Free public control tools

Practical templates for control operators

Use these worksheets and checklists to organize one decision, one evidence set, or one governance conversation. They are public and require no email or account.

This is the Ironframe distribution hub — not Governance Frame. From LinkedIn or email, link to a tool page. On each page, use Print / Save PDF for an offline copy.

Template / checklist for operators. Not legal advice. Not a certification.

Cyber risk scenario worksheet

Frame one plausible cyber-loss scenario, its assumptions, ownership, and next decision.

Best for: A risk has been raised, but the business impact, assumptions, or decision owner are still unclear.

Evidence readiness assessment

Identify whether control evidence is complete, attributable, current, and reviewable.

Best for: A team needs to organize proof for a control without claiming that the control has been independently validated.

Third-party criticality questionnaire

Classify supplier dependency so due diligence and ongoing oversight match operational exposure.

Best for: A vendor is new, materially changing, renewing, or supporting a business-critical service.

NIST CSF 2.0 Govern function checklist

A practical checklist for reviewing governance outcomes in the NIST Cybersecurity Framework 2.0 Govern Function.

Best for: Leadership needs a shared view of cybersecurity governance, accountability, and oversight before selecting detailed controls.

AI governance inventory

Create an accountable inventory of AI use cases, data, owners, risks, and human oversight.

Best for: A team is introducing, renewing, or materially changing an AI-assisted workflow, vendor, or model.