Colorado AI Act in · EU AI Act (High-Risk) in · ISO 42001 + NIST AI RMF + Agentic AI — unified in one toolkit
Recommended

AI Controls Professional: Complete AI Governance Implementation System

Everything in ACT Tier 1 — enhanced — plus 5 audit-ready policy templates, an AI agent security module with dual-OWASP coverage, a FRIA template with Colorado consumer rights operational templates, a board reporting pack, a 6-month implementation plan, and an MCP security governance checklist. From gap analysis to audit-ready evidence in one toolkit.

$1,299 One-time purchase · Instant download
Get AI Controls Professional

Payments processed by Lemon Squeezy (Merchant of Record). Price increases to $1,499 after initial launch period.

Five AI governance frameworks — ISO 42001, NIST AI RMF, NIST GenAI Profile, Colorado AI Act, and OWASP Top 10 — converging into the Move78 AI Controls Toolkit that produces gap analysis, risk register, compliance evidence, board reporting, and safe harbor defense

Includes Everything in ACT Tier 1

ACT Tier 2 Professional contains the complete Tier 1 workbook — enhanced with two additional tabs and expanded gap analysis columns — plus 14 additional deliverable files that close the implementation gaps Tier 1 identifies.

What’s Inside: 16 Files

One ZIP file. 13-tab enhanced workbook, 8 Word policy and procedure templates, 4 Excel deliverables, 1 PowerPoint board pack, plus README and legal disclaimer. Delivered as an instant download.

Enhanced Workbook

Excel · 13 Tabs

AI Controls Professional Workbook

All 11 Tier 1 tabs plus new Evidence Tracker (Tab 12) with completion dashboard and Regulatory Update Log (Tab 13). Gap Analysis enhanced with Remediation Status and Evidence Attached columns. 106-row cross-framework controls matrix.

Policies & Procedures

Word · 8–10 pages

AI Governance Policy

Foundational policy establishing governance structure, risk appetite, classification criteria, approved and prohibited uses, data governance, human oversight requirements, and third-party governance. RACI matrix included.

Word · 10–12 pages

AI Acceptable Use Policy

Comprehensive acceptable use rules covering approved tools, data handling, prohibited activities, output review, IP obligations, and incident reporting. Section 8 adds 9 subsections of open-source AI agent governance covering deployment scenarios, credential isolation, HITL thresholds, network controls, and decommissioning.

Word · 6–8 pages

AI Risk Management Procedure

Operational risk identification, 5×5 assessment methodology, treatment options, residual risk acceptance, register maintenance, and escalation thresholds. Color-coded risk matrix with brand-consistent formatting.

Word · 8–10 pages

AI Incident Response Procedure

Detection, classification, triage, containment, root cause analysis, and corrective action. Section 8 adds agent-specific procedures: supply chain compromise (ClawHavoc pattern), gateway token theft, persistent memory poisoning, and credential rotation checklist.

Word · 5–7 pages

AI Vendor Due Diligence Procedure

8-category vendor assessment criteria, 5-point risk scoring, due diligence workflow, contractual clause recommendations, and MCP server vetting pipeline with 7-step operational workflow.

Word · 4–6 pages

Vendor Risk Assessment Questionnaire

Email-ready questionnaire with 8 sections. Internal scoring guidance included (marked “Do Not Send to Vendor”). Scoring thresholds aligned with the Due Diligence Procedure.

AI Agent Security & Governance

Excel · 5 Tabs

AI Agent Security Module

50-control security matrix covering OWASP Agentic Top 10 (ASI01–ASI10), OWASP LLM Top 10 (LLM01–LLM10), and MCP protocol controls. Agent inventory, access control matrix, agent risk register, and open-source agent risk register with 18 mapped risks.

Word · 8–10 pages

Agentic AI Governance Policy

Strategic governance layer for autonomous and semi-autonomous agents. 5-level autonomy boundaries, dynamic access control, identity management, inter-agent communication governance, MCP tool and protocol governance (5 subsections), deployment approval workflow, monitoring, and kill-switch requirements.

Excel · 3 Tabs

MCP Security Governance Checklist

MCP server inventory with approval status tracking, 20-control security checklist across 6 categories, and 7-step server vetting workflow with sign-off fields. The only purchasable MCP governance artifact on the market.

Colorado Compliance & Reporting

Word · 10–15 pages

Impact Assessment Template (FRIA)

Structured fundamental rights impact assessment with rights identification checklist, affected population analysis, risk scoring, stakeholder consultation, and approval workflow. Appendix contains 6 Colorado Consumer Rights operational templates: consumer notice, adverse decision explanation, data correction workflow, appeal routing SOP, public website disclosure, and AG notification template.

PowerPoint · 7 slides

Board Reporting Pack

Executive-ready presentation covering governance posture across 12 domains, risk heat map, 4-framework compliance progress with deadline tracker, remediation timeline, and budget recommendations.

