The Practitioner Toolkit
Ten instruments, and the order you run them in.
Most AI governance frameworks tell you what good looks like. Almost none tell you what to do on Monday, in what order, or what will go wrong at step three. This is that — nine steps, ten instruments, and the predictable failure at each step with the move that avoids it.
The nine steps
The order is load-bearing through step five — each one supplies something the next needs, and skipping ahead is the most common way a programme ends up with instruments nobody uses. From step six the work runs continuously: you are no longer completing steps, you are keeping columns up.
- 01
Diagnose
Run the four questions on the governance picture your organisation is actually using. Whatever comes back marks where a column has stopped running.
The bump — The test gets run by the person who drew the picture.
- The Column Test
- 02
Assign
One named person per column, each with a launch-hold scope, a budget line and an escalation route. Then set who is allowed to decide what.
The bump — Owners named without authority. The map completes and nothing changes.
- Column Ownership Map
- Decision-Rights Register
- 03
Inventory
Every AI system and agent running, its owner, its vendor, its model version, and what it is permitted to touch. Start it here; it does not finish here. The last slice of any inventory comes out of enforcement, not out of an inventory project.
The bump — You capture what was procured. What is running is a longer list.
- AI & Agent Inventory and Registry
- 04
Staff the capability
Turn the twelve layer-by-column intersections into a competence requirement per seat, then make it something HR can hire and train against.
The bump — Everyone trained, nobody competent.
- Columns × Layers Competence Matrix
- AI-Literacy Syllabus
- 05
Pilot
One bounded use case with all three columns live on it. Bounded means specified before it runs: an allowlist of what it may settle alone, everything else halting by default, enforced where the model cannot reach it rather than written into a prompt. A governance trial that happens to involve technology.
The bump — The pilot is chosen to succeed, so it proves nothing.
- The Practitioner Playbook
- Acceptance Criteria
- 06
Run it
Two bodies, one rhythm, a named convener, and standing agenda items that carry a number so they cannot be marked “no update”.
The bump — The cadence gets absorbed into another committee and disappears.
- Governance Operating Model
- 07
Measure
Four numbers — one anchor signal per column, plus spend against value. Each one a triggered diagnostic, never a target.
The bump — The dashboard goes green and nobody samples the zero.
- Board Metric Cards
- 08
Scale
Widen deployment only where the columns held, at the pace the weakest column sets.
The bump — Scale follows the loudest function, not the readiest one.
- Maturity Model
- Transition Plan
- 09
Evidence
Show a regulator, an auditor or a customer that the above satisfies what applies to you. Compliance is the residue, not a separate workstream.
The bump — Evidence assembled after the fact, by the system it evidences.
- EU AI Act × NIST × ISO 42001 Crosswalk
What you get
Ten instruments, each answering one question a board has to answer anyway.
-
The Practitioner Playbook
The spineThe order you roll the rest of this out in, and at each step the failure that shows up first and the move that avoids it.
-
The Column Test
The diagnosticFour questions, as a worked instrument. Run it on whatever framework is on your table and see which columns are specified but unstaffed.
-
Columns × Layers Competence Matrix
The substrateTwelve intersections. Each one names the specific skill that seat needs and what breaks without it.
-
The Column Ownership Map
WorksheetOne named person, one cadence and one number per column — plus the question most ownership records skip: name one decision that owner actually made last quarter.
-
The AI & Agent Inventory
Worksheet + sheetEvery system and agent you run, its owner, its vendor, its model version, and what it is allowed to touch.
-
The Decision-Rights Register
WorksheetWhich decisions an agent may make alone, which need a human, and what evidence moves a decision up a tier or pulls it back down.
-
The AI-Literacy Syllabus
The specThe competence spec per seat, written so HR can hire and train against it.
-
The Governance Operating Model
WorksheetThe cadence, the two bodies that convene it, and the governance-before-scale rule that stops a deployment shipping ahead of the column meant to hold it.
-
The Board Metric Cards
Four cardsFour numbers, each a triggered diagnostic rather than a target. The AI Oversight Override Rate is the anchor.
-
The Verified Crosswalk
The receiptAll twelve intersections mapped to the EU AI Act, NIST AI RMF and ISO/IEC 42001, checked against the primary sources.
And the wrapper that makes it implementable
The layer that sits on top of the instruments, so you know what to do Monday rather than what to believe.
- Controls Catalog — 22 controls, one per layer × column intersection, each with the test that proves it.
- Maturity Model — Levels 0–4 per column — and a demotion trigger at every level, because a maturity model you cannot fall down is a ratchet.
- Transition Plan — Six waves from where you are to where the columns hold, with the three dependencies you cannot sequence around.
- Acceptance Criteria — What “done” means at each step, who signs it, and the false pass most often mistaken for completion.
- Cost & Latency Sheet — What each control costs to run and what it costs you in shipping speed, with the cheapest defensible version of each.
One purchase · no tiers · no per-seat licence
$1,500
Everything above, delivered as working files: worksheets, registers, metric cards, the playbook and the wrapper. Yours to run internally, across your own organisation, without a further licence.
Enquire about the toolkitDirect purchase opens later this year. For now the enquiry reaches me directly — which for something you are going to run against your own estate is the better first conversation anyway.
What this is not
- A compliance product. Compliance is what the governance column produces when it runs; it is not the thing you buy.
- A certification, an audit, or a substitute for legal advice on your own obligations.
- A software platform. These are instruments — worksheets, registers, metric cards and a playbook — that work against whatever stack you already run.
- A promise that your AI programme returns more money. It is about value that survives its first incident, and failure that has someone’s name on it.
Start without paying anything
The diagnostic that tells you whether you need any of this is free, and asks nothing of you.
The nine steps
The whole rollout path, published in full — every step, the failure that shows up first at each one, and which instrument does it properly. Free.
The Column Test
Four questions. Surfaces the columns that are named on a slide and unstaffed in reality. A minute, no email.
Columns Not Layers
The framework in full — the layers you build, and the columns that have to hold across all of them.
The AI Governance Game
Five governance situations, real director decisions, each choice scored against NIST, ISO 42001 and the EU AI Act.
Resources
Reference diagrams and one-page downloads built for board packs. Ungated, and built to circulate.
Running the instruments with your team in the room, against your own estate, instead of filling them in alone? That is advisory.