← Back to Playbooks

Part 5 — Templates & Tools

The four artefacts that keep the framework running

Four working templates carry the framework. None of them is complex; the value is in keeping them current rather than in the format itself.

The templates

Tools

None of these four artefacts need dedicated software to start. For most SMB-sized rollouts:

Worked example

One filled-in row per artefact, so the fields aren’t abstract.

Risk register

ID Category Description L I Score Owner Mitigation Due Status
R-014 Data Customer records used for the pilot haven’t been checked for consent basis 3 4 12 Data owner (Sana) Run consent audit before build starts Oct 3 Open

RAID log

Same register entry, plus:

Pre-mortem checklist

“It’s twelve months from now and this failed — why?” → answer logged: “We never got sign-off on the data source, so the pilot stalled at week 3 waiting on legal.” → becomes risk R-014 above.

Stage-gate checklist (before funding Phase 2)

Business case validated ✓ · data readiness confirmed ✗ (blocked on R-014) · compliance mapping complete ✓ · change-management plan in place ✓ · rollback plan defined ✓. One open item is enough to hold the gate.

Ownership & cadence

Each artefact ties back to the RACI and review cadence set in Part 4.

Artefact Owner Updated Reviewed
Risk register Risk owner As risks are identified Every steering meeting (Part 4)
RAID log Project lead Weekly during build Monthly steering review
Pre-mortem checklist Sponsor + technical lead Once per stage gate, before kickoff At the stage gate itself
Stage-gate checklist Sponsor At each gate Gate decision meeting

A register updated only when someone remembers is the exact failure Part 2 warns against — “a register written once and filed is worse than no register at all.” The same discipline applies to all four artefacts here, not just the register.

Where these break down

How the five parts fit together

Part 1 named the seven categories that derail AI projects. Part 2 turned that into a scored, living register. Part 3 gave each category its own mitigation, not a generic one. Part 4 put three named people and a fixed cadence around the whole thing so it doesn’t stop running after week one. These four artefacts are where all of that lives day to day — the register is the one to build first, because everything else here either feeds it or reads from it. Build it, put it in front of the steering committee from Part 4, and the rest of the framework has somewhere to run.

It also connects outward: the governance register in the AI Governance Playbook Series is where the compliance side of the same risks lives, and the dashboard in Measure Value, Risk, Costs & KPIs is where you watch them after go-live.