Software platform or template — which do you actually need?

"AI governance tools" covers two very different products. Enterprise GRC platforms (the kind that show up in analyst reports) automate tracking and workflow across dozens or hundreds of AI systems, with a price tag to match. Templates and checklists cover the same underlying requirements — system inventories, risk classification, documentation, monitoring — as static, editable documents you own outright.

If your organization runs fewer than roughly 20 AI systems, a software platform is usually solving a problem you don't have yet. The toolkit below is organized the way a governance program is actually built: structure first, then risk classification, then the documents and monitoring that structure requires.

1. Governance structure & accountability

Who owns what — the foundation everything else depends on. See the full RACI framework this category maps to.

2. Risk classification & system registers

What you have, and how risky each system is under Annex III of the AI Act.

3. Policy documents

The written rules that make human oversight and access control real instead of aspirational.

4. Documentation for high-risk systems

Only relevant once a system lands in the high-risk category — but non-negotiable once it does.

6. Data foundations for AI governance

Article 10 of the AI Act runs through these — training data is a governance problem before it's a model problem.

7. Framework mapping & benchmarking

For teams juggling more than one standard at once, or deciding which to adopt first.

8. Training & culture

Article 4 of the AI Act requires AI literacy for staff — these cover that obligation directly.

9. Vendor & third-party AI risk

10. Bundles & starting points

If the nine categories above feel like too much at once, start here.

How to choose without getting stuck

Don't start with category 4, 5 or 7 — they only matter once categories 1 and 2 exist. The realistic order for a company starting from nothing: (1) governance structure, so someone owns the decision; (2) risk classification, so you know which systems need the heavier documentation; (3) the policy documents that structure requires; (4) documentation and monitoring, scoped to whatever category 2 actually flagged as high-risk. Most companies never need the full 40+ — they need the 8 to 12 that match their actual system inventory.

Where this fits: if you haven't mapped roles yet, start with the AI Governance Responsibilities RACI before picking tools from this list — it tells you who's supposed to be using each one.

Frequently asked questions

What's the difference between an AI governance tool and AI governance software?

Software platforms (GRC suites) automate tracking and workflow across dozens of systems and are usually priced for enterprises already running large AI portfolios. Templates and checklists cover the same underlying requirements — inventories, risk classification, documentation, monitoring — without a subscription, and are the more practical starting point for teams with fewer than 20 AI systems in production.

Do I need all of these tools at once?

No. Start with governance structure (who owns what) and a risk classification checklist — those two determine which of the remaining categories actually apply to your systems. A company with no high-risk AI systems can skip most of the documentation-for-high-risk-systems category entirely.

Are these templates enough to be AI Act compliant on their own?

They cover the documentation and process layer that regulators and auditors actually check, but compliance also depends on how you use them — a completed risk classification only counts if someone with real authority reviews and signs it. Treat these as the operational foundation, not a substitute for legal review of your specific situation.

Which tool should a company with zero AI governance start with?

The AI Act Starter Kit or the MVG Guide (Minimum Viable Governance) — both are built specifically for organizations with nothing structured yet, and sequence the rest of this toolkit for you instead of requiring you to figure out the order yourself.