Your AI governance framework and AI policies, written from your answers. Free.
Answer a forty-minute questionnaire about how your organisation uses AI. The moment you send, four governance documents are written for you, with your organisation, owners, tools, functions and jurisdictions in them, ready to download as editable Word files. No cost, no obligation.
What you walk away with
01
Four EU AI Act documents, written for youIncluded free
AI Governance Framework, Acceptable Use Policy, Vendor Due Diligence Checklist, Risk Assessment Template. Your organisation, owners, tools and jurisdictions written in.
02
Your readiness score and maturity level
Ten governance domains scored from your own answers, on screen beside the downloads.
03
Editable Word files, yours to keep
Each ends with a schedule showing which answer shaped which clause. Review, approve, publish.
Regulation (EU) 2024/1689 applies to anyone placing AI on the EU market, wherever they sit.
Risk-tiered obligations, an AI literacy duty for every deployer, and penalties up to €35M or 7% of global turnover. The Digital Omnibus, in force since 27 July 2026, moved the high-risk deadlines: December 2027 for stand-alone Annex III systems, August 2028 for AI embedded in regulated products.
1 Aug 2024
In force
2 Feb 2025
Prohibited practices and AI literacy duty apply
2 Aug 2025
General-purpose AI model obligations; governance and penalties
2 Dec 2027
High-risk obligations for Annex III systems (was 2 Aug 2026)
2 Aug 2028
High-risk AI in regulated products, Annex I (was 2 Aug 2027)
ExtraterritorialAI literacyRisk tiersGPAI
GDPR
02 / 02
Every AI system that touches personal data is a GDPR system first.
Lawful basis, purpose limitation, data minimisation, DPIAs for high-risk processing and Article 22 limits on automated decisions all apply to AI exactly as they did before. The AI Act adds to GDPR; it does not replace it, and the four documents are written for both.
Art. 35
DPIA where AI processing is likely high-risk
Art. 22
Rights around solely automated decisions
Art. 5
Minimisation and purpose limitation for training and prompts
DPIAAutomated decisionsData minimisationSpecial category data
General information, not legal advice. Dates move; the documents state the ones that apply to you at the time.
4
EU AI Act documents, written for you
€0
Nothing to pay, no obligation
Instant
Ready the moment you send
Reviewed by Fredrik Karlsson, Group COO & CISO, Opsio·Last reviewed
The documents
An AI governance framework, an AI policy and two templates. Written for your organisation, not a template with your logo.
The controlling framework, the rules for staff, the gate for vendors and the assessment for each use case. Together they are what a customer's procurement questionnaire or a regulator's first letter asks to see, and what the EU AI Act's literacy, deployer and risk-management duties assume exists.
[Organisation]v1.0
AI Governance Framework
Owner: [Executive AI owner]
1.Purpose and scope
2.AI governance model
3.Enterprise AI governance
4.AI risk, data and security
5.Appendices A–E
Written for you≈ 35 pages
01Word · editable · free
AI Governance Framework
The document everything else hangs off.
Who is accountable for AI, how a use case moves from idea to operation, how risk is classified, how information may be used, and which tools are approved.
EU AI Act hooks
Art. 4 AI literacy
Art. 26 deployer obligations
Art. 9 risk management
Inside
Principles and standards alignment (ISO/IEC 42001, 27001, 23894, NIST AI RMF)
Governance model, roles, committee, decision rights
Five-stage governance process and approved tools
Risk matrix, information-handling matrix, RACI
Approved AI Tools Register
Written in from your answers
Your organisation, owner and custodian on the cover and in Document Control
Your business functions in scope, your existing policies alongside it
Appendix E register seeded with the AI providers you declared
A schedule recording the governance position you declared
Every file ends with a schedule that lists the answer behind each tailored clause.
[Organisation]v1.0
AI Acceptable Use Policy
Owner: [Executive AI owner]
1.Core rules for AI use
2.Approved AI tools
3.Information handling
4.Prohibited AI uses
5.Quick decision guide
Written for you≈ 30 pages
02Word · editable · free
AI Acceptable Use Policy
The rules for everyone who uses AI at work.
