rules for AI systems. Covers classification levels, RAG governance, anonymization standards, and access controls.

  • Third-Party AI Vendor Due Diligence v2.0 (PDF, 14 pages)

    Assessment framework and scoring template for evaluating external AI vendors using the Third-Party Comfort Index (TCI).

  • GenAI Risk Scorecard Assistant (PDF, 7 pages)

    Design blueprint for building a ChatGPT-based risk scorer. Uses McKinsey's 5/3/1 framework to tier and control GenAI use cases.

  • AI Scaling Advisor (CFO Edition) (PDF, 4 pages)

    Design blueprint for a ChatGPT advisor that reads your AI Maturity Assessment results and builds a prioritized scaling roadmap.

  • AI Maturity Assessment Toolkit (Excel, 4 tabs)

    Self-assessment questionnaire based on the MIT CISR Enterprise AI Maturity Model. Scores five capability areas and assigns a maturity stage.

A Closer Look at Each Tool

GenAI Governance Policy v3.0 (AI Policy)

The master document in your governance stack. It defines the principles, governance structure, and accountability model for every AI initiative in your organization. All other documents in this bundle sit underneath it.

  • Three Lines of Defense model with clear GenAI-specific responsibilities
  • Risk tiering framework (Red, Amber, Green) with control escalation rules
  • Full lifecycle governance gates from ideation through decommission
  • Incident severity classification and response procedures

Best For- CROs, AI Risk Officers, and AI Oversight Committee members setting top-level policy.

Model Risk Management Standards v3.0 (Standards)

The operational rulebook for anyone registering, validating, testing, or monitoring GenAI models. Covers everything from mandatory registration fields to red-team testing protocols and quantitative performance thresholds.

  • Mandatory model registration with 12+ required fields per model
  • Pre-production validation requirements including prompt chain testing
  • Red-team testing protocols required for Amber and Red tier models
  • Quantitative performance thresholds (response consistency, hallucination rates)

Best For- AI Risk Officers, model owners, and MRM teams responsible for model governance.

AI Data Classification Policy v4.0 (AI Policy)

Defines how data should be classified, handled, and protected when used with AI systems. Goes beyond traditional data policies to address RAG knowledge bases, anonymization for AI training, and third-party data transmission rules

  • Four-level classification framework (Public, Internal, Confidential, Restricted)
  • RAG knowledge base governance with mandatory metadata fields
  • Approved anonymization techniques with validation requirements
  • Role-based access controls mapped to risk tiers

Best For- Data Protection Officers, Chief Privacy Officers, and teams managing AI data pipelines.

HITL Oversight Checklist v2.0 (Checklist)

A ready-to-use operational checklist for putting human review controls around GenAI outputs. Specifies what to review, who reviews it, how often, and what to do when something goes wrong.

  • Tiered review coverage: 100% for Red, 15% sampling for Amber, optional for Green
  • Golden questions for quality spot-checks of AI outputs
  • Escalation procedures with clear authority levels
  • 30-day periodic review cycle with sign-off requirements

Best For- Operations teams, model owners, and anyone deploying AI in customer-facing or financial workflows.

Third-Party AI Vendor Due Diligence v2.0 (Procedures + Template)

A structured 30-day assessment process for evaluating external AI vendors, complete with a fill-in scoring template. The Third-Party Comfort Index (TCI) gives you a repeatable, quantifiable score for every vendor.

  • Six-stage due diligence process from initiation to approval
  • TCI formula combining documentation, transparency, and regulatory alignment scores
  • Assessment depth scales by risk tier (Green, Amber, Red)Auto-generated Excel workbook with editable assumptions, ROI calculator, and Gantt-style roadmap
  • Automatic disqualifiers and approval authority matrix

Best For- Procurement teams, AI Risk Officers, and legal counsel evaluating AI vendors.

GenAI Risk Scorecard Assistant (CustomGPT Blueprint)

A design blueprint for building your own ChatGPT-powered risk scorer. Feed it a GenAI use case, and it calculates a weighted risk score using McKinsey's 5/3/1 framework, then recommends controls across four layers.

  • McKinsey 5/3/1 risk scoring with five weighted factors
  • Automated tier classification: Red (70+), Amber (40-69), Green (under 40)
  • Four-layer control mapping: business, procedural, manual, automated
  • Portfolio-level summary for multi-use-case governance

Best For- AI governance teams scoring new GenAI use cases before deployment.

AI Scaling Advisor (CFO Edition) (CustomGPT Blueprint)

A design blueprint for a ChatGPT advisor that interprets your completed AI Maturity Assessment. Upload your results, and it identifies gaps, maps them to the MIT CISR framework, and builds a 12-week action plan.

  • Reads and validates the AI Maturity Assessment Toolkit results directly
  • Maps gaps to MIT CISR dimensions with evidence-based recommendations
  • Generates a board-style one-pager and a 12-week prioritized action plan
  • Labels inferences vs. data-backed findings for transparency

Best For- CFOs and CIOs building an enterprise AI scaling roadmap.

AI Maturity Assessment Toolkit (Excel Model)

A self-assessment questionnaire based on the MIT CISR Enterprise AI Maturity Model. Rate your organization across five capability areas, and the toolkit calculates your maturity stage with detailed results and improvement areas.

  • Five capability areas: Strategy, Data, Skills, Use Cases, Technology
  • 1-5 rating scale with clear definitions for each level
  • Automatic maturity stage calculation with detailed results dashboard
  • Feeds directly into the AI Scaling Advisor CustomGPT for action planning

Best For- CFOs and senior leaders assessing organizational AI readiness.

How the Kit Works Together

Your Question / Need Start With Then Use Result
"We need a governance framework for our AI initiatives." GenAI Governance Policy MRM Standards + Data Classification Policy A three-tier policy hierarchy with principles at the top and operational standards underneath.
"How do we score and prioritize GenAI risk?" GenAI Risk Scorecard Assistant (CustomGPT) HITL Checklist Every use case gets a quantified risk tier, then the right level of human oversight is applied.
"We're evaluating a new AI vendor." Third-Party Vendor Due Diligence Data Classification Policy A TCO score for the vendor plus clear data handling rules for whatever classification level applies.
"Where does our organization stand on AI maturity?" AI Maturity Assessment Toolkit (Excel) AI Scaling Advisor (CustomGPT) A maturity score across five dimensions plus a 12-week action plan to close the gaps.
"Our board wants to see our AI risk controls." GenAI Governance Policy GenAI Risk Scorecard Assistant + HITL Checklist A board-ready policy document supported by quantified risk scores and documented oversight procedures.
"We need to ensure AI outputs get proper human review." HITL Checklist MRM Standards (monitoring section) A complete human review workflow with quality standards, escalation paths, and ongoing monitoring.

Common Questions

Get Your AI Governance Framework in Place Today

8 components. 70+ pages. Updated for 2026. Everything you need to govern AI responsibly.

Get the Full Stack