WORKING CHECKLIST

AI governance checklist.

Use this as a starting conversation, not a pass-or-fail certification. A “yes” should be supported by evidence and should remain proportionate to the risk.

Published by Mise · Last reviewed 17 July 2026 · General information, not legal advice

Ownership and purpose

  • Each material AI use has a named organisational owner.
  • The intended purpose, users and affected people are recorded in plain language.
  • There is a clear approval route for introducing or materially changing an AI use.
  • People know who can pause or stop a use when concerns arise.

Inventory and classification

  • The organisation can identify material AI systems, embedded features and informal tools in use.
  • Each material use records the supplier, model or service where known.
  • Higher-impact uses receive more scrutiny than routine, reversible uses.
  • The inventory is reviewed when suppliers or workflows change.

People, impact and fairness

  • The organisation understands who may be affected if an output is wrong, biased or misleading.
  • People can obtain human review where the context requires it.
  • Accessibility and the needs of potentially vulnerable people have been considered.
  • Complaints, challenges and overrides can be recorded and learned from.

Data and privacy

  • Staff know what information must not be entered into unapproved AI tools.
  • Data purpose, minimisation, access, retention and deletion are considered for each material use.
  • Supplier terms are checked against actual intended data use.
  • Data-protection assessment is completed where required.

Supplier and technical dependency

  • The organisation understands what the supplier may change without notice.
  • Security, availability, subcontractors and data location have been considered where relevant.
  • There is a fallback when the system is unavailable or unsuitable.
  • Exit, deletion and record-retention needs are understood.

Human oversight and quality

  • Reviewers have enough time, information and authority to challenge an output.
  • The organisation has tested the use against realistic examples before relying on it.
  • Known limits and prohibited uses are communicated to users.
  • Performance or error patterns are monitored in proportion to impact.

Evidence and reporting

  • Important decisions, approvals and changes are recorded.
  • The organisation can explain which claims are evidenced and which remain assumptions.
  • Incidents and near misses have an escalation and learning route.
  • Leadership receives information suited to the decisions it must make.

How to use the result

Mark each item evidenced, partly evidenced, not evidenced or not applicable, with a reason. Prioritise by potential impact and dependency rather than counting ticks. A missing owner or unknown data flow may need attention before a long policy rewrite.

This checklist is intentionally general. Applicable law, regulation, contracts and sector guidance may create additional requirements.

For a structured examination of the evidence, see the Mise AI governance audit.