AI Governance
We Published Our AI Governance Templates. They Are Free.
Most companies get stuck between a $50,000 assessment and a blank page. So we put the AI governance templates we use on GitHub, free, grounded in NIST AI RMF and ISO 42001.
July 7, 2026 · 4 min read

Here is a gap I keep running into.
A mid-market company knows it needs AI governance. The board asked about it last quarter. Someone forwarded an article about the EU AI Act. Now there is a line on a roadmap that says "AI governance" and nobody is quite sure what goes underneath it.
So they go looking. What they find is two bad options. On one side, a Big Four assessment that costs $50,000 and takes three months to tell them what they mostly already suspected. On the other, a 200-page international standard written in language that assumes you already have a governance function to interpret it.
Neither of those helps a CFO who has to answer a board question in two weeks.
So we published what we actually use. Two AI governance templates, free, on GitHub, under a Creative Commons license. No sign-up. No email wall. No "book a demo to unlock the PDF." You click the link and you read them.
You can find both in the CarbeneAI AI Governance Toolkit.
The first template: a maturity self-assessment
Before you spend money on governance, you should know where the money needs to go. That is what the self-assessment is for.
Ten questions across six dimensions: data governance, model governance, human oversight, transparency, security, and continuous monitoring. Each question is scored zero to three. Five minutes gets you a total, a maturity band, and three concrete next steps for your weakest area.
It is not an audit. It is a directional read, the kind of thing you run in a leadership meeting so the conversation starts from evidence instead of opinion. Most teams find their score is uneven. They are strong in one dimension and exposed in another, and the exposure is usually the one nobody owns. That is the useful part. A low score is not a failure. It is a map.
The second template: a full governance framework
The assessment tells you where you stand. The framework template helps you build the program.
It is the real thing, not an outline. Governance structure and a committee roster. Six ethics principles. A four-tier risk classification that scales the rigor to the stakes, so a low-risk scheduling tool does not get governed like an autonomous decision system. An end-to-end AI lifecycle from proposal to retirement. Data governance, an AI-specific security threat model, a vendor evaluation scorecard, regulatory mapping, workforce readiness, and the metrics a board actually wants to see.
You search and replace one placeholder with your company name, delete the sections that do not apply, and you have a working draft instead of a blank page. It is sector-neutral, with the regulated-industry differences called out where they matter, whether you are in healthcare, financial services, public safety, or government.
Both documents are grounded in the NIST AI Risk Management Framework and ISO/IEC 42001. Not because standards are magic, but because when a regulator or an auditor or an acquirer asks what your governance is based on, "we grounded it in NIST AI RMF and ISO 42001" is a much better answer than "we wrote something."
Now the honest part
A template does not govern anything. People do.
The real work is not the document. It is deciding which of your AI use cases are high-stakes, who has the authority to pause a system that is drifting, and what your specific regulators and contracts actually require. The template gives you the structure. The judgment about how to fit it to your risk, your industry, and your operating reality is where the work lives.
That judgment is advisory work. If the templates get you most of the way on their own, good; if they show you a gap, that gap is what advisory work is built to close.
Why we give this away
I spent 33 years in environments where getting the governance wrong had real consequences. Thirteen in law enforcement, twenty in cybersecurity. The habit that comes out of that is simple: show your work.
Security through obscurity does not hold up, and neither does governance you cannot explain. Publishing the templates is the same discipline behind everything else we publish, including the open-source tools, just applied to governance instead of code. It is the same reason we open source the security and AI tools we build. These are not our product. They are how we show our work.
Take the templates. Use them. Fork them and make them better. Run the assessment, and if it comes back ugly in a couple of dimensions, that is information, not a sales trigger.
And if you want a working session to turn a low score into a 90-day plan, my door is open. But the templates never cost you a conversation.