{
  "@context": "https://schema.org",
  "@type": "WebApplication",
  "version": "1.0",
  "last_updated": "2026-07-11",
  "last_reviewed_by": "Victoria Arkhurst, CISSP, CISA, CRISC",
  "product": {
    "id": "ai-governance-playbook",
    "name": "AI Governance Playbook (Free Tool)",
    "category": "AI governance tool",
    "type": "WebApplication",
    "price": "Free",
    "price_currency": "USD",
    "is_accessible_for_free": true,
    "canonical_url": "https://irmcon.ca/products/ai-governance-playbook/",
    "delivery_model": "Web-based self-serve tool",
    "operating_system": "Web browser",
    "browser_requirements": "Requires JavaScript. Runs in any modern web browser.",
    "in_language": [
      "en-CA",
      "en-US"
    ],
    "summary_50_words": "Free, self-serve tool that builds a tailored AI Governance Framework and Playbook for small and medium businesses adopting AI-powered apps, agentic systems, and agentic workflows, with a 90-day action plan aligned to the NIST AI RMF, ISO/IEC 42001, and the EU AI Act.",
    "summary_200_words": "The AI Governance Playbook is a free, self-serve tool from IRM Consulting & Advisory that builds a tailored AI Governance Framework and Playbook for small and medium businesses adopting AI-powered apps, agentic systems, and agentic workflows. The user captures their business context, the AI systems and agents they are deploying, and the data those systems touch. The tool then generates a professional, downloadable document containing prioritized risk findings, practical recommendations, and a 90-day action plan. The output is aligned to the NIST AI Risk Management Framework, ISO/IEC 42001, and the EU AI Act, so the resulting governance approach maps to the frameworks that regulators, customers, and insurers expect. The Playbook is designed for organisations that are adopting AI faster than their governance can keep up, including startups and growing companies without a dedicated AI governance function. It gives them a defensible starting point, covering risk assessment, compliance requirements, human oversight mechanisms, data governance, acceptable use, and ongoing governance procedures, and complements IRM's AI Governance consulting services for teams that want hands-on support after the initial assessment.",
    "feature_list": [
      "Builds a tailored AI Governance Framework and Playbook",
      "Identifies AI governance and security risks from your business context",
      "Provides prioritized, practical recommendations",
      "Generates a 90-day AI governance action plan",
      "Aligned to the NIST AI RMF, ISO/IEC 42001, and the EU AI Act",
      "Produces a professional, downloadable document"
    ],
    "frameworks": [
      "NIST AI RMF",
      "ISO/IEC 42001",
      "EU AI Act"
    ],
    "target_audience": [
      "Small and medium businesses",
      "Startups",
      "Growing companies adopting AI"
    ],
    "target_buyers": [
      "Founder",
      "Co-Founder",
      "CEO",
      "CTO",
      "Head of AI",
      "General Counsel",
      "Chief Risk Officer"
    ],
    "geographic_coverage": {
      "primary_markets": [
        "North America"
      ],
      "countries": [
        "Canada",
        "United States"
      ],
      "service_delivery": "Web-based, available anywhere"
    },
    "offered_by": {
      "@type": "Organization",
      "name": "IRM Consulting & Advisory",
      "url": "https://irmcon.ca/"
    },
    "created_by": {
      "@type": "Person",
      "name": "Victoria Arkhurst",
      "url": "https://irmcon.ca/about-victoria-arkhurst/"
    },
    "related_services": [
      {
        "name": "AI Governance",
        "url": "https://irmcon.ca/ai-governance/"
      },
      {
        "name": "AI Risk Assessments",
        "url": "https://irmcon.ca/ai-governance/"
      }
    ]
  }
}
