This checklist turns AI governance into working evidence. It is not certification or legal advice. Adapt depth to impact, jurisdiction and whether the organization develops, provides or deploys the system.

Discovery and purpose

  • document the problem, user and intended outcome;
  • consider non-AI alternatives;
  • define prohibited and out-of-scope uses;
  • include potentially affected people;
  • name product and decision owners.

Data, model and vendor

  • verify data origin, rights, quality and retention;
  • minimize personal and confidential data;
  • record model, version, vendor and region;
  • assess training use and subprocessors;
  • plan for replacement, outage and vendor exit.

Risk, launch and operations

Add the system to the AI inventory, classify impact and reversibility, test normal and adversarial cases, set thresholds before testing, match approval to risk, provide meaningful human oversight, test rollback and incidents, version material changes and assign a review date.

Use the AI governance guide for the full operating system and the risk matrix for initial triage.

[ PRACTICAL RESOURCES ]

Use these resources

[ CONTINUE EXPLORING ]

AI Governance

Turn responsible AI principles into operational decisions, controls and evidence.

Primary sources