Governance should tell a team who can release an AI system, under what evidence, and what happens when it fails.
This checklist gives mid-market teams a workable control set for one AI system. It is designed to turn broad principles into owners, boundaries, tests, records, release gates, monitoring, and response actions.
Complete this for a named system and workflow—not for “AI” in general.
Name the system, owner, users, workflow, data, and decisions in scope.
Mark only controls that exist and can be demonstrated with evidence.
Assign every incomplete item to an owner and due date outside this page.
Stop release when a blocking gate remains unresolved.
Repeat the review after material model, data, workflow, vendor, or authority changes.
Local-only worksheet
Checkbox selections are not submitted or stored and reset when the page reloads. Print or save the completed page if you need a working copy.
This operational checklist is not legal, regulatory, security, privacy, clinical, financial, or compliance advice. Qualified owners must apply requirements specific to the organization and use case.
Blocking release gates
Do not release while a foundational control is unresolved.
Blocker
Why it stops release
Minimum resolution
No accountable owner
No one can accept the operating result or coordinate a response
Name business, technical, data, evaluation, and required domain owners
Unclear authority
The system may influence or take actions beyond its approved role
Document and enforce allowed, reviewed, and prohibited decisions and actions
Unresolved rights or access
Data, sources, outputs, or users may be handled without an approved basis
Resolve access, purpose, retention, permission, and contractual requirements
No representative evaluation
A curated demo cannot establish performance across real and high-risk cases
Run a versioned test set with slice-level gates and authorized review
Unsafe failure mode
Errors, outages, or adversarial input can create uncontrolled consequences
Implement abstention, escalation, containment, degraded operation, and rollback
No monitoring or response
The team cannot detect degradation or act when production differs from the pilot
Instrument material risks and assign responders with stop authority
Minimum evidence package
Keep a small set of living artifacts instead of a ceremonial policy binder.
After a serious failure: contain, preserve evidence, assess impact, communicate appropriately, correct, and add regression coverage
At least when risk or context changes: re-evaluate scope, authority, data, reviewers, thresholds, and continued business value
Proportionality rule
A low-consequence internal drafting aid and a system influencing employment, health, finance, safety, public services, or customer rights should not share the same evidence burden or release authority.
Apply the checklist
Turn incomplete controls into an owned implementation plan.
Use the AI Readiness Framework to confirm the initiative has operational value, then use this checklist with system-specific security, privacy, legal, compliance, risk, and domain requirements.