AI governance

AI Governance Starter Kit

Cycore's starter kit for governing the AI you build or buy. Compare ISO/IEC 42001, NIST AI RMF, and the EU AI Act, check the current EU application dates, and triage your systems in the inventory at the end.

Download the PDF
PDF, 13 pages, no form

We built this starter kit for technology and health care teams that build or use AI and have a customer, an auditor, or a regulator asking how they govern it. It compares the three frameworks people mean when they say AI governance, tells you which ones apply, and ends with an inventory you can fill in this week.

What's inside

  • The three frameworks compared. ISO/IEC 42001:2023, NIST AI RMF, and the EU AI Act, with what each one asks of you.
  • Who the EU AI Act applies to. Providers, deployers, and the other roles in Article 2.
  • Which frameworks you need. Six questions with yes and no answers, and the combinations we'd start with.
  • EU AI Act risk tiers. Prohibited practices, high-risk systems, systems with transparency obligations, and five steps to classify your own.
  • The current EU AI Act schedule, as amended in 2026.
  • An AI policy outline in ten parts.
  • Five common mistakes.
  • Your inventory and next steps. Owners, triage, controls, and the systems that need legal review.

How to use it

Read the comparison and answer the six questions. Then fill in the inventory for every AI system you develop, deploy, or buy, including third-party tools with AI features. Give each system an owner, tag its risk tier, note which controls exist, and mark the ones that need legal review. If you already run a GRC platform, load the finished inventory into it. Download the PDF.

Download the PDF
Format
PDF, 13 pages
Last reviewed
September 23, 2026
Form
None

proof of work

Read the case study
AI governance

AI Governance Starter Kit

Cycore's starter kit for governing the AI you build or buy. Compare ISO/IEC 42001, NIST AI RMF, and the EU AI Act, check the current EU application dates, and triage your systems in the inventory at the end.

Download the PDF

We built this starter kit for technology and health care teams that build or use AI and have a customer, an auditor, or a regulator asking how they govern it. It compares the three frameworks people mean when they say AI governance, tells you which ones apply, and ends with an inventory you can fill in this week.

What's inside

  • The three frameworks compared. ISO/IEC 42001:2023, NIST AI RMF, and the EU AI Act, with what each one asks of you.
  • Who the EU AI Act applies to. Providers, deployers, and the other roles in Article 2.
  • Which frameworks you need. Six questions with yes and no answers, and the combinations we'd start with.
  • EU AI Act risk tiers. Prohibited practices, high-risk systems, systems with transparency obligations, and five steps to classify your own.
  • The current EU AI Act schedule, as amended in 2026.
  • An AI policy outline in ten parts.
  • Five common mistakes.
  • Your inventory and next steps. Owners, triage, controls, and the systems that need legal review.

How to use it

Read the comparison and answer the six questions. Then fill in the inventory for every AI system you develop, deploy, or buy, including third-party tools with AI features. Give each system an owner, tag its risk tier, note which controls exist, and mark the ones that need legal review. If you already run a GRC platform, load the finished inventory into it. Download the PDF.

ISO 42001 framework page

Read the case study

More Cycore resources

Next step

Talk to Cycore about your AI governance program

This checklist is a Cycore diagnostic organized around the AICPA Trust Services Criteria. It is not an AICPA checklist and it is not legal or audit advice. Your auditor determines examination scope, evidence, and conclusions. Completing every item does not guarantee readiness or a particular audit outcome.