A free, 14-item self-scored readiness checklist across NIST AI RMF — Govern, Map, Measure, and Manage — mapped to ISO/IEC 42001 and US supervisory expectations. Score yourself in about ten minutes and see exactly where your AI governance stands before an examiner, a board, or a procurement team asks.
No score is sent anywhere. You score yourself; we send you the checklist to keep.
This is a self-assessment, not an audit and not a certification. It walks you through 14 concrete questions across the four NIST AI RMF functions, each tagged with the ISO/IEC 42001 clause and the US supervisory expectation it lines up with, so you know which questions an examiner, a board, or a procurement team is most likely to press on.
Mapped to ISO/IEC 42001 and US supervisory expectations (SR 26-2 model risk, which replaced SR 11-7, plus third-party risk, fair lending, and UDAP/UDAAP). Roughly ten minutes to complete.
The checklist walks the four functions of the NIST AI Risk Management Framework and asks for evidence, not intentions. Fourteen concrete items, each tagged with the ISO/IEC 42001 clause and the US supervisory expectation it lines up with, so you know which questions an examiner, a board, or a procurement team is most likely to press on. Roughly four items sit under each function.
Who owns AI governance, what the policy says, which roles are defined, and whether every AI and GenAI system is in a current inventory with a named owner. The program layer that makes everything else auditable.
What each system does, who it affects, and how risk is tiered, plus the third-party and vendor AI dependencies behind it. The context layer that decides how much scrutiny each system warrants.
How each system is tested, monitored, and reviewed for fairness, and whether the documentation an auditor would ask for actually exists. The evidence layer where most AI programs come up short.
How risks are prioritized and responded to, how change to AI systems is controlled, and whether there is a path for handling an AI incident when one happens. The response layer that proves the program runs.
This checklist is for financial services: banks, captive finance arms, and fintechs, and specifically the compliance, risk, and model-risk-management people who answer to examiners, a board, or enterprise procurement. If you run Microsoft 365 Copilot, Azure OpenAI, or in-house models and someone has started asking how that AI is governed, it gives you a fast, honest read on where you stand before the conversation gets formal. It is not a generic template. Each item is framed against the supervisory expectations a US financial institution is actually held to, so a compliance lead can hand it to a model-risk owner and a procurement reviewer and have all three reading the same page.
Readiness is not about having every control perfect. It is about whether each item has evidence an examiner could review, and knowing which gap to close first.
The checklist ties its items back to the NIST AI RMF functions and, for financial services, to SR 26-2 (which replaced SR 11-7) and the other supervisory expectations examiners apply. The right-hand column is what to have ready in an audit.
| Framework / supervisory anchor | What to evidence in an audit |
|---|---|
| NIST AI RMF (Govern) | A current AI inventory with named owners, an approved AI policy, and defined roles, so accountability for every system is documented rather than assumed. |
| NIST AI RMF (Map / Measure / Manage) | Risk-tiering for each use case, test and monitoring records including fairness review, and a documented risk-response and incident path tied to each system. |
| SR 26-2 (model risk) | AI and ML models treated as models: inventory, tiering, development and validation documentation, and ongoing monitoring evidence, adapted for non-deterministic systems. |
| Third-party / vendor risk | Due-diligence and monitoring records for AI vendors and model providers, with vendor certificates evaluated as inputs, never inherited as your own controls. |
| Fair lending (ECOA / Reg B) | Where AI touches credit, bias and disparate-impact testing, adverse-action evidence, and documentation a supervisor can review. |
| ISO/IEC 42001 | AI management system clauses crosswalked onto controls you already evidence, the recognized standard procurement and board reviewers increasingly ask for. |
A score is a starting point, not a verdict. If the checklist surfaces gaps you want help closing, the AI Governance Readiness engagement turns it into a defensible inventory, a gap assessment, and a 90-day roadmap.
The AI Governance Audit-Readiness Checklist is a self-scored readiness aid, not an audit, an attestation, or a certification. DSE is not an accredited certification body and does not issue ISO/IEC 42001 certificates or certify EU AI Act or NIST AI RMF compliance.
Completing the checklist does not guarantee passing an audit or avoiding enforcement, and it is not legal advice. Where it describes "mapping to" NIST AI RMF, ISO/IEC 42001, or US supervisory expectations, that means advisory alignment, not certification. For a scoped engagement, all work is governed by a signed SOW / MSA.