AI Governance & Policy Quick-Start Checklist

An interactive, saveable checklist to establish and track core AI governance elements: roles, policies, model registry, review gates, logging, third-party model handling, monitoring, and next steps.

Interactive Tool

AI Governance & Policy Quick-Start Checklist

Use this checklist to capture your organization or team's core AI governance elements. Completing and saving this form creates a governance record you can review, share with stakeholders, and use to prioritize next steps.

The unit responsible for the AI system(s) (e.g., Marketing, Fraud Ops, Clinical Services).
Person responsible for governance coordination or the model owner.
Select roles that are already assigned for AI governance work.
Is there a documented acceptable-use policy for AI systems?
Are rules defined for data sourcing, labeling, retention, and access?
Has a privacy/PIA been performed where required?
Do you maintain a registry or inventory of models (including purpose, owner, version)?
Link or describe where the registry lives and how to access it. If none, leave blank.
Are formal review gates defined (design review, pre-deployment validation, security review)?
Are decisions, data inputs, and model versions logged to support audits?
How does your org handle models from external vendors or open-source sources?
Are specific triggers defined for when issues must be escalated (harm, bias, performance degradation, data breaches)?
Is production monitoring defined (data drift, model accuracy, fairness metrics)?
Is there a defined approach for retraining, version control, and deployment of model updates?
Are processes in place to detect and mitigate bias?
Are explainability or interpretability requirements documented for relevant use cases?
Are pre-deployment tests defined (unit tests, validation datasets, edge-case tests)?
Is model lineage and decision documentation maintained (training data, features, hyperparameters)?
How often governance reports are prepared for stakeholders?
Number of days audit logs and training metadata are retained. Enter a number.
How willing is your organization to accept residual AI risk? Use this to prioritize controls.
1.0 10.0
List 2–3 highest-priority actions to reduce governance gaps (owners & target dates).
Notes for policy writing, training, tooling, or integrations needed (e.g., model registry, monitoring).
You can explore this tool now. Sign in or create an account to save your responses and return to them later.
Make this tool part of your work

Save a personal copy, bring it to your team, or tailor the questions and workflow to fit what you are hungry to improve.

Member customization and team collaboration are coming soon.

Discussion

Comments and conversation will live here.