Svenska Dokumentmallar
AI Governance Package 2026 – AI Act Compliance Word/PDF/Excel
AI Governance Package 2026 – AI Act Compliance Word/PDF/Excel
Downloading the template is available immediately after purchase. Our document templates are always delivered in customizable formats.
If you are unsure which template is appropriate or how you should complete it, please see the relevant information under the 'Legal Information' tab in our main menu.
Our templates are designed in accordance with current legislation and practice in each area to ensure that the documents you create are legally correct.
Couldn't load pickup availability
AI Governance & AI Act Compliance Package 2026
A complete document package for Swedish companies and organizations looking to implement structured, documented, and practical artificial intelligence governance. The package combines an AI policy, AI system register, risk assessment, supplier audit, impact assessment, and a governance and approval workflow into a cohesive methodology.
You receive six professionally designed templates in both Word and PDF, as well as a practical AI register in Excel with dropdowns, status, risk classification, AI Act role, DPIA/FRIA screening, and an overview. In total, the Word/PDF material spans 48 pages.
The templates were legally reviewed on September 27, 2026, and are based on the AI Act (EU) 2024/1689 in its consolidated version following Regulation (EU) 2026/1744 – Digital Omnibus on AI, alongside GDPR and current EU guidance.
What's included
1. AI Policy for Companies – Word + PDF
The complete 19-page AI policy contains practical rules for how employees may use AI, which tools are permitted, what information may be entered, and how the organization should manage human oversight, AI literacy, data protection, security, HR, copyright, transparency, and incidents.
The policy includes, among other things:
- a traffic light model for green, yellow, and red AI usage,
- prohibited and high-risk use cases,
- approval of new AI tools,
- GDPR, personal data, and trade secrets,
- information security, AI agents, API keys, and prompt injection,
- human oversight and fact-checking,
- Article 50 and AI-generated content,
- HR, recruitment, and other high-impact decisions,
- AI literacy according to Article 4,
- incident reporting, roles, and annual review.
2. AI System Register and Classification – Word + PDF + Excel
A ready-made structure for inventorying the organization's AI systems and use cases. The register helps the business document who owns a system, how it is used, what data it processes, what role the organization has under the AI Act, and what controls are required.
The register template covers, among other things:
- AI-ID, system, supplier, and version,
- business process and intended purpose,
- affected persons and data types,
- personal data and sensitive personal data,
- model training, storage, and third-country transfers,
- screening of Article 5, Article 6, and Annex I/III,
- screening of transparency requirements in Article 50,
- DPIA and FRIA screening,
- human oversight, incident owner, and approval,
- status: idea, pilot, approved, conditional, paused, or decommissioned.
The Excel version also includes an overview with key figures, dropdowns, risk classification, expired reviews, and a classification guide.
3. AI Risk Assessment – Word + PDF
A structured risk analysis for new or modified AI use cases. The template uses a simple probability × consequence model but clearly distinguishes between internal risk prioritization and legal permissibility.
Risk areas addressed include, among others:
- legal classification,
- data protection,
- information security,
- hallucinations and data quality,
- discrimination and fundamental rights,
- human oversight,
- transparency,
- copyright and intellectual property rights,
- vendor lock-in and operational dependency,
- customer trust and reputational risk.
The template includes a risk register, control questions, responsibilities, mitigation, residual risk, and a pre-formatted approval decision.
4. AI Supplier Assessment – Word + PDF
A practical due diligence template for the procurement and approval of external AI services, language models, APIs, AI agents, and other AI platforms.
The assessment covers, among other things:
- the roles of the supplier and customer under the AI Act,
- product information and usage restrictions,
- data processing agreements and sub-processors,
- model training on customer data,
- storage locations and third-country transfers,
- SSO/MFA, permissions, logging, and encryption,
- prompt injection, data exfiltration, and agent permissions,
- incident management, backup, and continuity,
- license terms, input/output, liability, and SLA,
- exit, export, deletion, and vendor lock-in.
5. AI Impact Assessment with DPIA and FRIA Screening – Word + PDF
A broad impact analysis that helps the organization describe an AI use case and assess whether further legal analysis is required.
The template covers:
- description of process, purpose, and affected groups,
- AI Act screening against Article 5, Article 6, and Article 50,
- DPIA screening according to GDPR Article 35,
- FRIA screening according to the AI Act Article 27,
- impact on privacy, equal treatment, working life, accessibility, and other rights,
- safeguards, transparency, complaint channels, and follow-up.
The template does not assume that a DPIA or FRIA is always mandatory. Instead, it helps the business document the screening and identify when a full assessment might be needed.
6. AI Governance and Approval – Word + PDF
This template ties the package together into a practical control system. It contains roles, RACI, decision workflows, approval matrices, control plans, and decision protocols for AI use cases.
The workflow follows the principle:
- Proposal
- Registration
- Classification and screening
- Risk analysis
- Approval decision
- Deployment
- Ongoing follow-up
- Review or decommissioning
Legally updated for 2026
The package takes into account the changed timeline following the Digital Omnibus on AI. This means, among other things, that:
- AI literacy rules according to Article 4 apply,
- transparency requirements according to Article 50 apply from August 2, 2026,
- additional prohibitions according to the amended Article 5 begin to apply on December 2, 2026,
- Chapter III, Sections 1–3 for high-risk AI according to Article 6.2 and Annex III begin to apply, under current legal status, on December 2, 2027,
- corresponding rules for high-risk AI according to Article 6.1 and Annex I begin to apply on August 2, 2028.
The package is therefore designed so that the business can work with classification and preparation now without incorrectly treating future high-risk requirements as if all were already fully applicable.
Who is the package for?
The package is particularly useful for Swedish companies and organizations that use ChatGPT, Microsoft Copilot, Gemini, Claude, generative AI in business systems, AI-based recruitment, analysis tools, code assistants, RAG solutions, AI agents, or other AI functions.
It can be used by, for example:
- CEO and management team,
- board of directors,
- IT manager and information security officer,
- Data Protection Officer (DPO),
- HR,
- legal and compliance,
- procurement,
- system owners and business owners,
- consultants helping companies with AI governance.
Format and delivery
Digital product – immediate download after purchase.
The delivery contains 14 files:
- 6 editable Word files (DOCX)
- 6 PDF versions
- 1 AI system register in Excel (XLSX)
- 1 Read me file
Total: 48 Word/PDF pages + Excel workbook.
Important regarding customization
The AI Act is risk-based, and obligations depend on the organization's role, the system's function, the area of use, and other applicable regulations. The package is therefore a professional template and governance framework that must be adapted to the business's actual AI systems, data processing, industry, collective agreements, information classification, and technical environment.
A specific high-risk use case or extensive processing of personal data may require separate legal, technical, labor, or data protection analysis.
Frequently asked questions
Is the AI policy included?
Yes. The complete AI policy for companies 2026 is included in the package.
Do we get both Word and PDF?
Yes. All six templates are delivered in both editable Word version and PDF.
Is Excel included?
Yes. The AI system register is also delivered as a practical Excel workbook with 50 register rows, dropdowns, a classification guide, and an overview.
Is the package only for high-risk AI?
No. It is intended for broad AI governance and can also be used for generative AI and other use cases with low or limited risk. High-risk and prohibition screening are included to help the organization identify when specific legal control is needed.
Does the package replace a DPIA or FRIA?
No. The package contains screening and documentation materials. If the actual use triggers a requirement for a full DPIA or FRIA, it must be carried out with the depth required by legislation.
Share



