Ownership and purpose
- Each material AI use has a named organisational owner.
- The intended purpose, users and affected people are recorded in plain language.
- There is a clear approval route for introducing or materially changing an AI use.
- People know who can pause or stop a use when concerns arise.
Inventory and classification
- The organisation can identify material AI systems, embedded features and informal tools in use.
- Each material use records the supplier, model or service where known.
- Higher-impact uses receive more scrutiny than routine, reversible uses.
- The inventory is reviewed when suppliers or workflows change.
People, impact and fairness
- The organisation understands who may be affected if an output is wrong, biased or misleading.
- People can obtain human review where the context requires it.
- Accessibility and the needs of potentially vulnerable people have been considered.
- Complaints, challenges and overrides can be recorded and learned from.
Data and privacy
- Staff know what information must not be entered into unapproved AI tools.
- Data purpose, minimisation, access, retention and deletion are considered for each material use.
- Supplier terms are checked against actual intended data use.
- Data-protection assessment is completed where required.
Supplier and technical dependency
- The organisation understands what the supplier may change without notice.
- Security, availability, subcontractors and data location have been considered where relevant.
- There is a fallback when the system is unavailable or unsuitable.
- Exit, deletion and record-retention needs are understood.
Human oversight and quality
- Reviewers have enough time, information and authority to challenge an output.
- The organisation has tested the use against realistic examples before relying on it.
- Known limits and prohibited uses are communicated to users.
- Performance or error patterns are monitored in proportion to impact.
Evidence and reporting
- Important decisions, approvals and changes are recorded.
- The organisation can explain which claims are evidenced and which remain assumptions.
- Incidents and near misses have an escalation and learning route.
- Leadership receives information suited to the decisions it must make.
How to use the result
Mark each item evidenced, partly evidenced, not evidenced or not applicable, with a reason. Prioritise by potential impact and dependency rather than counting ticks. A missing owner or unknown data flow may need attention before a long policy rewrite.
For a structured examination of the evidence, see the Mise AI governance audit.