Templates

    Working documents, not blank forms.

    Registers, statements of applicability and assessment forms, each with a short note on how to fill it in and what an auditor will look for inside it.

    Pillar
    Track
    Framework

    16 of 16

    AI system register

    A three-sheet register: every AI system with its two roles and its owner, one impact assessment per system, and the Annex A statement of applicability.

    Compliance5 Sept 20263 min read

    AI governance

    AI use-case triage form

    A twenty-two column form that runs the AI Act decision test over one AI use case per row and closes each row with proceed, conditions or stop.

    Compliance5 Sept 20263 min read

    AI governance

    Control catalogue

    A sixteen-column register of the controls that actually run: owner, evidence producer, approver, reference controls served, evidence record and last test.

    Governance5 Sept 20263 min read

    Control test workpaper

    A twenty-one-column record of one control test: the population, its completeness check, the sample, the procedure, the evidence and a conclusion two roles sign.

    Compliance5 Sept 20263 min read

    CRA technical documentation index

    Four sheets that map the Annex VII file: one row per element per product, the declaration's Annex V items, and a retention schedule with derived end dates.

    Compliance5 Sept 20263 min read

    Product & OT

    Findings-to-closure tracker template

    A sixteen-column register that carries every external audit finding from the auditor's wording to a verification date, with correction and cause kept apart.

    Compliance5 Sept 20263 min read

    One-page risk picture

    A one-page board view of five to seven risks, each with an owner role, a position against appetite, a trend and the decision the body is asked to take.

    Governance5 Sept 20263 min read

    One-page security strategy

    One approvable page: five to seven security objectives, each tied to a business objective and a risk, with a measure, a baseline, a target and an owner role.

    Governance5 Sept 20263 min read

    Policy map

    A fourteen-column register of the policy set: tier, owner, approver, audience, the requirement that put each document there, and its next review date.

    Governance5 Sept 20263 min read

    Register of information starter

    A five-sheet starter that mirrors the standard templates for the register of information, so the function, arrangement and provider data is collected once.

    Compliance5 Sept 20263 min read

    BFSI

    Risk acceptance record

    A fifteen-column record for accepted risks, with the authority table that says who may accept each level and an expiry log that forces a re-decision.

    Risk5 Sept 20263 min read

    Risk criteria and appetite statement

    Appetite per risk category, anchored consequence and likelihood scales, and a published lookup that says which level is accepted, treated or escalated.

    Risk5 Sept 20263 min read

    Scenario library

    The maintained set of risk scenarios a committee can decide on: sources with a desired end state, consequence and likelihood with a basis, and an owner per row.

    Risk5 Sept 20263 min read

    Third-party tiering

    A four-sheet workbook that scores suppliers on five closed-option factors, bands the scores into three tiers, and sets the depth of assurance each earns.

    Risk5 Sept 20263 min read

    BFSI

    Vulnerability handling record

    Four sheets for Annex I Part II: an SBOM index by product version, a disclosure log, an update log, and a reporting clock with the two Article 14 anchors.

    Risk5 Sept 20263 min read

    Product & OT

    Risk register template

    A sixteen-column information security risk register with anchored 1-5 scales, a published combination rule and two mandatory decisions on every row.

    Risk3 Sept 20263 min read