Tool · Governance checklist

Enterprise AI Governance Checklist

Forty controls in eight domains. Answer Yes, Partial or No; the score and maturity band update as you go, and the page prints as a document you can table at the next risk committee. Every control cites its source.

Scoring. Yes = 2, Partial = 1, No = 0. Each domain scores out of 10; the total is out of 80 and shown as a percentage. Bands: Foundational below 40%, Developing 40–69%, Established 70–89%, Assured 90% and above. The bands are our editorial scale, not a regulatory rating. Answers are kept only in your browser.

Without JavaScriptThe checklist still works on paper: print this page, mark each control, add 2 for Yes and 1 for Partial, and compare the total out of 80 with the bands above.

Overall

0%
Foundational

0 of 80 points · 0 of 40 answered

By domain

DomainScoreMeter
01 Accountability and policy0/10
02 Model inventory and lifecycle0/10
03 Data protection (CDPA and SI 155)0/10
04 Security and access control0/10
05 Vendors and third parties0/10
06 Human oversight and automated decisions0/10
07 Monitoring, audit trail and incidents0/10
08 Skills, culture and change0/10

01 · Accountability and policy

0 / 10
01 A board-approved AI policy exists and was reviewed within the last 12 months. Act s.24; RBZ PS 01-2024 para 7.2.8
02 A named executive is accountable for AI, with the responsibility in their objectives. RBZ PS 01-2024 para 8.4
03 An AI risk appetite statement says which decisions may be automated and which may not. RBZ PS 01-2024 section 2.9
04 Every AI use case is classified by impact (customer-affecting, employee-affecting, operational, internal) before build. NIST AI RMF 1.0, Map function
05 The board or its risk committee receives an AI and model report at least quarterly: register changes, incidents, validation findings. RBZ PS 02-2023 para 2.1.5

02 · Model inventory and lifecycle

0 / 10
06 A complete model register exists, including vendor-embedded and hosted models, with owner, purpose, data, hosting location and materiality. RBZ PS 02-2023 Definitions (model register/inventory)
07 Material models are identified and receive board-level oversight. RBZ PS 02-2023 paras 2.1.3–2.1.4
08 Material models are independently validated before production and re-validated on change. RBZ PS 02-2023 paras 2.4.5, 2.4.17
09 Models, prompts and retrieval indexes are version-pinned under change control with a model log. RBZ PS 02-2023 Definitions (model log)
10 A retirement procedure covers model decommissioning and deletion of associated data and indexes. Act s.13 (retention no longer than necessary)

03 · Data protection (CDPA and SI 155)

0 / 10
11 The organisation holds a data controller licence in the correct tier and renews at least three months before expiry. SI 155 s.4–6
12 A Data Protection Officer is appointed, certified and notified on Form DP2, with continuing professional development funded. SI 155 s.10(1), s.12–13
13 Processing activities, including AI systems, are notified to the Data Protection Authority. SI 155 s.10(2)(a); Act s.20
14 Personal data is classified at ingestion; sensitive, genetic, biometric and health data are processed only with written consent; biometric processing is notified. Act s.11–12; SI 155 s.10(2)(d)
15 Cross-border transfers are assessed for adequacy, a legal basis is documented, the Authority is notified, and processors are under written contract. Act s.18(8), s.28–29; SI 155 s.10(2)(c), s.10(4)(f)

04 · Security and access control

0 / 10
16 All model calls pass through a gateway the organisation operates; no application holds a vendor API key. Act s.18(4); RBZ Guideline para 6.4
17 Retrieval enforces the requesting identity's entitlements; the model never decides access. Act s.18; RBZ Guideline access-management requirements
18 Prompt-injection and output-handling controls are in place: no shell or raw-SQL tools, parameterised tools, screened retrieved content. OWASP Top 10 for LLM Applications 2025 (LLM01, LLM05)
19 Secrets, logs and indexes are encrypted in transit and at rest; administrative access is nominative with multi-factor authentication. RBZ Guideline para 6.4 (core security controls); SI 155 s.16
20 The AI surface is included in the annual penetration test and findings are tracked to closure. RBZ Guideline section 4 (testing), para 6.4

05 · Vendors and third parties

0 / 10
21 A due-diligence file exists for every AI vendor: security policies, certifications, sub-processors, data handling. RBZ Guideline para 5.3; Act s.18(7)
22 Contracts include audit rights, data segregation, portability, exit arrangements and incident cooperation. RBZ Guideline para 5.6; Act s.18(8)
23 Vendor licensing and international sanctions screening is completed and recorded. RBZ Guideline para 6.4(b)
24 A current third-party inventory exists and substitutability of critical AI providers is assessed. RBZ Guideline paras 5.7, 5.14
25 For banking institutions: the Reserve Bank was informed early of cloud outsourcing of critical functions and prior written approval was obtained before go-live. RBZ Guideline paras 5.12, 6.4(a)

06 · Human oversight and automated decisions

0 / 10
26 An inventory of decisions with legal or similarly significant effects exists, and none is taken solely by automated processing without consent or a legal basis. Act s.25; SI 155 s.10(3)
27 A human route to contest an automated outcome exists and is communicated to data subjects. Act s.14, s.25
28 Agent tools are classified read, propose or write; write actions require a named human approval enforced in the tool gateway. RBZ Guideline para 6.4(c) (evidence of approvals and audit trails)
29 Children's data is never subject to automated decision-making that affects their rights. SI 155 s.10(5)(f)
30 Customer-facing notices disclose AI use and purposes at the point of collection. Act s.15

07 · Monitoring, audit trail and incidents

0 / 10
31 Prompts, retrieved record identifiers, tool calls and outputs are logged with the initiating identity and retained under access control. Act s.14; RBZ PS 01-2024 para 7.2.8
32 Drift, quality and bias are monitored with thresholds and named owners. RBZ PS 01-2024 paras 7.2.7–7.2.8
33 The breach path has been tested by drill: 24 hours to the Authority on Form DP3, 72 hours to affected people where high-risk, and 3 hours to the Reserve Bank for regulated institutions. Act s.19; SI 155 s.17(1)–(3); RBZ Guideline para 4.30
34 A breach register is maintained and the organisation can answer information requests within 14 days and report within 21 days. SI 155 s.17(4)–(5)
35 AI incidents feed the operational risk event database and board reporting. RBZ PS 01-2024 section 7.3

08 · Skills, culture and change

0 / 10
36 The board and executive received an AI briefing within the last 12 months. RBZ Guideline para 7.1
37 An acceptable-use standard tells staff which AI tools are approved and which data may never be entered. SI 155 s.16(2)(b)
38 Role-based training is in place for model owners, validators, the DPO and the CISO. RBZ Guideline section 7; SI 155 s.13(2)
39 The whistleblowing or concern route explicitly covers AI misuse. Act s.31
40 An annual governance review is scheduled and changes in law and regulator guidance are tracked. Act s.18(6) (Authority may issue standards)

MethodControls were derived from the eight domains on the governance page. Citations refer to the Data Protection Act, Act 5 of 2021 (cited in regulations as the Cyber and Data Protection Act [Chapter 12:07]), Statutory Instrument 155 of 2024, RBZ Prudential Standards No. 01-2024/BSD and No. 02-2023/BSD, the RBZ Cybersecurity and Resilience Guideline (August 2025), NIST AI RMF 1.0 and the OWASP Top 10 for LLM Applications 2025. Non-bank organisations should read RBZ items as good practice. Last reviewed September 2026.