Everything above can be run by a firm with no risk department and no GRC budget — that is the point. The checklist is the whole programme: tick off what you already have, and the gaps are your to-do list. The template below gives you each document as a fill-in-the-blanks page.

The reasoning behind every item — which regulatory hook demands it, and what proportionate looks like — is in the AI governance series: the UK guide maps each control to Consumer Duty, SM&CR, UK GDPR, SYSC and record-keeping; the jurisdiction guides do the same for the EU, US, UAE & DIFC, Singapore, Hong Kong and Australia.

Two habits make the pack real rather than shelf-ware. First, the register is the gate: new tools go on it before they are used, not after — that single discipline prevents most shadow-AI problems. Second, the monitoring record is your evidence: a simple log of sampled reviews, findings and fixes is what turns “we have controls” into something you can demonstrate.

This page and the template are for informational purposes only and do not constitute regulated financial advice, legal advice, or a compliance opinion. Adapt the pack with a qualified compliance professional.