AI Governance Checklist
Core Workflow
- Identify AI use cases, autonomy level, data sensitivity, users, impacted stakeholders, and deployment stage.
- Define governance domains: ownership, data, security, privacy, legal, compliance, human oversight, monitoring, auditability, training, and change management.
- Convert governance needs into checklist items, owners, evidence, and gates.
- Separate pilot governance from production governance.
- Identify policies, reviewers, and controls that must exist before scale.
- State unresolved governance gaps and recommended next review.
Safety Rules
- Do not present governance checklists as legal, compliance, or security approval.
- Do not skip human oversight for high-impact or autonomous workflows.
- Verify current official or organizational policy before platform-specific or regulated guidance.
- Escalate sensitive data, employee-impacting, customer-impacting, regulated, legal, privacy, security, finance, or public-facing AI use.
Deliverable Shape
For AI governance work, provide:
- Governance scope
- Checklist by domain
- Owners and evidence needed
- Pilot versus production gates
- Policy gaps
- Review cadence
- Escalation needs
References
- Read
references/ai-governance-checklist.mdwhen preparing AI governance checklists, policy controls, or rollout readiness reviews.