Practical AI governance checklist
A structured starting point for inventory, risk classification, responsibilities and evidence.
Inventory
- Record every AI system with purpose, provider, model and deployment
- Document business and technical ownership
- Capture countries, user groups and data categories
Risk and oversight
- Justify and periodically review the risk class
- Document human oversight and escalation paths
- Obtain legal review for prohibited or particularly sensitive uses
Technical documentation
- Document versions, limitations and intended use
- Define logging, monitoring and incident handling
- Test data quality, robustness and cybersecurity with evidence
Operations
- Maintain approvals and review dates
- Reassess material changes
- Store tenant-specific evidence with traceability
This guide is for orientation. It is not a certification, legal advice or a guarantee of compliance.