From diagnostic to badge: a 30-day AI governance sprint
Most AI governance work fails for the same reason: it gets treated as a programme when it should be treated as a sprint. The companies that move fastest pick a 30-day window, freeze scope, and ship the six controls procurement actually asks for. This is the sprint we built AI Essentials around. Here's how to run it.
Why 30 days
Long enough to write real policies and gather real evidence. Short enough to keep one person accountable and avoid the usual death-by-committee. If you can't do it in 30 days, you won't do it in 90 either — the scope will just grow.
Before you start (day 0)
Pick an owner. One person, not a working group. Block 4–6 hours a week in their diary. Run the free AI Risk Assessment so you start with a baseline score — it's a 5-minute diagnostic, no sign-up required. Decide now what "done" looks like for you: most companies are aiming for the AI Essentials Essential or Professional badge at the end of day 30.
Start with the free AI Risk Assessment and get your Red/Amber/Green score before day 1.
Week 1 — Inventory and ownership
The single highest-leverage week. You cannot govern what you cannot name.
List every AI tool in use, sanctioned or not. Ask each team lead in writing.
Tag each tool: vendor, data it touches, who owns it, whether it makes or supports a decision.
Decide your sanctioned-tools list and publish it. Anything not on the list needs approval.
Name the senior owner for AI risk. This is rarely the CTO — it's usually the COO or General Counsel.
By Friday you have an AI register and a named accountable owner. Two of the six controls done and two of the questions on your AI Essentials self-assessment answered.
Week 2 — Policy and use rules
Adopt an AI use policy that covers acceptable use, prohibited use, data handling and human oversight. Don't write from scratch; start from a template and tailor.
Add vendor due-diligence questions to your procurement process for any new AI tool.
Brief the whole company in a 20-minute all-hands. People follow rules they've heard explained once, not rules buried in a PDF.
By Friday you have policy and vendor screening. Four of six controls done.
Starting your Essential self-assessment now means you're banking these answers as you go, not reconstructing them in week 4.
Week 3 — Risk and incident handling
Run a lightweight AI risk assessment on the top five tools from your register. Likelihood × impact, one page each.
Write a one-page AI incident response plan. For example: what counts as an incident, who to tell, how to contain. Plug it into your existing incident response process if you have one.
Identify the highest-risk tool and put a human-in-the-loop check on the output.
By Friday you have risk and incident handling. All six controls in place.
Week 4 — Evidence, attestation, badge
Gather evidence: screenshots, signed policy acknowledgements, register exports, vendor responses, training attendance.
Have the named owner sign off.
Complete your self-assessment and submit for the badge. Self-certify with Essential, or add evidence upload and a signed senior officer attestation for the verified badge under Professional.
Brief sales: here's the badge, here's the one-pager, here's how to answer the top five AI questions on a security questionnaire.
By the end of day 30 you have a defensible position and a certificate to show for it.
Get Essential (£499/year) to self-certify, or get Professional (£2,999/year) for a verified badge and public certificate.
The six controls procurement actually asks for
If you do nothing else, do these:
AI register / inventory of tools in use.
Named senior owner accountable for AI risk.
Written AI use policy, acknowledged by staff.
Vendor due-diligence for AI tools.
AI risk assessment for the highest-impact tools.
AI incident response process.
Every AI security questionnaire we've seen maps to these. Get them done and most of your buyer pressure evaporates. They also map directly onto the AI Essentials self-assessment, so the work you do here is the certification — there's no separate exercise afterwards.
Common stalls (and how to beat them)
"We need legal to review." Time-box it. Legal gets one week, not one quarter.
"We don't know all the tools." You won't on day 1. Inventory what you know, commit to a quarterly refresh.
"We want it perfect." Perfect is the enemy of defensible. Ship at 30 days, iterate after.
Next step
Run the free AI Risk Assessment, pick your start date, and put the four weeks in the calendar. The companies that win procurement aren't the ones with the best AI — they're the ones who can prove they have it under control.
Start free, then choose Essential or Professional when you're ready to certify.
Essential Takeaways
Treat AI governance as a focused 30-day sprint, not an open-ended programme, to ensure completion.
Assign a single, accountable owner to avoid the common death-by-committee.
The sprint follows a weekly progression: inventory, policy, risk management, and evidence gathering for your badge.
Focus on the six controls that satisfy most procurement requests: register, owner, use policy, vendor DD, risk assessment, and incident plan.
Scope
AI Assured is a governance programme, not an accredited certification body. It does not issue ISO/IEC 42001 certificates or statutory sign-off for the EU AI Act, FCA, FDA, NYC LL144 or other regulatory regimes. Articles are general information, not legal or regulatory advice.
Frequently asked questions
What is a 30-day AI governance plan?
It's a focused sprint designed to establish essential AI controls quickly. Instead of a long, drawn-out programme, this approach implements six core controls over four weeks, covering inventory, policy, risk assessment, and incident response. The goal is to create a defensible governance framework and earn an AI Assurance badge to satisfy procurement requirements, all within a single month.
What are the six essential controls for AI governance?
The six core controls that procurement and security questionnaires typically ask for are: 1) an AI register of all tools; 2) a named senior owner accountable for AI risk; 3) a written AI use policy; 4) a vendor due-diligence process for new tools; 5) risk assessments for high-impact systems; and 6) an AI incident response plan. These form the foundation of a robust framework.
How should a company start an AI governance plan?
Before day one, designate a single project owner and run a free AI Risk Assessment to get a baseline score. This initial diagnostic helps frame the work ahead. The owner should then create an inventory of all AI tools in use by asking each team lead. Finally, you must name a senior owner, such as the COO or General Counsel, who is ultimately accountable for AI risk.
What happens in the first week of an AI governance sprint?
The first week focuses on inventory and ownership. The main tasks are to list every AI tool in use and compile an official AI register, tagging each tool with its owner and data usage. During this week, you must also name a senior owner who is accountable for AI risk. By the end of the week, you will have completed two of the six core governance controls.
What are common challenges when implementing an AI governance plan?
Common stalls include waiting too long for legal reviews, trying to create a perfect inventory from day one, and general perfectionism that delays completion. To overcome these, you should time-box legal feedback to one week, start with the inventory you have and commit to quarterly updates, and prioritise creating a defensible position in 30 days rather than a perfect one that never gets finished.
Harmeen Birk, AI Governance Advisor
Harmeen Birk is an ex-Citi senior AI strategist and executive advisor with over 20 years of experience leading large-scale data and AI programs within global financial institutions. As an IAPP-trained Artificial Intelligence Governance Professional (AIGP) she specialises in bridging the gap between rigorous compliance and practical innovation. Her expertise focuses on establishing robust AI governance frameworks and responsible AI practices for mid-market companies, boards, and emerging tech vendors.
Credentials: AI Governance Advisors, Institutions & Financial Services | Ex-Citi | HBS | AIGP | CGI

