Open AI Governance and Deployment Framework

An operating manual for institutions that buy, deploy, and run AI systems

Version 1.0, 1 October 2026. doi:10.5281/zenodo.22986774

What it is

AI governance is being written for the organisations that build AI. It will be lived by the organisations that deploy it. Nearly all published guidance addresses the developers of models, with their evaluation teams and compliance departments. Almost none of it addresses the institution that buys a system, installs it, and runs it inside decisions about care, money, benefits, education, or essential services. That institution typically has a procurement office, an IT team at capacity, a vendor’s sales deck, and a deadline. The gap is visible in the instruments themselves: most of the EU AI Act’s obligations attach to providers of systems. This framework fills that gap: an operational manual for adopting and running AI responsibly, written for the deployer’s seat.

Five operating rules, each turned into checklists, clauses, and signatures: accountability names a person; evidence comes before trust; oversight carries real authority; watching continues after go-live; and you can always leave.

It restates no principles and competes with no standard. It maps visibly onto the EU AI Act, the NIST AI Risk Management Framework, ISO/IEC 42001, the OECD AI Principles, and the UNESCO Recommendation on the Ethics of AI, so work done under it is evidence of movement towards recognised standards, and where any law applies, the law prevails. It states what it cannot do and names the few points where an institution must buy specialist help.

Who it is for

A technology or operations lead inside an institution adopting AI: a public hospital, a ministry, a municipal utility, a regional bank, a tax authority, a school system, a mid-sized enterprise. It assumes no AI expertise, no compliance department, and no budget for consultants. It covers systems you buy and run, both predictive (systems that score, rank, classify, or forecast) and generative (systems that produce text, images, or code). Systems authorised to act on their own (agentic systems) are covered through Module 2’s autonomy rules, which treat an adverse action taken without prior human review as a matter for escalation.

Versions and downloads

This is Version 1.0. Every file, including the editable artifacts, is free to download from ystech.io/ai-governance without registration. Revised versions are published there with a version history that records what changed and why. The publisher decides revisions. Earlier versions remain available, so each institution decides when to move to a new version; the system register (Artifact 7.11) records the version it adopted.

The framework

PDF
Complete framework, accessible PDF
86 pages, 1.3 MB
Download
Word
Complete framework, Word
86 pages, 151 KB
Download

The framework by part (Word)

  • Front and back matter
    12 pages, 31 KB
    Download
  • Module 1: Foundations
    5 pages, 18 KB
    Download
  • Module 2: Risk tiering
    8 pages, 24 KB
    Download
  • Module 3: Governance roles and human oversight
    8 pages, 24 KB
    Download
  • Module 4: Procurement and vendor accountability
    15 pages, 36 KB
    Download
  • Module 5: Data, security, and sovereignty
    7 pages, 23 KB
    Download
  • Module 6: The deployment lifecycle
    10 pages, 28 KB
    Download
  • Module 7: The implementation toolkit
    19 pages, 41 KB
    Download

The toolkit as editable files

Each artifact repeats its own instructions, carries its own licence line, and works without its parent module.

  • 7.1 One-page orientation
    Word, 1 page, 12 KB
    Download
  • 7.2 Risk classification worksheet
    Word, 2 pages, 13 KB
    Download
  • 7.3 Vendor due diligence checklist
    Word, 2 pages, 14 KB
    Download
  • 7.4 Contract clause library
    Word, 3 pages, 14 KB
    Download
  • 7.5 Governance RACI and role definition pack
    Word, 2 pages, 14 KB
    Download
  • 7.6 Pre-deployment readiness pack, with the data checklist
    Word, 3 pages, 15 KB
    Download
  • 7.7 Stage-by-stage lifecycle checklist
    Word, 1 page, 11 KB
    Download
  • 7.8 Monitoring plan template
    Word, 1 page, 11 KB
    Download
  • 7.9 Appeal notice template
    Word, 1 page, 10 KB
    Download
  • 7.10 Incident response template
    Word, 1 page, 12 KB
    Download
  • 7.11 System register
    Excel workbook, 14 KB
    Download

Version history

Version 1.0, 1 October 2026. First published version. doi:10.5281/zenodo.22986774.

Feedback

Write to Anuuj Chauhan, Co-Founder and CEO of Yellow Sapphire Technologies, at [email protected] when an artifact fails in practice, a checklist is missing a question, a passage does not survive translation, you find an error, or you have an improvement to suggest. The authors will read every message. Institutions adopting the framework can use the same address to arrange a conversation with the authors about implementation, at no charge. A contribution that leads to a material change in a checklist, clause, or definition is acknowledged in a later version, with the contributor’s consent.

Translations

Community translations are welcome under the licence and will be linked from the framework page. A translation is official only when the publisher has commissioned and checked it, and every translation states the version it was made from.

How to cite

Yellow Sapphire Technologies Inc. Open AI Governance and Deployment Framework, Version 1.0. Moncton, New Brunswick: Yellow Sapphire Technologies Inc., 1 October 2026. doi:10.5281/zenodo.22986774. Version 1.0 is deposited, on publication, in an open archival repository (Zenodo) under that DOI, so the reference is stable and permanent; each future version receives its own DOI, and citations should state the version.

Provenance, licence and disclaimer

Written and published by Yellow Sapphire Technologies Inc. as the delivery of a commitment registered through the Partnerships Hub of the United Nations Global Dialogue on AI Governance; it was not endorsed, approved, or authored by the United Nations. Published free of charge under CC BY 4.0: any institution may use, adapt, translate, and localise it, with attribution.

This framework is guidance and it is not legal advice. Full disclaimers in the back matter.