Which tools, which accounts, what may and may not be entered, how outputs are verified, what is prohibited, how incidents are reported.
When due diligence is required, set from your procurement answer
Schedule 1 pre-lists every provider you declared as the first assessments to run
Your regulatory position in the legal section
Owner and custodian named
Every file ends with a schedule that lists the answer behind each tailored clause.
[Organisation]v1.0
AI Risk Assessment Template
Owner: [Executive AI owner]
1.Basic information
2.Personal data and privacy
3.EU AI Act mapping
4.Risk classification
5.Approval
Written for you≈ 40 pages
04Word · editable · free
AI Risk Assessment Template
One assessment per AI use case, mapped to the Act.
The structured record that decides whether a use case may proceed: purpose, data, privacy, agents, oversight, legal mapping, security, classification, controls, approval, review.
EU AI Act hooks
Art. 9 risk management
Art. 27 fundamental-rights impact
Annex III classification
Inside
When an assessment is required, governance process
A–B basic information and description
C–G information, privacy, agents, oversight
H–N legal, security, third party, classification, EU AI Act mapping
The first lines of the generated policy, word for word. Your organisation's name, the owner you named and your approved tools are written in where the brackets are.
[Your organisation] – AI Acceptable Use Standard
Version 1.0
Owner: [named from your answers]
Parent document: [Your organisation] AI Governance Framework
Review: annual, or on material legal, regulatory, technological or business change
Purpose
The purpose of this AI Acceptable Use Standard is to establish clear and practical requirements for the day-to-day use of AI by employees, contractors and other authorised users acting on behalf of [Your organisation].
The Standard is intended to enable responsible AI adoption without unnecessarily restricting legitimate business use.
Core rules for AI use
AI shall be used only where there is a legitimate business purpose. Users shall not introduce AI into a business process merely because an AI capability is available.
Users shall use only AI tools that have been approved by [Your organisation] for business use. The current Approved AI Tools Register is maintained as Appendix E to the AI Governance Framework.
Why now
AI arrived in most organisations before anyone governed it.
The EU AI Act does not ask whether you build AI. It asks how you use it, whose data it touches, which systems it can reach, and whether the people using it know the rules. Three things make that urgent.
Shadow AI is already in the building.
Personal ChatGPT accounts, browser extensions, AI features switched on inside SaaS you already pay for. Most organisations discover their real AI footprint when a customer, a regulator or an incident makes them look.
Covered by · AI Acceptable Use Policy · Approved AI Tools Register
The AI literacy duty already applies.
Since 2 February 2025 every organisation using AI in the EU must ensure its staff have sufficient AI literacy. That means a written policy people have been trained on, not an all-hands slide.
Covered by · AI Acceptable Use Policy · AI Governance Framework
Agents turn a chat into an action.
An AI with access to email, tickets, cloud consoles or production data can act without anyone approving it. If nobody can say who can stop it, restrict it or reverse it, that is the first gap to close.
Covered by · AI Risk Assessment Template · AI Acceptable Use Policy
In plain words
AI governance, answered.
What is an AI governance framework?
An AI governance framework is the controlling document for how an organisation uses AI. It names who is accountable, sets how a new AI use case is assessed, classified and approved, defines which information may be used and which tools are approved, and is where an EU AI Act deployer shows how it meets its AI literacy and risk duties.
What should an AI acceptable use policy include?
An AI acceptable use policy tells staff which AI tools and accounts they may use, what they must never enter, such as personal data, customer confidential information or credentials, how to check AI output before relying on it, which uses are prohibited, and how to report an AI incident. It is also how most organisations evidence the EU AI Act's Article 4 literacy duty.
What does the EU AI Act require of organisations that use AI today?
Since 2 February 2025 every organisation using AI in the EU must ensure its staff have sufficient AI literacy (Article 4) and must not use prohibited AI practices (Article 5). General-purpose AI obligations and penalties have applied since 2 August 2025. After the Digital Omnibus, deployer duties for high-risk Annex III systems apply from 2 December 2027.
What is an AI readiness assessment?