Excel · 4 Tabs

Board Reporting Data

Data feed workbook supporting the Board Reporting Pack. Governance posture scores, risk summary, framework compliance status, and implementation progress with working formulas.

Excel · 28 tasks

Implementation Project Plan

6-month phased implementation roadmap with 28 tasks, phase-colored rows, deliverable cross-references, and dependency tracking. From policy approval through audit readiness.

AI Agent Security Governance

No competing product maps both OWASP Agentic Top 10 and OWASP LLM Top 10 into ISO 42001 controls, adds MCP protocol governance, and provides open-source agent risk mapping — all in purchasable, customizable templates.

ACT Tier 2 covers OpenClaw, Manus, AutoGPT, CrewAI, LangGraph, and any autonomous agent architecture. The governance documentation addresses shadow AI agent deployments, supply chain compromise scenarios (including the ClawHavoc registry attack pattern), credential isolation, persistent memory governance, and decommissioning obligations.

The MCP Security Governance Checklist is the first purchasable governance artifact dedicated to the Model Context Protocol — covering server inventory, 20 security controls across 6 categories, and a 7-step vetting workflow.

FrameworkIssuing BodyCoverage in ACT Tier 2
OWASP Agentic Top 10OWASP Foundation (Dec 2025)24 controls mapped to ASI01–ASI10
OWASP LLM Top 10OWASP Foundation (2025)18 controls mapped to LLM01–LLM10
MCP Security GovernanceMove78 (proprietary)8 protocol controls + 20-item checklist + 7-step vetting
Singapore IMDAIMDA (Jan 2026)Referenced in Agentic AI Governance Policy
UC Berkeley BAIRUC Berkeley (Feb 2026)Referenced in Agentic AI Governance Policy

Colorado AI Act Safe Harbor

The Colorado AI Act (SB 24-205 as amended by SB 25B-004, enforcement June 30, 2026) gives deployers an affirmative defense under C.R.S. 6-1-1706 if they demonstrate compliance with a recognized AI risk management framework. ACT Tier 2 provides the governance documentation to support that defense.

Framework Coverage

Nine frameworks unified in one implementation system. Every reference verified against primary source documents.

FrameworkSourceCoverage
ISO/IEC 42001:2023Purchased standard PDFEvery clause (4.1–10.2) and Annex A control (A.2–A.10)
NIST AI RMF 1.0NIST AI 100-1 (Jan 2023)All 72 subcategories across GOVERN, MAP, MEASURE, MANAGE
NIST AI 600-1 GenAI ProfilePublished profile (Jul 2024)200+ actions mapped to corresponding RMF subcategories
Colorado AI ActSB 24-205 as amended by SB 25B-004All deployer and developer obligations with C.R.S. citations
OWASP Agentic Top 10OWASP Foundation (Dec 2025)ASI01–ASI10 mapped to ISO 42001 and NIST controls
OWASP LLM Top 10OWASP Foundation (2025)LLM01–LLM10 mapped to ISO 42001 and NIST controls
MCP Security GovernanceMove78 proprietary research20 controls, 6 categories, server vetting workflow
Singapore IMDAGov framework (Jan 2026)Referenced in Agentic AI Governance Policy
UC Berkeley BAIRAcademic framework (Feb 2026)Referenced in Agentic AI Governance Policy

Cost Comparison

A complete AI governance implementation typically costs $20,000–$200,000 in consulting fees or $5,000–$50,000 per year in platform subscriptions. ACT Tier 2 delivers equivalent documentation at less than 3% of the cheapest alternative.

Big 4 Consulting
$50K–$200K
Enterprise-wide AI governance implementation. 3–12 month engagement.
Boutique GRC
$20K–$80K
Cross-framework gap analysis and remediation. 4–12 week timeline.
Enterprise SaaS
$5K–$50K/yr
GRC platform subscription. Recurring. Vendor lock-in. Training overhead.
ACT Tier 2 Professional
$1,299
One-time. 16 files. No subscription. No platform dependency. No vendor lock-in.

Who This Is For

CTOs, CISOs, DPOs, and compliance leads at technology-centric SMEs (10–250 employees) who need a complete, audit-ready implementation system covering ISO 42001, NIST AI RMF, Colorado AI Act, and AI agent security — including autonomous agent governance for OpenClaw and similar open-source deployments.

ACT Tier 2 is the right choice for organizations that have completed an initial gap analysis (or are ready to skip directly to implementation) and need the full documentation set to demonstrate governance maturity to auditors, regulators, boards, and customers.

Starting point. Not sure where the gaps are yet? ACT Tier 1 Starter ($399) provides the unified controls matrix, gap analysis checklist, and risk register to assess your current posture. The gap analysis results will name exact Tier 2 deliverables needed to close each gap.

Build Your AI Governance System

16 files. 9 frameworks. Audit-ready documentation. From assessment to evidence in 6 months.

Get AI Controls Professional — $1,299

Not sure yet? Take the free 15-question readiness assessment first.