Toolkit bundle

AI Risk & Lifecycle Control

Connect one risk method to lifecycle controls, inventory, AISIA workflow, and evidence structure for AI systems.

Best for: Operational control of AI lifecycle risk.

This bundle combines the unified risk method in Toolkit 5 with the lifecycle operating controls in Toolkit 6, so each AI system can be identified, assessed, risk-treated, evidenced, monitored, and escalated through one operating model.

£1,295 bundle price £1,598 individually. Save £303 (19%). One risk method plus a stage-gated lifecycle record for every AI system
Your Implementation Route

Two toolkits. One connected route from inventory to assured risk.

◎
Step 1 Week 1-3
TK6 - AI Lifecycle Control System
control

✓Register every AI system with a System ID, owner and lifecycle stage
✓Run AISIA triage to decide which systems need assessment
✓Pass stage-gated lifecycle reviews from design to retirement
📄 Deliverable: Live AI Inventory & Lifecycle Records
◈
Step 2 Week 4-8
TK5 - Unified AI & Security Risk System
manage

✓Score AI and security risks against each System ID
✓Keep SoA lite views for ISO/IEC 42001 and ISO 27001 aligned with treatment decisions
✓Record residual risk acceptance by risk band with sign-off
📄 Deliverable: Live Risk Register & Risk Acceptance Records
🎯
End result: Every AI system inventoried, risk-scored and lifecycle-controlled Inventory, risk treatment and lifecycle evidence in one connected system

Available now

Instant digital download
Toolkit 5 and Toolkit 6 in full. No subscription. One-off purchase.
£1,295

Paying by invoice or need a PO raised first? Request an invoice →

We'll send you a proforma invoice within 1 business day. Access is provided once payment clears, using the same automated delivery as a card purchase.

🔒 Secure checkout via Lemon Squeezy ⚡ Instant delivery to your email 📄 7-day refund policy 🧾 Price includes UK VAT 👤 Your governance data stays with you

Included in this bundle

  • Toolkit 5 - Unified AI & Security Risk System
  • Toolkit 6 - AI Lifecycle Control System

Toolkit 5 is also included in the AI Governance Starter and AI Ethics & Risk bundles. If you already own Toolkit 5, choose the standalone toolkit option or contact us before purchase.

Includes all current files from Toolkit 5 and Toolkit 6, plus a bundle Start Here guide, delivered as a one-off digital download.

Outputs may be shared with auditors, customers, regulators, and advisers for assurance.


By the end of implementation you will have

  • A live AI inventory with one System ID per AI system, linked to ownership, lifecycle stage, and assessment status.
  • A unified AI and security risk method for scoring, treatment, evidence, and reporting.
  • A repeatable route from AISIA triage into scored risk, treatment, residual acceptance, and stage-gated lifecycle records from design to retirement.
  • Committee-ready oversight records that connect AI lifecycle control with risk position and evidence status.

Designed for

  • Organisations that need operational control of AI systems from design to retirement.
  • CISO, GRC, InfoSec, AI, data, and risk leaders managing AI lifecycle accountability.
  • Teams that want AI inventory, AISIA, model cards, and risk treatment to operate as one workflow.
  • Internal audit and assurance teams that need traceable evidence across AI system ownership, change, monitoring, and retirement.

Toolkit contribution comparison

Use this matrix to compare what each included toolkit contributes, what it costs, and what manual work it replaces.

CapabilityToolkit 5
£499
Toolkit 6
£1,099
AI inventory and ownershipSupporting roleRecords the System ID from the inventory against each AI risk, so risks trace to the system they affect.Primary roleProvides the AI inventory, Model_Register, supplier AI mapping, and data lineage structure.
AISIA impact assessmentSupporting roleRecords the AISIA reference against each AI risk and turns findings into scored risk and treatment.Primary roleRuns AISIA triage (nine signals, seven trigger overrides) and the full weighted assessment for new or materially changed AI systems.
Unified risk registerPrimary roleProvides risk criteria, the unified AI and security risk register, scoring method, treatment plan, residual acceptance, and audit exports.Supporting roleRecords linked Risk IDs on each inventory entry and feeds AISIA outcomes and control evidence into the risk method.
Lifecycle evidenceSupporting roleLinks risk entries and treatment actions to evidence IDs, owners, dates, and control status.Primary roleProduces seven stage records from design to retirement, each with entry and exit gate criteria, plus model cards.
Committee reportingPrimary roleProvides treatment status, risk acceptance decisions, and audit pack views.Primary roleProvides inventory, AISIA outcome, lifecycle stage gate, and model documentation views for approvals.
What it replacesReplaces separate ISMS risk logs, AI risk spreadsheets, informal acceptance decisions, and treatment trackers.Replaces uncontrolled AI inventories, inconsistent impact assessments, scattered model documentation, and informal lifecycle sign-offs.

Toolkit 5 - Unified AI & Security Risk System

£499

  • AI inventory and ownership: Links each AI risk to its System ID.
  • AISIA impact assessment: Turns AISIA findings into scored risk.
  • Unified risk register: Provides scoring, treatment, acceptance, and audit exports.
  • Lifecycle evidence: Links risks to evidence IDs and treatments.
  • Committee reporting: Provides treatment status and acceptance decisions.