An AI readiness assessment measures how far an organisation's governance of AI has come: ownership, policies, risk process, privacy, security, vendors and agents. Opsio's free assessment scores ten domains on a five-level maturity scale from your answers and writes the four governance documents those answers call for.
The EU AI Act
Written for the duties that already apply.
Regulation (EU) 2024/1689 applies to anyone placing AI on the EU market or using its output in the EU, wherever they are established. Its prohibitions and its AI literacy duty have applied since February 2025; the general-purpose AI and governance provisions since August 2025. The high-risk timetable was moved by the Digital Omnibus to December 2027 and August 2028.
The four documents are written against those duties, and against GDPR wherever personal data is involved, because every AI system that touches personal data is a GDPR system first.
The documents are an initial draft prepared from your self-assessment. They are not a legal opinion, a certification, a security audit or a DPIA, and each one says so. What they give you is the written governance the Act assumes exists, in your organisation's name, ready for review.
EU AI Act timeline: what applies whenSource: Regulation (EU) 2024/1689 on EUR-Lex, as amended by the Digital Omnibus (in force 27 July 2026). Last checked 7 October 2026.
Date
What applies
1 Aug 2024
In force
2 Feb 2025
Prohibited practices and AI literacy duty apply
2 Aug 2025
General-purpose AI model obligations; governance and penalties
2 Dec 2027
High-risk obligations for Annex III systems (was 2 Aug 2026)
2 Aug 2028
High-risk AI in regulated products, Annex I (was 2 Aug 2027)
How it works
The AI readiness assessment: forty minutes of answers. Four documents, instantly.
Step 01About forty minutes, on its own page
Answer the questionnaire
Fourteen steps covering how your organisation actually uses AI: tools, data, people, vendors, agents. Saved as you go, with a private link so Legal, IT, Privacy and HR can each answer their part.
Step 02The moment you send
Four documents are written from your answers
The AI Governance Framework, Acceptable Use Policy, Vendor Due Diligence Checklist and Risk Assessment Template are generated with your organisation, owners, tools, functions and jurisdictions written in, and your readiness score across ten domains appears beside them.
Step 03Editable Word files, yours to keep
Download, review, adopt
Each document ends with a schedule showing which answer shaped which clause. Take them through your normal approval and publish. An Opsio consultant reviews your answers and offers a walkthrough call if you want one.
Opens the questionnaire on its own page. Saved as you go.
What is assessed
Ten domains. One score.
Each domain is scored on its own checks and tells the documents what to write. A domain that does not apply to you, because you have no agents or no AI in HR, is left out of the score, and the matching section is marked out of scope rather than written as if it applied.
Domain 01 of 10
AI governance
Ownership, committee, roles, register, strategy, periodic review and change control.
Documents you receive for this domain
AI Governance Framework
What the assessment checks
Governance framework
Designated owner and RACI
AI register
Review and change triggers
Domain 02 of 10
Acceptable use
What employees may put into which tools, personal accounts, output verification and shadow AI.
Documents you receive for this domain
AI Acceptable Use Policy
AI Governance Framework
What the assessment checks
Acceptable use policy
Approved tools
Personal account rules
Output verification
Domain 03 of 10
Risk management
Whether AI is assessed and classified before it is switched on, and who approves it.
Documents you receive for this domain
AI Risk Assessment Template
AI Governance Framework
What the assessment checks
Risk methodology
Risk classification
Approval process
Monitoring and continuity
Domain 04 of 10
Privacy
Personal and special-category data in AI, DPIAs, automated decisions and transparency.
Documents you receive for this domain
AI Risk Assessment Template
AI Acceptable Use Policy
What the assessment checks
DPIA process
Automated decision-making
Minimisation controls
Privacy notices
Domain 05 of 10
Information security
The controls between AI systems and your data, and whether AI-specific threats are on the list.
Documents you receive for this domain
AI Governance Framework
AI Acceptable Use Policy
What the assessment checks
Security baseline
AI threat assessment
Access and logging
Data-loss prevention
Domain 06 of 10
Third-party AI
Vendor due diligence, contracts, inventories, training-on-your-data clauses and exit.
