Use this checklist to get an honest, first-pass read on where your organization stands with AI governance. It’s organized the way a gap assessment would be structured — by category, not by framework — so you can walk through it regardless of which standards or frameworks you eventually adopt. For the reasoning behind each area, see our main guide, AI Governance for Enterprises: A Practical Framework for IT, Cybersecurity, and Risk Leaders.
A simple way to use it: go category by category and mark each item as in place, partially in place, or not in place. Don’t expect all green on a first pass — the point is to see the gaps clearly, not to pass a test.
Strategy
- Leadership has explicitly acknowledged AI governance as a business priority, not just an IT topic
- There is a stated position on how the organization intends to use AI (and where it will not)
- AI governance objectives are connected to actual business risk, not copied from a generic template
Governance and Ownership
- A specific person or committee is accountable for AI governance
- Roles are defined for IT, security, legal, compliance, risk, privacy, HR, and business units
- There is an escalation path for AI-related questions or incidents
- Governance ownership is documented somewhere employees can actually find it
Policies
- A written AI acceptable-use policy exists and is genuinely readable (not buried in legal language)
- The policy specifies which tools are approved, restricted, or prohibited
- The policy addresses what data can and cannot be entered into AI tools
- Employees have been trained on the policy, not just informed it exists
- The policy is reviewed and updated on a defined schedule
AI Inventory
- A current inventory exists of approved AI systems and tools
- The inventory includes AI features embedded in existing SaaS products, not just standalone AI tools
- There is a process for detecting unsanctioned (“shadow”) AI usage
- AI agents and autonomous systems are separately identified in the inventory
- The inventory records what data each AI system has access to
- Someone owns keeping the inventory current
Risk
- AI use cases are classified by risk level (for example, based on business impact, data sensitivity, and autonomy)
- Higher-risk AI systems receive more scrutiny than lower-risk ones
- Risk assessments consider regulatory exposure, not just technical risk
- AI risk is tracked somewhere visible to leadership (a risk register or equivalent)
Data
- Data used in AI systems is classified by sensitivity
- There are controls on what data can be sent to external AI/SaaS providers
- Training data provenance and quality are considered for any internally built or fine-tuned models
- Data retention rules apply to AI system inputs and outputs, not just traditional records
Privacy
- AI use involving personal data has been reviewed against applicable privacy obligations
- Data subject rights (access, deletion, correction) are honored where AI systems process personal data
- Privacy review is a required step before new AI use cases involving personal data go live
Cybersecurity
- Identity and access management controls apply to AI systems and their administrative interfaces
- AI-specific risks (prompt injection, data poisoning, model manipulation) are part of the organization’s threat model
- Logging and monitoring cover AI system usage and outputs, not just infrastructure
- AI systems are included in the vulnerability management and patching process
- Security testing has been performed on AI applications, not assumed to be covered by general application security testing
Third Parties and Procurement
- Vendor security and privacy review includes specific questions about AI features
- Contracts with AI vendors address data usage, data residency, and liability
- New AI features added to existing vendor tools trigger a review, not just new tool purchases
- There’s a documented approval process before a new AI vendor or tool is adopted
Model and Application Security
- Access controls exist around who can modify, retrain, or reconfigure AI models
- Outputs from AI systems are validated before being used in decisions with real consequences
- Applications built on top of AI models follow standard secure development practices
- Known AI/LLM application risks (as described in resources like the OWASP LLM guidance) have been considered
Monitoring
- AI system performance and behavior are monitored on an ongoing basis, not just at launch
- There’s a process for detecting when an AI system’s risk profile changes (new use case, new data, vendor model update)
- Monitoring results are reviewed by someone with authority to act on them
Incident Response
- The incident response plan explicitly covers AI-related incidents
- Roles are clear for who investigates and responds to an AI-related incident
- There’s a defined process for taking an AI system offline quickly if needed
Compliance
- Applicable regulations (such as the EU AI Act, where in scope) have been assessed for relevance
- Compliance obligations are mapped to specific AI use cases, not assumed to apply generically
- Someone is responsible for tracking regulatory changes relevant to AI
Training
- Employees receive training on acceptable AI use and data handling
- Technical teams receive training on AI-specific security risks
- Leadership receives periodic briefings on the state of AI governance and risk
Lifecycle Management
- New AI use cases go through a defined approval process before deployment
- AI systems are reviewed periodically after deployment, not just at initial approval
- Changes to existing AI systems (model updates, new data sources, new integrations) trigger a governance review
- There’s a defined process for retiring AI systems that are no longer needed or approved
Using This Checklist
If most items in a category are “not in place,” that’s your starting point — not a failure. Very few organizations score well across every category on a first pass, including ones with mature IT and security programs, simply because AI governance is newer than most other governance disciplines. Prioritize the categories tied to your highest-risk AI use cases first, and revisit this checklist periodically as your AI governance program matures, as outlined in our main guide, AI Governance for Enterprises: A Practical Framework for IT, Cybersecurity, and Risk Leaders.