What it replaces: Replaces separate ISMS risk logs, AI risk spreadsheets, informal acceptance decisions, and treatment trackers.

Toolkit 6 - AI Lifecycle Control System

£1,099

  • AI inventory and ownership: Provides the AI inventory and Model_Register.
  • AISIA impact assessment: Runs triage and full assessment workflow.
  • Unified risk register: Records linked Risk IDs and feeds evidence into risk treatment.
  • Lifecycle evidence: Produces seven stage-gated records and model cards.
  • Committee reporting: Provides lifecycle, AISIA, and model documentation views.

What it replaces: Replaces uncontrolled AI inventories, inconsistent impact assessments, scattered model documentation, and informal lifecycle sign-offs.

What each included toolkit adds

Each included toolkit keeps its full standalone content and purpose. The bundle gives you a joined-up route through those artefacts.

Toolkit 5 - Unified AI & Security Risk System preview

One risk register for information security and AI lifecycle risks. Replace fragmented ISMS and AI risk spreadsheets with a single governance-ready register, unified scoring method, and audit-traceable evidence hooks.

Key contribution

  • Unified Risk Register - risk criteria, unified scoring, treatment plan, SoA lite views and audit-ready exports.
  • Risk Acceptance Form - residual risk sign-off by band, up to Board or Executive Sponsor for Critical risk.
  • Risk Owner Charter and RACI, AI Incident Log and Customer Assurance One-Pager.
  • System ID link - each AI risk records the System ID and AISIA reference from Toolkit 6.
View individual toolkit
Toolkit 6 - AI Lifecycle Control System preview

Control AI from design to retirement with an ISO/IEC 42001-aligned inventory, AISIA workflow, lifecycle evidence structure, and model documentation that governance reviewers can navigate.

Key contribution

  • AI Inventory Workbook - AI inventory, Model_Register, supplier AI mapping, data lineage and classification reference.
  • AISIA Triage and Full Assessment - intake gate and weighted assessment placing each system in the Low, Medium, High or Critical tier.
  • Model Card templates - short and long form documentation for system purpose, data, model behaviour, limits, monitoring, and approvals.
  • Seven lifecycle stage records - design and scoping to retirement, each with entry and exit gate criteria.
View individual toolkit

Suggested implementation path

  1. Use Toolkit 6 to identify AI systems, confirm ownership, assign lifecycle stage, and run AISIA triage.
  2. Use Toolkit 5 to score material AI and security risks against each System ID, assign treatment owners, record residual acceptance, and track evidence links.
  3. Use the Toolkit 6 stage records and model cards to pass each lifecycle gate with evidence for approvals, monitoring, change control, and retirement.
  4. Use Toolkit 5 reporting outputs to brief the Technology & Risk Committee on risk position, treatment status, and assurance gaps.

Why choose this bundle

This bundle is for organisations that need more than a risk register. It connects AI system ownership, AISIA, lifecycle governance, risk scoring, treatment, and evidence so AI systems can be governed from design to retirement.

Procurement justification

This bundled purchase supports implementation of integrated AI risk-management and lifecycle governance controls.

The combined materials connect risk identification, scoring and treatment with AI inventory, approval, model documentation, monitoring, change control and retirement evidence so that AI systems can be managed throughout their operational lifecycle.

The materials can be implemented internally by AI governance, information security, risk, data, product, compliance and internal audit teams using our organisation's own governance and evidence systems.

This is a one-off digital bundle purchase. The supplier does not require access to our AI inventories, AI systems, prompts, models, datasets, customer data, source code, production environments, internal systems, risk registers or completed lifecycle evidence to fulfil this purchase.

The purchase is proportionate because it links the risk method to the lifecycle controls that keep AI oversight current, while providing a saving against buying the included toolkits separately.

Designed for internal approval and procurement workflows.

Frequently asked questions

Why combine risk and lifecycle control?

Risk treatment is more effective when it is linked to the AI system lifecycle. Toolkit 5 provides the risk method, and Toolkit 6 provides the controls for intake, approval, monitoring, change and retirement.

Is this a hosted AI inventory platform?

No. It is a self-contained digital toolkit, not a hosted SaaS platform or managed governance portal.

Does the supplier need access to our AI inventory?

No. The supplier does not require access to AI inventories, systems, datasets, prompts, models, source code, risk registers or completed lifecycle evidence.

What file formats are included?

The bundle is delivered as PDF, DOCX and XLSX files: read-only guides as PDF, editable templates as DOCX and workbooks as XLSX.

Can this be used with our existing GRC or document systems?

Yes. The outputs can be adapted and stored in the organisation's own document management, risk, audit and evidence systems.

How should this be implemented?

Start by establishing the AI inventory and lifecycle status, then connect each system to impact assessment, risk treatment, model documentation and review evidence.

Complete indexed PDF remains standalone

Build Once. Comply Twice.™ is sold separately as a £17.99 complete indexed PDF desk reference. It supports the operating model, but it is not required to purchase or use these bundles.