AIGRF™ is an AI governance framework in Excel that turns “we are using AI” into “we can trust, control and scale AI.” It is a fully interlinked, 18-tab model that scores an AI initiative across ten governance dimensions and applies six veto gates that stop a critical weakness being hidden by a strong average.
What the AI governance framework does
Most AI governance is a checklist completed after the technology is already live. This AI governance framework brings the decision forward. Answer 100 structured questions, attach the supporting evidence, and the model returns a consistent AI governance assessment — so leadership knows whether an initiative is ready to scale, needs remediation, or should not proceed.
MATURITY ENGINE
100 questions across 10 dimensions, scored 1–5 and weighted into a single governance maturity score.
VETO GATES
Six mandatory gates for privacy, compliance, security, ethics, accountability and risk monitoring. One failure overrides the score.
RISK HEATMAP
Critical, High, Medium or Low exposure for every dimension — built for the risk committee and board pack.
REMEDIATION PLAN
Priority gaps pre-populated from your scores, with recommended actions, owner, target date and status tracking.
What’s inside the AI governance Excel model
- Governance Dashboard — overall maturity score, dimension breakdown, veto status and the final recommendation, plus an Executive Governance Scorecard for board packs.
- 10 dimension tabs (G01–G10) — ten questions each, with dropdown scoring, a confidence rating and a structured evidence layer: reference, owner, review date and strength.
- Veto Gates tab — five gates calculate automatically from dimension scores; the human-accountability gate links directly to the named-owner question in G10.
- Risk Heatmap — dimension-level exposure with a priority action for each.
- Remediation Plan — an auto-prioritised action register you can assign and track.
- Standards Crosswalk — each dimension mapped to the NIST AI RMF, ISO/IEC 42001 and the EU AI Act, as an alignment guide rather than a compliance certificate.
- User Guide & Results Guide — built in, so any risk or compliance professional can run and interpret the AI governance framework without training.
The 10 dimensions of the AI governance framework
Each dimension carries a weight reflecting its governance impact. Weights are adjustable on the Home tab, with a live check that they total 100%. The ethics, bias and explainability dimensions together form a practical responsible AI framework inside the model.
0112%
Governance Structure
Ownership, roles, approval authority and escalation.
0214%
Regulatory & Compliance
Laws, regulations, internal policy and AI standards.
0312%
Data Privacy & Protection
DPIA, consent, retention and data safeguards.
0410%
Ethics & Responsible AI
Principles embedded in design and deployment.
0510%
Bias & Fairness
Testing, mitigation and ongoing monitoring.
068%
Explainability & Transparency
Outputs that can be explained, reviewed and challenged.
0712%
Cybersecurity & Model Security
Access control, adversarial attack and model integrity.
088%
Third-Party & Vendor Risk
Due diligence, contracts and vendor oversight.
098%
Monitoring & Auditability
Performance monitoring, audit trails and incidents.
106%
Human Oversight & Accountability
Human-in-the-loop controls and named accountability.
Four AI governance decisions
If any veto gate triggers, the result is High Risk regardless of the score. If every gate clears, the weighted maturity score sets the decision.
≥ 80%
Govern & Scale
Mature governance. Proceed to scale with confidence and advance to AIAF™ (Stage 5).
65–79%
Conditional
Address the flagged dimension gaps before scaling, then re-assess.
50–64%
Remediate
Significant gaps. Strengthen controls before any wider deployment.
< 50%
High Risk
Governance is insufficient. Do not scale under current conditions.
Who the AI governance framework is for
Chief Risk Officers, compliance leads, CISOs, data protection officers, CIOs, legal teams and AI programme owners who are accountable for AI risk — and the consultants and advisory firms who assess it for clients. Use it as an AI risk assessment template you can repeat across every initiative, and show a board or regulator one evidence-backed scorecard.
From financial case to governed decision
This AI governance framework is Stage 4 of the AIDEX™ suite. It follows AIBCF™ once an initiative is financially justified, and a Govern & Scale result advances it to AIAF™ for AI agent readiness.
Part of the AIDEX™ suite: AIRDIF™ (readiness) → AIPIF™ (prioritisation) → AIBCF™ (business case) → AIGRF™ (governance) → AIAF™ (agents). Want the background? read the full AIGRF™ overview.
AI governance framework Results Guide — how to read your output
Once your assessment is complete, the model produces four layers of output. Read them in this order.
1. The veto gates (pass / fail)
Check the Veto Gates tab before any score. A triggered gate stops the initiative regardless of its maturity score — a high average behind a failed gate is not a governance clearance.
2. The maturity score and decision band
The dashboard shows your overall weighted score and maps it to Govern & Scale, Conditional, Remediate or High Risk. Read the score and the band together.
3. The Risk Heatmap
Shows where risk is concentrated: Critical, High, Medium or Low exposure for each of the ten dimensions, with a priority action.
4. The Executive Governance Scorecard
Overall maturity, veto status, dimensions completed and the highest-risk areas on one screen — the page for the risk committee or board pack.
Tip: Assign an owner and target date to every Critical and High item on the Remediation Plan straight away — an AI governance framework only works when gaps have named owners. Governance gaps without named owners rarely get closed.
AI governance framework User Guide — how to run the assessment
The model is built so a risk, compliance or strategy professional can complete a full AI governance assessment without training. Work through the workbook left to right.
1
Start on the Lifecycle and Overview tabs
Confirm the initiative has cleared AIBCF™ before applying the AI governance framework. Review the model map and the colour convention: yellow cells are your inputs, everything else is calculated or linked.
2
Complete the Home tab
Enter the organisation and use-case details, then review the ten dimension weights. Adjust for your sector; the model checks that they total 100%.
3
Work through G01–G10
Score each question 1–5 from the dropdown, set your confidence, and complete the evidence fields. A dimension shows “incomplete” until all ten questions are answered.
4
Check the Veto Gates tab
Five gates calculate automatically and the human-accountability gate links to G10. The AI governance framework stops at any triggered gate, so resolve it before reading the dashboard.
5
Read the Governance Dashboard and Risk Heatmap
Review the weighted maturity score, the final recommendation and the dimension-level exposure. This is your board-ready output.
6
Assign remediation actions
Open the Remediation Plan, add an owner and target date to each priority gap, and update the status as work progresses.
Only enter data in yellow cells. The 18 tabs are fully interlinked, so every output updates the moment you change an input. Never overtype a calculated cell. See the Results Guide above for how to read the veto gates, maturity score and heatmap.
Standards alignment note: The Standards Crosswalk is an alignment aid only. This AI governance framework does not provide compliance certification or legal advice under the
NIST AI RMF,
ISO/IEC 42001 or the
EU AI Act.