Templates
This folder contains reusable templates for applying and extending the AI Control Architecture.
The templates are grouped into three categories:
- Core operational templates
- Advanced control templates
- Authoring templates
Use the core templates first. Use the advanced templates when deeper control design is required. Use the authoring templates when contributing new pillars, requirements, or risk scenarios to the architecture.
1. Core Operational Templates
Core operational templates are used to assess, approve, evidence, and manage AI use cases.
These are the primary templates most organizations should start with.
2. Advanced Control Templates
Advanced control templates are used when a use case requires deeper design, evidence, or assurance for a specific control area.
These templates are optional, but useful for higher-risk AI, agentic AI, vendor AI, regulated AI, customer-facing AI, or AI with sensitive data or action capability.
3. Authoring Templates
Authoring templates are used by contributors who want to extend the AI Control Architecture itself.
Use these when adding new architecture content to the repository.
Recommended Use Sequence
For most AI use cases, use the templates in this order:
1. ai-use-case-intake-template.md
2. ai-risk-assessment-template.md
3. ai-control-assessment-template.md
4. ai-architecture-decision-record-template.md
5. ai-assurance-test-plan-template.md
6. ai-control-evidence-package-template.md
If the AI use case involves a vendor, add:
ai-vendor-assessment-template.md
If the AI use case involves an exception, add:
ai-exception-record-template.md
If the AI use case involves an incident, add:
ai-incident-record-template.md
If the AI use case involves agentic AI or action capability, add:
ai-agent-control-template.md
ai-tool-and-action-control-template.md
ai-incident-containment-recovery-template.md
If the AI use case involves sensitive data, retrieval, RAG, or vendor processing, add:
ai-data-boundary-template.md
ai-prompt-and-input-control-template.md
ai-monitoring-logging-evidence-template.md
If the AI use case influences decisions or records, add:
ai-output-and-decision-control-template.md
ai-human-accountability-template.md
Minimum Template Set
For a lightweight implementation, start with only these:
ai-use-case-intake-template.md
ai-risk-assessment-template.md
ai-control-assessment-template.md
ai-assurance-test-plan-template.md
ai-exception-record-template.md
ai-incident-record-template.md
ai-vendor-assessment-template.md
This gives enough structure to register AI use cases, assess risk, review controls, test assurance, manage exceptions, respond to incidents, and review vendors.
Full Template Set
For a mature implementation, use the full template set.
The full set supports:
- AI inventory
- risk tiering
- requirements traceability
- architecture decisions
- control assessments
- vendor assessments
- data boundaries
- identity and access controls
- prompt and input controls
- output and decision controls
- tool and action controls
- agent controls
- human accountability
- monitoring and evidence
- incident containment and recovery
- assurance testing
- exceptions
- evidence packages
- maturity assessment
- authoring new architecture content
Template Usage Principles
When using these templates:
- Keep responses plain and practical.
- Avoid vendor-specific assumptions unless documenting a vendor assessment.
- Map every high-risk use case to clear ownership.
- Map every risk tier to required controls.
- Map every required control to evidence.
- Test controls before trusting them.
- Retain enough evidence to reconstruct important AI activity.
- Treat exceptions as temporary and owned.
- Treat incidents as opportunities to improve the architecture.
- Keep the architecture reusable, vendor-neutral, and brownfield-compatible.
Contribution Guidance
When contributing a new template:
- Use clear headings.
- Keep language vendor-neutral.
- Make requirements testable.
- Include evidence expectations.
- Include ownership fields.
- Include approval fields where risk decisions are involved.
- Include review triggers.
- Avoid product-specific configuration unless the template is explicitly vendor-specific.
- Keep the structure consistent with existing templates.
Summary
The templates are designed to turn the AI Control Architecture from a reference model into something that can be applied.
Use the core templates to start.
Use the advanced templates when risk, complexity, autonomy, vendor dependency, data sensitivity, or assurance needs increase.
Use the authoring templates to extend the architecture in a consistent way.