AI Compliance Kit · version 1.1 · 22 September 2026

The documents an inspector actually asks for

Written for companies with 20 to 500 staff that use AI tools and sometimes build them. Every document maps to a specific obligation, says what evidence it produces, and is ready to fill in. Not a guide. Not a platform. Files you own.

Buy single licence, USD 149 Read the free sample

What is inside

DocumentFormatMeetsEvidence it produces
00 How to use this kitDOCX, MDOrder of work, 5-step quick start, update policy
01 AI Governance PolicyDOCX, MDAccountability expected by every regime; Polish inspection scopeNamed roles, approval process, review cycle
02 AI Acceptable Use Policy with acknowledgment formDOCX, MDArticle 4 written rules; Texas banned uses; data leakage controlSigned acknowledgments, approved-tools table
03 AI System InventoryXLSX (27 columns, dropdowns, definitions) + specRegister expected in Poland; basis for Article 50 and Annex IIIThe inventory itself
04 Risk Classification ProcedureDOCX, MDProhibited / high-risk / Article 50 / minimal; Korea high-impact; Colorado, California overlaysClassification record per system
05 Transparency Checklist and Disclosure TextsXLSX (21 checks) + 9 textsArticle 50(1)–(5) and (7); 2 Dec 2026 marking; Korea; Utah; ColoradoCompleted checklist, texts in place
06 AI Literacy Programme with 15-question quizDOCX + XLSX registerArticle 4Training register, programme, validation results
07 Vendor Due-Diligence QuestionnaireXLSX (37 questions, weighted scoring)Vendor commitments expected in Poland; Article 50 support; incident noticeScored questionnaire per vendor
08 AI Incident Response ProcedureDOCX, MDIncident procedure expected in Poland; Korea; GDPR interplayIncident log, post-incident reviews
09 AI Impact Assessment TemplateDOCX, MDKorea high-impact assessment; preparation for Annex III (Dec 2027)Signed assessment per rights-affecting system
10 Inspection Readiness ProtocolDOCX, MDKRiBSI 7-day-notice inspections; any regulatorNamed contact, document index, meeting log
11 Contract ClausesDOCX, MDRole allocation, transparency support, audit rights, incident noticeUpdated vendor and customer contracts
12 Jurisdiction MappingXLSX (32 obligation rows)EU, Poland, Korea, Texas, California, Colorado, Utah, New York"Applies to us / our status" per obligation
13 90-Day RoadmapDOCX, MDWeek-by-week plan with owners and milestones
14 ISO/IEC 42001 MappingXLSX (38 Annex A controls + 12 clauses) + DOCXDraft Statement of Applicability for clause 6.1.3; gap list before a certification auditApplicability and justification per control
15 NIS2 MappingXLSX (Article 21(2)(a)–(j), Articles 20 and 23) + DOCXAI angle of the NIS2 risk-management and incident-reporting duties, for entities in scopeCoverage per measure, link from AI incidents to the 24h / 72h / one-month reports

40 files. Markdown sources included so you can keep them in git and diff every update. Version 1.1 adds the ISO/IEC 42001 and NIS2 mappings.

Pricing

Single licence

$149 one-time

$199 after the launch period

  • One company, unlimited internal users
  • All 16 documents and 7 spreadsheets
  • Quarterly updates for 12 months
  • Changelog with every update
Buy single licence

Advisor licence

$499 one-time

For consultancies, law firms and data protection officers

  • Use with up to 10 client companies
  • Everything in the single licence
  • Editable branding on all documents
  • Priority correction requests
Buy advisor licence

Prices in USD. VAT is added at checkout where it applies; the checkout provider is the merchant of record and issues the invoice, with reverse charge for VAT-registered EU businesses. 14-day refund if you have not downloaded the files.

Questions

Is this legal advice?

No. These are operational templates written from the legal texts and law-firm briefings cited on this site. Each document says so and marks the points where counsel should look. Thirty such points are flagged in version 1.0.

We are outside the EU. Is it still useful?

Yes if you have EU customers or users, and the kit covers Korea and the US states with their own rows in the mapping and their own disclosure texts. The inventory, policy, training and vendor documents are useful under any regime.

What do updates cover?

Changes in law and guidance: new dates, new obligations, corrected wording. Each update ships with a changelog. Updates are delivered through the same download link for 12 months.

How is this different from a €199 ISO 42001 kit?

Those kits document a management system. This kit produces the evidence for specific legal duties, across jurisdictions, and includes the ready-to-use disclosure texts, the scored vendor questionnaire and the inspection protocol. Document 14 maps every one of the 38 Annex A controls and the management-system clauses to the kit and marks honestly what is covered, partial or missing, so it doubles as a draft Statement of Applicability if you pursue certification.

Is the kit ISO 42001 or NIS2 certified?

No. Templates cannot be certified; organisations can. Documents 14 and 15 are our own mappings to ISO/IEC 42001 Annex A and to NIS2 Article 21, written from the standards' structure, and say so on every page. We are preparing our own operation for ISO/IEC 42001 certification and will publish the certificate when issued.

Can I see a document before buying?

Yes. Document 00 is published in full at /kit/sample/, and the free inventory template is a cut-down version of document 03.