Toolkits

Practical toolkits, ready to deploy.

Most of our engagements leave your team assets they can re-use long after we’re gone. These are those assets, productised.

Published in full · not gated

The seven AI governance non-negotiables

The minimum baseline an enterprise operating in Sub-Saharan Africa needs before a board can confidently authorise AI adoption. Each statement grounded in binding regulation across South Africa, Nigeria, Kenya, Rwanda and Ghana.

Read all seven →
Group A

AI delivery toolkits

Extracted from assets in active use on live engagements.

AI Readiness & Discovery Questionnaire

The structured intake we run at the start of every engagement: who the business is, where the data is actually trapped, what the system should do, when it should run, and what might stop it. Designed to be run by your own team on the next process after we’ve gone.

Includes Question script by section · data-location mapping table · tribal-knowledge capture sheet · intake summary template · pain-audit prompts.

Request this toolkit →

Data Classification Framework

The document that decides your architecture. Sorts everything the business holds into green, amber and red, and states the handling rule, tooling constraint, model-tier restriction and paperwork required at each level.

Includes Tier definitions with worked examples · handling matrix · non-negotiables checklist · sub-processor register template · DPA and retention-clause starters · plain-language client explainer.

Get the PDF →

AI Opportunity & Value Model

Quantify what a manual process actually costs before deciding whether to automate it. Volume, minutes per unit, loaded hourly cost, error rate and cost per error, revenue lost to slow follow-up — annualised, with a conservative and a realistic curve.

Includes Value model workbook · input-collection sheet · direct and second-order savings calculations · twelve-month projection · proposal-ready summary.

Get the PDF →

Prompt & Work Profile Pack

The participant toolkit from our enablement programme, usable without attending it. The templates that turn AI from a search box into a briefed colleague.

Includes Six-part prompt brief · questions-first technique · output-control menu · AI work profile template · continuity file template · reusable work-recipe template · task triage and privacy rules · verification checklist.

Request this toolkit →

AI Handover & Runbook Pack

The handover discipline, as templates. Built on the principle that handover is a deliverable rather than the last week of a project — and that every automation needs an obvious stop button the owner can hit without calling anyone.

Includes Runbook template · build-verification checklist · controls-and-off-switch walkthrough script · credential and access transfer checklist · test-data scrub checklist · sign-off form · post-handover review schedule.

Request this toolkit →

AI Evaluation Starter Harness

AI systems drift. This is the small, versioned test set and the groundedness checks that tell you whether yours still works — the discipline that separates a system from a demo.

Includes Golden-set construction guide · groundedness and faithfulness check definitions · regression-run schedule · drift-escalation thresholds · reviewer screen pattern · results log template.

Request this toolkit →
Group B

AI governance and data protection

Available as part of an engagement. The Nigeria register is available on request.

Nigeria AI Compliance Register

Six instruments govern AI in Nigeria today and none of them are in the National AI Strategy. The working register for establishing which apply to you, and what you could actually put in front of a regulator this week.

Includes All six in-force instruments with the obligation that bites · a ten-minute applicability filter · the register itself · what counts as evidence, obligation by obligation · eight open questions to re-check quarterly.

Get the PDF →

AI / Data Usage Policy Template Pack

A defensible, board-ready set of policies covering staff use of generative AI, third-party models, agentic systems, and customer data in AI workflows. Written to be tailored, not signed off as-is.

Includes Acceptable AI Use Policy · Generative AI Policy · Third-Party Model Risk Policy · Data Classification Annex for AI · Board AI Briefing Pack.

Available with an engagement

NDPA Readiness Scorecard

A structured self-assessment benchmarking your organisation against the Nigeria Data Protection Act 2023 and NDPC implementation guidance.

Includes Self-assessment workbook · heatmap template · remediation tracker · 90-minute calibration workshop.

Available with an engagement

Privacy Maturity Assessment Tool

Multi-jurisdiction privacy maturity assessment covering NDPA, POPIA, GDPR, PDPA and emerging African frameworks, giving a comparable maturity score across geographies.

Includes Assessment workbook · scoring rubric · maturity heatmap · reporting template for board and audit committee.

Available with an engagement

DPO Starter Kit

Everything a newly appointed Data Protection Officer needs in their first 90 days. Built from real-world DPO onboarding work.

Includes DPO charter · 90-day plan · stakeholder map · initial RoPA template · breach playbook · training plan · board reporting pack.

Available with an engagement

Board Privacy & AI Dashboard Template

A one-page reporting template that turns privacy and AI posture into something a board can act on: open issues, regulatory exposure, incident counts, DSAR volumes, transfer status, sanctioned-versus-shadow AI use.

Includes Dashboard template · KRI definitions · reporting cadence guide · sample board narrative.

Available with an engagement

Cross-Border Transfer Assessment Template

A practical Transfer Impact Assessment template covering NDPA, GDPR, POPIA and PDPA transfer regimes — increasingly an AI question, since that’s where the models sit.

Includes Transfer Impact Assessment template · Standard Contractual Clauses pack · decision tree · sample assessment · model-and-region annex.

Available with an engagement

Privacy Incident Playbook Pack

Playbooks for the most common privacy incident scenarios, designed to be lifted into your existing incident response framework.

Includes Lost device · misdirected email · third-party breach · ransomware with personal data · insider exfiltration · regulator notification template.

Available with an engagement
Group C

Assurance and readiness

Available as part of an engagement.

SOC 2 Evidence Preparation Checklist

A structured pre-audit evidence library organised by Trust Services Criteria. Designed to compress the typical six-month evidence scramble into a structured 8–12 week build.

Includes Evidence checklist by TSC · evidence library structure · sample evidence templates · auditor question bank.

Available with an engagement

Sector-Specific Compliance Toolkit

A modular toolkit assembling the controls, evidence and reporting expected of a given sector — initial modules cover financial services, fintech, energy/CII and healthtech.

Includes Sector control library · mapped to NIST CSF 2.0, ISO 27001, SOC 2 and sector regulation · sample evidence catalogue.

Available with an engagement
Start here

Want one of these applied to your business?

The toolkits are the residue of the work, not a substitute for it. If one of them describes a problem you have, the conversation is usually shorter than you expect.