FREE GOVERNANCE TEMPLATES

AI Agent Governance Templates

Copy-paste policies, checklists, and playbooks for enterprise AI agent governance. Mapped to SOC 2, ISO 27001, and NIST AI RMF. Free to use — no sign-up required.

18
Templates
7
Categories
3
Frameworks
MIT
License
Filter:
Agent Governance Policies 4 templates
SOC 2 ISO 27001 NIST
AI Agent Governance Policy
Master governance policy covering agent deployment approval, decision authority levels, monitoring requirements, and incident escalation procedures.
SOC 2 NIST
Agent Autonomy Levels Policy
Defines four autonomy tiers (supervised, semi-autonomous, autonomous, restricted) with decision thresholds, review requirements, and override procedures for each tier.
SOC 2 ISO 27001
Agent Data Access Policy
Governs what data agents may read, write, and retain. Includes PII handling rules, data minimisation requirements, and retention schedules for agent-generated outputs.
NIST
AI Agent Acceptable Use Policy
Defines permitted and prohibited use cases for AI agents across the organisation. Includes department-specific carve-outs and a rapid exception request process.
Audit Checklists 4 templates
SOC 2 ISO 27001 NIST
AI Agent Pre-Deployment Audit
27-point checklist for launching a new AI agent into production. Covers data access review, escalation path testing, confidence threshold validation, and rollback plan verification.
SOC 2 NIST
Quarterly Agent Governance Review
Structured quarterly review template covering override rate trends, INTERRUPT frequency by agent, decision drift indicators, and retraining trigger evaluation.
ISO 27001
ISMS Agent Integration Audit
ISO 27001 Annex A controls checklist for AI agent integration into information security management systems. Maps directly to control domains A.8, A.9, A.12.
NIST AI RMF
NIST AI RMF Readiness Assessment
Self-assessment checklist mapping Agent OS governance events to NIST AI RMF Core Functions: Govern, Map, Measure, Manage. Produces a readiness score across 4 dimensions.
INTERRUPT Escalation Policies 3 templates
SOC 2 NIST
INTERRUPT Escalation Matrix
Defines who receives INTERRUPT events by severity level (low/medium/high/critical), SLA for response, what happens on timeout, and how the outcome is documented.
SOC 2
Confidence Threshold Policy
Defines mandatory INTERRUPT thresholds by agent type and action category. Includes rationale for each threshold, override procedure for temporary adjustment, and review schedule.
NIST
Human-in-the-Loop Decision Authority
Role-based INTERRUPT response authority matrix. Maps decision types to minimum seniority level required to approve, deny, or redirect. Includes delegation procedures for OOO scenarios.
Override Review Processes 2 templates
SOC 2 NIST
Override Pattern Review Process
Weekly override analysis workflow — how to identify systematic patterns in OVERRIDE events, classify root causes (prompt/data/threshold/policy), and trigger retraining or policy updates.
ISO 27001 NIST
Critical Override Escalation Procedure
Immediate response procedure for severity:critical OVERRIDE events. Who is notified, what investigation is required within 24h, and how findings feed into the corrective action register.
Incident Response Playbooks 3 templates
SOC 2 ISO 27001 NIST
Agent Runaway Action Playbook
Step-by-step response to an agent taking unintended high-volume or high-impact actions (e.g. sending 10,000 emails, bulk-deleting records). Includes immediate containment, stakeholder notification, and post-incident review.
SOC 2 ISO 27001
Agent Data Exfiltration Response
Incident response for suspected unauthorised data access by an agent. Evidence preservation, access revocation sequence, breach notification assessment, and regulatory reporting checklist.
NIST
Agent Bias / Discrimination Incident
Response playbook for discovering systematic discriminatory outputs from an AI agent. Investigation methodology, stakeholder communication templates, and remediation documentation.
DEBRIEF Review Templates 1 template
SOC 2 NIST
DEBRIEF Review Agenda Template
Structured agenda for human review of agent DEBRIEF events. Guides reviewer through outcome assessment, edge case prioritisation, and decision on whether learned observations trigger policy updates.
Vendor & Procurement Assessment 1 template
SOC 2 ISO 27001 NIST
AI Vendor Governance Assessment
Security and governance questionnaire for evaluating AI agent vendors. 35 questions covering data handling, audit trail quality, override capabilities, SLA commitments, and incident response SLAs.

Use templates with the Agent OS platform

These templates are most powerful when your agents are already emitting governance events. Connect Agent OS in 5 minutes and start building your audit trail today.