A complete system for managing AI risk
What’s included
The pack is organised in a deliberate sequence so that each component builds on the last. It begins with the executive foreword, which sets context and clarifies where responsibility sits. From there, the usage guide explains how the framework should be applied across an organisation, followed by a clear leadership responsibility statement that anchors accountability.
The full 10 pillar framework provides the structure, supported by the threat map assessment tool which introduces scoring and prioritisation. Case studies show how risk develops in practice and how it can be managed, while AI usage prompts and reflection prompts support day-to-day application and decision validation.
How it is used
In practice, the toolkit follows a clear progression.
Leadership establishes a shared understanding of AI use and risk. The organisation then assesses how AI is currently being used, identifies where exposure exists, and applies controls where needed. From there, the framework becomes part of ongoing decision making, not a one-off exercise.
This creates visibility. It makes AI use something that can be understood, discussed and governed.
Why this works
Most AI policies fail because they do not influence behaviour. They sit as documents rather than operating systems.
This approach is different. It focuses on how people actually interact with AI, particularly under pressure, where shortcuts are most likely and oversight is weakest.
By structuring that interaction, it prevents small issues from compounding into larger problems.
The AI Policy Toolkit
- Executive foreword and context
- Step-by-step usage guide
- Leadership responsibility framework
- Full 10 pillar breakdown
- Case study and threat mapping examples
- Practical AI usage prompts
- Reflection tools for ongoing use
Each component builds on the next, guiding you from understanding through to implementation.