Tool · Governance checklist
Enterprise AI Governance Checklist
Forty controls in eight domains. Answer Yes, Partial or No; the score and maturity band update as you go, and the page prints as a document you can table at the next risk committee. Every control cites its source.
Scoring. Yes = 2, Partial = 1, No = 0. Each domain scores out of 10; the total is out of 80 and shown as a percentage. Bands: Foundational below 40%, Developing 40–69%, Established 70–89%, Assured 90% and above. The bands are our editorial scale, not a regulatory rating. Answers are kept only in your browser.
Without JavaScriptThe checklist still works on paper: print this page, mark each control, add 2 for Yes and 1 for Partial, and compare the total out of 80 with the bands above.
Overall
By domain
| Domain | Score | Meter |
|---|---|---|
| 01 Accountability and policy | 0/10 | |
| 02 Model inventory and lifecycle | 0/10 | |
| 03 Data protection (CDPA and SI 155) | 0/10 | |
| 04 Security and access control | 0/10 | |
| 05 Vendors and third parties | 0/10 | |
| 06 Human oversight and automated decisions | 0/10 | |
| 07 Monitoring, audit trail and incidents | 0/10 | |
| 08 Skills, culture and change | 0/10 |
MethodControls were derived from the eight domains on the governance page. Citations refer to the Data Protection Act, Act 5 of 2021 (cited in regulations as the Cyber and Data Protection Act [Chapter 12:07]), Statutory Instrument 155 of 2024, RBZ Prudential Standards No. 01-2024/BSD and No. 02-2023/BSD, the RBZ Cybersecurity and Resilience Guideline (August 2025), NIST AI RMF 1.0 and the OWASP Top 10 for LLM Applications 2025. Non-bank organisations should read RBZ items as good practice. Last reviewed September 2026.