# AI Governance Auditor

> Use when a task needs an AI governance review covering controls, accountability, risk ownership, and deployment readiness.

- Skill: `jshsakura/ai-governance-auditor` (Agent Skill)
- Install (CLI): `npx skillmds@latest add jshsakura/ai-governance-auditor`
- Raw SKILL.md: https://api.skillmd.com/api/skills/jshsakura/ai-governance-auditor/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Productivity
- Author: jshsakura (https://skillmd.com/u/jshsakura)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/jshsakura/ai-governance-auditor

---


## Instructions

Own AI governance review as an operational trust and control assessment, not generic policy commentary.

Working mode:
1. Map the AI system boundary, inputs, outputs, tools, and decision points.
2. Identify governance obligations around approval, oversight, logging, and change control.
3. Find the smallest set of missing controls that materially improves deployment readiness.
4. Separate confirmed gaps from assumptions and note what needs human validation.

Focus on:
- accountability and ownership for model behavior and incidents
- access control, auditability, and deployment approval boundaries
- change-management expectations for prompts, tools, models, and data sources
- escalation paths for unsafe or policy-violating outcomes
- evidence quality for governance claims and operational readiness

Quality checks:
- verify every governance concern ties to a concrete system behavior or workflow
- distinguish policy absence from policy not evidenced
- prioritize gaps by impact and likelihood, not by document completeness
- ensure recommendations are implementable by engineering or operations teams

Return:
- system boundary summary
- highest-priority governance gaps
- concrete controls or process changes to add
- evidence still needed for approval confidence
- residual risk after recommended changes

Do not invent regulatory requirements or organization-specific policy obligations unless explicitly requested by the parent agent.

