A documented AI governance and responsible AI management system built around ISO/IEC 42001:2023 — from the governance charter and risk taxonomy through to a defensible AI Statement of Applicability.
Overview
AI governance is no longer a single-standard exercise. ISO/IEC 42001:2023 defines what an AI management system must be; ISO/IEC 23894:2023 sets the discipline of AI risk management; ISO/IEC 42005 establishes AI system impact assessment as a subject in its own right; ISO/IEC 38507:2022 separates the governing body's duties from management's; the NIST AI Risk Management Framework 1.0 and its 2024 Generative AI Profile supply the operating vocabulary regulators increasingly borrow; and Regulation (EU) 2024/1689 — the EU AI Act — turns much of that practice into enforceable duty for providers and deployers. Most organisations now answer to several of these at once, usually before anyone has formally been given the job.
The AGS AI Governance & Responsible AI Management System (AIGMS) is our flagship response: one internally consistent documentation stack covering that whole landscape. It is built around ISO/IEC 42001:2023 as the principal management-system reference and cross-referenced, document by document and control by control, to ISO/IEC 23894:2023, ISO/IEC 42005, ISO/IEC 38507:2022, ISO/IEC 22989:2022, the NIST AI RMF and Generative AI Profile, the OECD AI Principles, the UNESCO Recommendation on the Ethics of AI, the EU AI Act and ISO/IEC 27001:2022. Every mapping sits in a thirteen-column framework crosswalk, and every source carries a stated verification status in the reference matrix — so the alignment is traceable, not merely asserted.
What this system covers
The AIGMS documents the complete management cycle — establish, operate, audit, improve — in five working layers:
- Govern — the AI Governance Manual, a governance charter and a policy layer running from acceptable use and procurement to generative AI, transparency and human oversight.
- Operate — procedures with matched forms for every recurring decision: use-case approval, classification, risk and impact assessment, vendor due diligence, model change, agent authorisation and retirement.
- Record — a fifteen-register workbook (AI systems, use cases, risks, incidents, vendors, obligations, evidence and more), sixteen audit checklists and a KPI catalogue.
- Assure — a control library of 163 AGS-authored controls, internal audit and management review packs, and an AI Statement of Applicability.
- Embed — role-based training modules, an implementation roadmap and topic indexes that gather every artefact by discipline.
Coverage extends to the questions that arrive after the policies are written: generative AI use and risk, workforce tool approval, AI agent authorisation, shadow-AI discovery, model cards, fairness testing, human rights and sustainability impact, business continuity and fallback, and complaint handling with human review. Every document uses consistent square-bracket placeholders, follows a single numbering scheme and is listed in a master document register; the risk method rests on a 76-item AI risk taxonomy, and an evidence pack index ties each record back to the claim it supports.
Who it's for
The daily user is whoever holds the AI governance officer role, formally appointed or not yet. Around that role, the manual, policies and KPI catalogue serve executives and the governance committee; the assessment forms serve AI system owners; the checklists and control library serve internal auditors; and the obligation register and regulatory change procedure serve legal and compliance.
The system is sector-neutral and scales from an organisation whose entire AI footprint is a handful of SaaS tools — the most common case, and the one most often ungoverned — to a group building and deploying its own models. AGS also publishes a policy-layer AI governance package and a single-standard ISO/IEC 42001 toolkit, and both remain the right choice where the need is narrower. The AIGMS sits above them: the full-stack system for organisations that want the entire discipline — governance, risk, assurance and training — from one coherent source.
By document type
Key documents
Need the complete document list for this toolkit? Request it — sent the same day. Want to check the quality first? Preview free sample documents.
Everything you get
Every toolkit gives you a full set of working documents for your standard, ready to edit and use.
Native Microsoft files. Add your logo and adapt every document to how you work.
Your full toolkit arrives as a ZIP the moment payment clears.
One purchase covers everyone in your organisation. No per-seat fees.
Built by people who run real audits, so the content matches what assessors check.
One payment, perpetual licence for your organisation. No subscriptions, no renewals.
Full refund if your files are faulty, incomplete or not as described and we can't put it right
From purchase to audit-ready
Buy & download instantly
Pay securely by card. Your ZIP download link appears immediately on the confirmation page and in your email.
Edit & brand as your own
Open the native Word & Excel files, add your logo and details, and adapt everything to your organisation.
Implement & get audit-ready
Roll out the manuals, procedures, forms and checklists to build a working, certification-ready system.
Frequently asked questions
What exactly do I receive?
A downloadable ZIP containing the full set of ready-to-use documents for this toolkit — manuals, procedures, forms, records, checklists, guidance and training material, all in editable Word and Excel format. The exact document count is shown at the top of this page.
Are the documents really editable?
Yes. Every file is native Microsoft Word or Excel — no locked PDFs. Add your logo, change wording, and tailor the content to your organisation. The toolkit is yours to keep and reuse.
Does this certify my organisation?
No. These are documentation toolkits aligned to the relevant standard to help you prepare. Certification itself is issued by an accredited certification body after their audit. Our toolkits give you a strong, audit-ready starting point.
How is it delivered?
Instantly and digitally. There's no physical shipment — you download the files right after payment and receive a backup link by email.
Do I get updates?
Yes. If we revise this toolkit, you're entitled to the updated version at no extra cost — just contact us with your order details.
What is your refund policy?
These are digital products, so once a toolkit has been downloaded we cannot take it back. If you have not downloaded yet, contact us and we will cancel the order and refund you in full. We also refund in full if the files are damaged, incomplete, or not what the product page described.
Tell us which scheme you work to. We will point you to the right toolkit.
