Seven working templates from the book — the framework crosswalk matrix, governance charter, risk-tiering worksheet, 90-day stand-up checklist, AI incident response playbook, board-ready one-pager, and vendor/AI-BOM question bank. Free. Maintained as the frameworks change.
A printed appendix ages. This toolkit doesn’t. These are the working instruments behind The Defensible AI Program by Dr. Derek A. Smith (VUST Foundation Publishing) — built for the leaders standing up, running, and defending AI governance programs in federal agencies and regulated enterprises. Enter your email and put them to work Monday morning.
28 unified controls mapped across NIST AI RMF, ISO/IEC 42001, the EU AI Act, and OMB M-25-21, with tier applicability and the evidence artifact for every control.
All nine elements, including the emergency-decision provision most charters omit.
The five-factor assessment, with a completed example at audit-grade specificity.
Dependency-ordered, four parallel tracks, honest about what is not done at day 90.
The five AI incident categories, detection signals, roles, and notification clocks.
The three questions every board actually asks, answered on one page.
Due-diligence questions with red flags, the seven AI-BOM categories, and the contract-provisions checklist.
Current release: August 2026 — citing OMB M-25-21 and the EU AI Act final text. Frameworks change; this toolkit is updated when they do.