AI Compliance Kit · version 1.1 · 22 September 2026
The documents an inspector actually asks for
Written for companies with 20 to 500 staff that use AI tools and sometimes build them. Every document maps to a specific obligation, says what evidence it produces, and is ready to fill in. Not a guide. Not a platform. Files you own.
What is inside
| Document | Format | Meets | Evidence it produces |
|---|---|---|---|
| 00 How to use this kit | DOCX, MD | — | Order of work, 5-step quick start, update policy |
| 01 AI Governance Policy | DOCX, MD | Accountability expected by every regime; Polish inspection scope | Named roles, approval process, review cycle |
| 02 AI Acceptable Use Policy with acknowledgment form | DOCX, MD | Article 4 written rules; Texas banned uses; data leakage control | Signed acknowledgments, approved-tools table |
| 03 AI System Inventory | XLSX (27 columns, dropdowns, definitions) + spec | Register expected in Poland; basis for Article 50 and Annex III | The inventory itself |
| 04 Risk Classification Procedure | DOCX, MD | Prohibited / high-risk / Article 50 / minimal; Korea high-impact; Colorado, California overlays | Classification record per system |
| 05 Transparency Checklist and Disclosure Texts | XLSX (21 checks) + 9 texts | Article 50(1)–(5) and (7); 2 Dec 2026 marking; Korea; Utah; Colorado | Completed checklist, texts in place |
| 06 AI Literacy Programme with 15-question quiz | DOCX + XLSX register | Article 4 | Training register, programme, validation results |
| 07 Vendor Due-Diligence Questionnaire | XLSX (37 questions, weighted scoring) | Vendor commitments expected in Poland; Article 50 support; incident notice | Scored questionnaire per vendor |
| 08 AI Incident Response Procedure | DOCX, MD | Incident procedure expected in Poland; Korea; GDPR interplay | Incident log, post-incident reviews |
| 09 AI Impact Assessment Template | DOCX, MD | Korea high-impact assessment; preparation for Annex III (Dec 2027) | Signed assessment per rights-affecting system |
| 10 Inspection Readiness Protocol | DOCX, MD | KRiBSI 7-day-notice inspections; any regulator | Named contact, document index, meeting log |
| 11 Contract Clauses | DOCX, MD | Role allocation, transparency support, audit rights, incident notice | Updated vendor and customer contracts |
| 12 Jurisdiction Mapping | XLSX (32 obligation rows) | EU, Poland, Korea, Texas, California, Colorado, Utah, New York | "Applies to us / our status" per obligation |
| 13 90-Day Roadmap | DOCX, MD | — | Week-by-week plan with owners and milestones |
| 14 ISO/IEC 42001 Mapping | XLSX (38 Annex A controls + 12 clauses) + DOCX | Draft Statement of Applicability for clause 6.1.3; gap list before a certification audit | Applicability and justification per control |
| 15 NIS2 Mapping | XLSX (Article 21(2)(a)–(j), Articles 20 and 23) + DOCX | AI angle of the NIS2 risk-management and incident-reporting duties, for entities in scope | Coverage per measure, link from AI incidents to the 24h / 72h / one-month reports |
40 files. Markdown sources included so you can keep them in git and diff every update. Version 1.1 adds the ISO/IEC 42001 and NIS2 mappings.
Pricing
Single licence
$199 after the launch period
- One company, unlimited internal users
- All 16 documents and 7 spreadsheets
- Quarterly updates for 12 months
- Changelog with every update
Advisor licence
For consultancies, law firms and data protection officers
- Use with up to 10 client companies
- Everything in the single licence
- Editable branding on all documents
- Priority correction requests
Prices in USD. VAT is added at checkout where it applies; the checkout provider is the merchant of record and issues the invoice, with reverse charge for VAT-registered EU businesses. 14-day refund if you have not downloaded the files.
Questions
Is this legal advice?
No. These are operational templates written from the legal texts and law-firm briefings cited on this site. Each document says so and marks the points where counsel should look. Thirty such points are flagged in version 1.0.
We are outside the EU. Is it still useful?
Yes if you have EU customers or users, and the kit covers Korea and the US states with their own rows in the mapping and their own disclosure texts. The inventory, policy, training and vendor documents are useful under any regime.
What do updates cover?
Changes in law and guidance: new dates, new obligations, corrected wording. Each update ships with a changelog. Updates are delivered through the same download link for 12 months.
How is this different from a €199 ISO 42001 kit?
Those kits document a management system. This kit produces the evidence for specific legal duties, across jurisdictions, and includes the ready-to-use disclosure texts, the scored vendor questionnaire and the inspection protocol. Document 14 maps every one of the 38 Annex A controls and the management-system clauses to the kit and marks honestly what is covered, partial or missing, so it doubles as a draft Statement of Applicability if you pursue certification.
Is the kit ISO 42001 or NIS2 certified?
No. Templates cannot be certified; organisations can. Documents 14 and 15 are our own mappings to ISO/IEC 42001 Annex A and to NIS2 Article 21, written from the standards' structure, and say so on every page. We are preparing our own operation for ISO/IEC 42001 certification and will publish the certificate when issued.
Can I see a document before buying?
Yes. Document 00 is published in full at /kit/sample/, and the free inventory template is a cut-down version of document 03.