Everything above can be run by a firm with no risk department and no GRC budget; that is the point. The checklist is the whole programme: tick off what you already have, and the gaps are your to-do list. The pack below explains each item and marks it clearly: four items you fill in inside the pack itself, four you set up in your own systems with a status box in the pack to track each. The policy, for instance, is its own two-to-three-page document you write; the pack carries its outline and your progress notes, and the companion policy guide walks you through the writing.

The reasoning behind every item (which regulatory hook demands it, and what proportionate looks like) is in the AI governance series: the UK guide maps each control to Consumer Duty, SM&CR, UK GDPR, SYSC and record-keeping; the jurisdiction guides do the same for the EU, US, UAE & DIFC, Singapore, Hong Kong and Australia.

Two habits make the pack real rather than shelf-ware. First, the register is the gate: new tools go on it before they are used, not after; that single discipline prevents most shadow-AI problems. Second, the monitoring record is your evidence: a simple log of sampled reviews, findings and fixes is what turns “we have controls” into something you can demonstrate.

This page and the template are for informational purposes only and do not constitute regulated financial advice, legal advice, or a compliance opinion. Adapt the pack with a qualified compliance professional.