Skip to content
AIRAS Cloud

Resource

Enterprise AI governance checklist

Forty practical checks across the full lifecycle. If you cannot answer one of them with a record rather than an opinion, that is where the work is.

1. Inventory and ownership

  • Every AI system, model, agent and vendor feature is registered
  • Embedded AI inside purchased tools is captured, not assumed
  • Each entry has a named business owner
  • Each entry has a named technical owner
  • Lifecycle stage is recorded and current
  • Shadow AI has a route to disclosure without penalty

2. Intake and screening

  • Intake captures purpose, population affected and data categories
  • Autonomy and human-oversight design are captured explicitly
  • Prohibited-use screening happens before assessment
  • Supplier position in the value chain is determined
  • Questions adapt to context rather than a fixed long form

3. Risk assessment

  • Criteria are published, versioned and human-approved
  • Scoring is deterministic and reproducible
  • Mandatory floors cannot be argued away
  • The explanation trace is readable by a non-specialist
  • Inputs and ruleset version are stored immutably
  • Reassessment triggers are defined at assessment time

4. Controls and evidence

  • Applicable controls derive from assessed context, not a fixed list
  • Each control has an owner and a due date
  • Evidence artefacts are attached to the control, not emailed
  • Evidence integrity is verifiable
  • Completeness is visible, including what is missing
  • Overdue controls escalate to a named person

5. Review and decision

  • Review routing depends on assessed risk
  • The reviewer is independent of the assessor
  • Approval with conditions is a first-class outcome
  • Rationale is mandatory, including for approvals
  • Decisions are versioned against the record state
  • Refusals and withdrawals are retained, not deleted

6. Monitoring and change

  • Production signals are linked to the governed record
  • Incidents attach to the entry they concern
  • Material change is defined, not left to judgement alone
  • Model, prompt or scope change triggers reassessment
  • Agent scope and permission changes are governed
  • Periodic reassessment is scheduled and enforced

7. Audit and reporting

  • History is append-only and cannot be silently edited
  • Every record exports as a coherent evidence pack
  • Board reporting draws from the same source as operations
  • Access to records is role-based and logged
  • An external reviewer can be given scoped access

Using this checklist

Score each line as evidenced, partial or absent. The pattern usually matters more than the total: organisations tend to be strong on policy and intake and weak on evidence integrity, independence of review and reassessment after change.

This checklist is general guidance, not legal advice, and is not a compliance certification against any framework.

Close the gaps the checklist exposes

Bring your scored checklist to an executive briefing and we will map each gap to the mechanism that closes it.

No pricing commitment. No confidential information required.