AI Governance Checklist: A 90-Day Implementation Sequence
Deploying artificial intelligence responsibly requires moving beyond ad hoc reviews to a systematic chain of oversight. This AI governance checklist provides an operational ninety-day roadmap for organizations establishing baseline oversight for both developed models and third-party tools. Structured across distinct chronological stages, each phase delivers a tangible administrative or technical artefact to ensure that AI usage aligns with compliance, risk posture, and organizational accountability.
Days 1 to 15: Discovery and AI Systems Inventory
The initial phase centers on mapping every deployed, piloted, and planned artificial intelligence capability across the organization. Teams often rely on shadow AI tools, embedded vendor features, or isolated analytical scripts that operate outside formal procurement and IT channels. Governance cannot evaluate what is not recorded; therefore, discovery requires interdepartmental inquiries across engineering, marketing, human resources, and operations.
The objective of this stage is to catalog each system alongside its primary purpose, data dependencies, hosting environment, and business owner. Capturing whether a system relies on external API integrations or internally trained architectures establishes the technical boundaries required for subsequent scrutiny. This visibility prevents governance efforts from becoming theoretical exercises disconnected from actual operational deployments.
- Artefact Produced: AI Use Case Register (System ID, business owner, operational purpose, model type, hosting infrastructure, and third-party vendor dependencies).
- Key Action: Conduct cross-departmental discovery interviews and review software procurement logs to uncover unmanaged AI tools.
- Key Action: Record input data categories, highlighting sensitive personal data, proprietary source code, or confidential operational files.
Days 16 to 30: Legal Scoping and Risk Classification
Once the inventory is compiled, the organization must classify each use case by its potential impact on fundamental rights, operational resilience, and regulatory exposure. In Brazil, teams must align their categorization models with the principles established by the LGPD and monitor the evolving parameters of draft bill PL 2338/2023, which outlines specific risk categorizations for automated systems. Voluntary international frameworks like ISO/IEC 42001 also offer structural guidance on evaluating contextual impact without imposing legal mandates.
Each logged use case must be mapped against explicit thresholds: does the model inform automated decisions that affect individuals, process personal information, or influence critical business processes? This assessment categorizes systems into distinct management tiers, ensuring that low-risk administrative utilities do not receive the same bureaucratic overhead as high-impact algorithmic decision engines.
- Artefact Produced: Risk Tiering Matrix and Obligations Log (Documented risk classification per system, mapped against LGPD, intellectual property guidelines, and emerging regulatory requirements).
- Key Action: Establish classification criteria based on human impact, autonomy level, and reversibility of decisions.
- Key Action: Assign an initial risk tier (Low, Medium, High) to every entry in the AI Use Case Register.
Days 31 to 60: Control Definition and Technical Verification
A risk tier is only useful if it dictates specific operational controls. During this month-long block, the organization specifies baseline controls for each tier and validates whether technical systems meet minimum standards. For third-party software, controls focus on vendor terms of service, data retention clauses, opt-out mechanisms for model training, and access restrictions. For proprietary developments, controls extend to dataset documentation, versioning, drift detection, and bias testing.
Teams must establish verifiable evidence requirements for every assigned control. Stating that a system is safe or transparent is insufficient; the governance structure requires documentary proof, such as data processing agreements, technical evaluations, human review logs, and system parameter sheets. Linking every control directly to a tangible record transforms abstract policy into defensible operational compliance.
- Artefact Produced: Control Implementation Baseline (Documented controls mapped to obligations, along with designated evidence types and verification cadences).
- Key Action: Formulate technical checklists for proprietary models (training provenance, validation metrics, explainability thresholds).
- Key Action: Institute procurement checklists for third-party AI tools (vendor training rights, data residency, API logging).
Days 61 to 75: Intake Workflows and Formal Decision Gates
Governance becomes sustainable only when new initiatives pass through an established intake and review gateway prior to production deployment. This stage defines the intake protocol for teams requesting new AI tools or developing custom features. The process must formalize handoffs between business requesters, security, legal counsel, and technical reviewers, avoiding bottlenecking through clear evaluation criteria.
The gate must produce a clear decision: approval, conditional approval with mandated mitigations, or rejection. A conditional approval must specify which controls must be implemented and verified before full production release. Logging these decisions creates an institutional record of who accepted specific residual risks, when the review occurred, and what conditions were established.
- Artefact Produced: AI Intake and Evaluation Procedure (A formal operating standard specifying the intake form, review committee roles, approval criteria, and signed decision records).
- Key Action: Define clear handoff triggers between business requesters, information security, and legal teams.
- Key Action: Implement structured decision records that archive the rationale, caveats, and designated sign-offs for each approved system.
Days 76 to 90: Governance Cadence, Audit Trails, and Operating Charter
The final fortnight of the initial sequence anchors long-term sustainability by establishing review frequencies and operational responsibilities. Artificial intelligence systems degrade, models drift, and external regulatory landscapes shift; therefore, oversight cannot terminate at procurement or deployment. An operating charter defines the ongoing obligations of system owners, internal auditors, and risk officers.
During this phase, the team consolidates all preceding steps into a structured governance dossier. The dossier connects the entire operational chain: the recorded use case, its statutory and organizational obligations, identified risks, enforced controls, verified evidentiary records, logged decisions, and the mandatory schedule for periodic review. This closed loop ensures continuous compliance and audit readiness.
- Artefact Produced: AI Governance Operating Charter and Audit Dossier (Consolidated operational documentation detailing roles, periodic review schedules, incident response protocols, and auditable governance logs).
- Key Action: Schedule mandatory reassessment intervals based on risk tier (e.g., quarterly reviews for high-impact systems).
- Key Action: Conduct a pilot review of one production system using the newly finalized audit dossier structure.
Frequently asked questions
How does this AI governance checklist accommodate both built and purchased tools?
The framework utilizes the same sequence of use case mapping, risk classification, and decision logging for all systems. The operational difference lies in the control tier: internally built models require controls over training data, model validation, and code repositories, whereas purchased tools require controls focused on vendor contracts, third-party data usage terms, and access configurations.
What role does Brazilian legislative context play in the initial ninety days?
Brazilian organizations must anchor their governance to existing frameworks like the LGPD while monitoring the draft bill PL 2338/2023 currently under legislative consideration. Addressing these principles during the first ninety days ensures that risk classifications and transparency controls are structurally aligned with emerging regulatory standards.
Is adoption of ISO/IEC 42001 mandatory to execute this checklist?
No, ISO/IEC 42001 is a voluntary international management system standard, not a statutory requirement. Organizations can use its clauses as reference architecture for structured controls and policies without pursuing formal third-party certification.
Who should be responsible for maintaining the artefacts produced during this process?
Artefact ownership should be distributed across an interdisciplinary structure rather than siloed in IT. Business units own their specific system entries, legal and compliance teams validate the risk classifications and obligations, and technical teams supply operational control evidence, all coordinated under an appointed governance lead.