A 30-Day AI Governance Plan: From Diagnostic to Badge

Treat AI governance as a focused sprint with this 30-day plan, implementing the six core controls needed to satisfy procurement and earn your AI Assurance badge.

By Harmeen Birk, AI Governance Advisor · 2026-06-06 · 6 min read

From diagnostic to badge: a 30-day AI governance sprint


Most AI governance work fails for the same reason: it gets treated as a programme when it should be treated as a sprint. The companies that move fastest pick a 30-day window, freeze scope, and ship the six controls procurement actually asks for. This is the sprint we built AI Essentials around. Here's how to run it.
## Why 30 days
Long enough to write real policies and gather real evidence. Short enough to keep one person accountable and avoid the usual death-by-committee. If you can't do it in 30 days, you won't do it in 90 either, the scope will just grow.
## Before you start (day 0)
Pick an owner. One person, not a working group. Block 4–6 hours a week in their diary. Run the free AI Risk Assessment so you start with a baseline score, it's a 5-minute diagnostic, no sign-up required. Decide now what "done" looks like for you: most companies are aiming for the AI Essentials Essential or Professional badge at the end of day 30.
**→ Start with the free AI Risk Assessment and get your Red/Amber/Green score before day 1.** ::cta[Start free assessment]{href=/assessment variant=primary} ## Week 1 - Inventory and ownership
The single highest-leverage week. You cannot govern what you cannot name.
- List every AI tool in use, sanctioned or not. Ask each team lead in writing. - Tag each tool: vendor, data it touches, who owns it, whether it makes or supports a decision. - Decide your sanctioned-tools list and publish it. Anything not on the list needs approval. - Name the senior owner for AI risk. This is rarely the CTO — it's usually the COO or General Counsel.
By Friday you have an **AI register** and a named accountable owner. Two of the six controls done and two of the questions on your AI Essentials self-assessment answered.
## Week 2 — Policy and use rules
- Adopt an **AI use policy** that covers acceptable use, prohibited use, data handling and human oversight. Don't write from scratch; start from a template and tailor. - Add **vendor due-diligence** questions to your procurement process for any new AI tool. - Brief the whole company in a 20-minute all-hands. People follow rules they've heard explained once, not rules buried in a PDF.
By Friday you have policy and vendor screening. Four of six controls done.
**→ Starting your Essential self-assessment now means you're banking these answers as you go, not reconstructing them in week 4.**

::cta[Find your tier]{href=/selector variant=primary}

Week 3 — Risk and incident handling


- Run a lightweight **AI risk assessment** on the top five tools from your register. Likelihood × impact, one page each. - Write a one-page **AI incident response plan**. For example: what counts as an incident, who to tell, how to contain. Plug it into your existing incident response process if you have one. - Identify the highest-risk tool and put a human-in-the-loop check on the output.
By Friday you have risk and incident handling. All six controls in place.
## Week 4 - Evidence, attestation, badge
- Gather evidence: screenshots, signed policy acknowledgements, register exports, vendor responses, training attendance. - Have the named owner sign off. - Complete your self-assessment and submit for the badge. Self-certify with Essential, or add evidence upload and a signed senior officer attestation for the verified badge under Professional. - Brief sales: here's the badge, here's the one-pager, here's how to answer the top five AI questions on a security questionnaire.
By the end of day 30 you have a defensible position and a certificate to show for it.
**→ Get Essential (£499/year) to self-certify, or get Professional (£2,999/year) for a verified badge and public certificate.**

::cta[Get AI Assured certified]{href=/selector variant=primary}

The six controls procurement actually asks for


If you do nothing else, do these:

  1. AI register / inventory of tools in use.
  2. Named senior owner accountable for AI risk.
  3. Written AI use policy, acknowledged by staff.
  4. Vendor due-diligence for AI tools.
  5. AI risk assessment for the highest-impact tools.
  6. AI incident response process.

Every AI security questionnaire we've seen maps to these. Get them done and most of your buyer pressure evaporates. They also map directly onto the AI Essentials self-assessment, so the work you do here is the certification — there's no separate exercise afterwards.

Common stalls (and how to beat them)


  • "We need legal to review." Time-box it. Legal gets one week, not one quarter.
  • "We don't know all the tools." You won't on day 1. Inventory what you know, commit to a quarterly refresh.
  • "We want it perfect." Perfect is the enemy of defensible. Ship at 30 days, iterate after.

Next step


Run the free AI Risk Assessment, pick your start date, and put the four weeks in the calendar. The companies that win procurement aren't the ones with the best AI — they're the ones who can prove they have it under control.

→ Start free, then choose Essential or Professional when you're ready to certify.

::cta[Start free assessment]{href=/assessment variant=primary}