Documents you receive for this domain
AI Vendor Due Diligence Checklist
What the assessment checks
Vendor due diligence
Procurement gate
Contract clauses
Vendor inventory
Domain 07 of 10
Engineering & development
AI-assisted coding, internal model development, testing, deployment and drift.
Documents you receive for this domain
AI Acceptable Use Policy
AI Risk Assessment Template
What the assessment checks
Development standard
Coding policy
Testing and validation
Deployment controls
Domain 08 of 10
HR
AI in recruitment, performance, monitoring and employment decisions, with human review.
Documents you receive for this domain
AI Acceptable Use Policy
AI Risk Assessment Template
What the assessment checks
Employee AI policy
Recruitment rules
Monitoring requirements
Human review
Domain 09 of 10
Customer & product AI
AI in what you sell: terms, disclosure, approval, contractual clauses and product governance.
Documents you receive for this domain
AI Vendor Due Diligence Checklist
AI Acceptable Use Policy
What the assessment checks
Customer AI terms
Disclosure
Contract clauses
Product governance
Domain 10 of 10
AI agents & automation
Agents with system access: permissions, human approval, logging, production limits, kill-switch.
Documents you receive for this domain
AI Acceptable Use Policy
AI Risk Assessment Template
What the assessment checks
Agent standard
Access controls
Human approval
Emergency shutdown
The scale
Five levels, from informal to measured and improved.
The questionnaire asks where you would put yourself. The score says where the answers put you. Most organisations using AI today sit at Level 1 or 2. The four documents are what takes an organisation to Level 3 on paper.
Level 1
Initial
AI is being used, but governance is largely informal.
Level 2
Developing
Some AI policies, controls or assessments exist, but governance is not consistent across the organisation.
Level 3
Defined
AI governance responsibilities, policies and risk processes are formally established.
Level 4
Managed
AI governance is integrated with privacy, security, procurement, risk and technology processes.
Level 5
Mature
AI governance is continuously monitored, measured and improved, and integrated into the broader risk and technology management framework.
Yes. The questionnaire, the readiness score and the four documents are free, with no card and no obligation. Opsio offers this because organisations that adopt the documents often want help implementing the controls behind them, and that is a separate, quoted engagement you are free to decline. The documents are yours either way.
Each document is written from your answers the moment you send: your organisation's name throughout, the executive owner and governance lead you named, your jurisdictions and the frameworks that apply, your business functions, the AI providers and use cases you declared, the personal-accounts rule you chose, and sections kept or marked out of scope depending on whether you use AI in HR, in development, in customer-facing services or as agents. A schedule at the end of each file lists every answer that shaped a clause, so nothing is hidden.
Editable Word documents, individually or as one zip. Change any clause, rebrand them, put them through your own approval. Nothing to license.
The four documents are written for the EU AI Act: the AI literacy duty, prohibited practices, deployer and provider responsibilities, risk management and the Annex III classification. Because every AI system that touches personal data is a GDPR system first, the privacy sections are written for GDPR too.
Most organisations adopt the Framework and the Acceptable Use Policy with light edits and use the two templates as they stand. Owner and custodian are already named from your answers. Where a clause depends on an answer you marked 'unknown', the schedule says so; fix that before approval.
No. The documents are an initial draft prepared from a self-assessment. They do not constitute a legal opinion, a regulatory compliance certification, a security audit or a privacy impact assessment, and each one says so. Review them with your legal, privacy and information-security functions before adoption.
About forty minutes if one person has the answers, spread across fourteen steps. It usually takes longer in calendar time because several functions contribute. That is what the save-and-share link is for.
The Opsio consultants who review assessments, and nobody else. Submissions are stored as confidential customer information, are not shared with third parties and are not used for marketing. Documents you attach can be provided under NDA instead.
Get your EU AI Act documents written. Free.
AI Governance Framework, AI Acceptable Use Policy, AI Vendor Due Diligence Checklist, AI Risk Assessment Template. Forty minutes of answers, four Word files you own, whether or not we ever work together afterwards.