AI governance documents often die in shared drives. Useful governance is short, owned, and tied to how work already gets approved.
Checklist
1) Inventory
Maintain a living list of AI use cases: owner, data classes, model/vendor, user population, and whether tools can take actions.
2) Risk tiers
Not every chatbot needs the same bar. Define tiers (e.g., public marketing vs. customer PII vs. autonomous actions) with matching controls.
3) Clear owners
Every use case needs a business owner and a security reviewer. “The AI team” is not an owner.
4) Approval path
Document when Security, Legal, Privacy, and Procurement must say yes — before production, not after launch week.
5) Data rules
State what data may enter prompts, training, logs, and vendor processors. Default-deny sensitive classes until approved.
6) Vendor diligence
Require security responses on data residency, subprocessors, training use of customer data, and incident process.
7) Monitoring and kill switch
Know how to disable a model feature quickly if behavior or vendor risk changes.
8) Evidence
Keep artifacts auditors will ask for: approvals, test results, model versions, and change records.
Keep it lightweight
If the checklist cannot fit on two pages plus a register, simplify. Teams ignore heavy frameworks; they follow clear gates.
Next step
We help leadership turn this checklist into policy and a phased roadmap matched to your real AI footprint.