§ Free download·self-scored · ~10 minutes

AI Governance Audit-Readiness Checklist.

A free, 14-item self-scored readiness checklist across NIST AI RMF — Govern, Map, Measure, and Manage — mapped to ISO/IEC 42001 and US supervisory expectations. Score yourself in about ten minutes and see exactly where your AI governance stands before an examiner, a board, or a procurement team asks.

No score is sent anywhere. You score yourself; we send you the checklist to keep.

What's inside

14 items. Four functions. One honest read.

This is a self-assessment, not an audit and not a certification. It walks you through 14 concrete questions across the four NIST AI RMF functions, each tagged with the ISO/IEC 42001 clause and the US supervisory expectation it lines up with, so you know which questions an examiner, a board, or a procurement team is most likely to press on.

  • Govern — accountability, policy, roles, and AI inventory ownership.
  • Map — use-case context, risk tiering, and third-party AI dependencies.
  • Measure — testing, monitoring, fairness, and documentation evidence.
  • Manage — risk response, change management, and incident handling.

Mapped to ISO/IEC 42001 and US supervisory expectations (SR 26-2 model risk, which replaced SR 11-7, plus third-party risk, fair lending, and UDAP/UDAAP). Roughly ten minutes to complete.

Get the checklist

Email it to me.

No spam. Unsubscribe anytime. The checklist is a self-assessment, not a certification.

§ What it covers·four functions · 14 items

The four NIST AI RMF functions, scored in plain English.

The checklist walks the four functions of the NIST AI Risk Management Framework and asks for evidence, not intentions. Fourteen concrete items, each tagged with the ISO/IEC 42001 clause and the US supervisory expectation it lines up with, so you know which questions an examiner, a board, or a procurement team is most likely to press on. Roughly four items sit under each function.

Function 01 · Govern

Accountability and the program

Who owns AI governance, what the policy says, which roles are defined, and whether every AI and GenAI system is in a current inventory with a named owner. The program layer that makes everything else auditable.

Evidence: AI inventory · policy · named owner
Function 02 · Map

Context and risk tiering

What each system does, who it affects, and how risk is tiered, plus the third-party and vendor AI dependencies behind it. The context layer that decides how much scrutiny each system warrants.

Evidence: use-case register · risk tiers · vendor list
Function 03 · Measure

Testing and documentation

How each system is tested, monitored, and reviewed for fairness, and whether the documentation an auditor would ask for actually exists. The evidence layer where most AI programs come up short.

Evidence: test records · monitoring · fairness review
Function 04 · Manage

Response and incidents

How risks are prioritized and responded to, how change to AI systems is controlled, and whether there is a path for handling an AI incident when one happens. The response layer that proves the program runs.

Evidence: risk response · change control · incident path
§ Who it is for·financial services

Built for banks, fintechs, and model-risk teams.

This checklist is for financial services: banks, captive finance arms, and fintechs, and specifically the compliance, risk, and model-risk-management people who answer to examiners, a board, or enterprise procurement. If you run Microsoft 365 Copilot, Azure OpenAI, or in-house models and someone has started asking how that AI is governed, it gives you a fast, honest read on where you stand before the conversation gets formal. It is not a generic template. Each item is framed against the supervisory expectations a US financial institution is actually held to, so a compliance lead can hand it to a model-risk owner and a procurement reviewer and have all three reading the same page.

§ The honest read·ready vs not ready

What ready looks like, and what it doesn't.

Readiness is not about having every control perfect. It is about whether each item has evidence an examiner could review, and knowing which gap to close first.

Ready
  • A current AI inventory with named owners for every system in production.
  • Documented risk tiers that match how each system is actually used.
  • Test, monitoring, and fairness records, especially where AI touches credit.
  • A control crosswalk that layers AI governance onto your existing SOC 2 or ISO 27001.
  • A defined incident path and a change-control process for AI systems.
Not ready
  • AI already in production with no inventory and no named owner.
  • No risk tiering, so a high-impact model gets the same attention as a low-risk one.
  • No bias or fair-lending testing where AI informs a credit decision.
  • Vendor certificates treated as your own controls instead of an input to assess.
  • No documentation trail, so the evidence exists only in someone's head.
§ Mapped to your supervisors·NIST AI RMF · SR 26-2

Each item maps to a framework and a supervisory expectation.

The checklist ties its items back to the NIST AI RMF functions and, for financial services, to SR 26-2 (which replaced SR 11-7) and the other supervisory expectations examiners apply. The right-hand column is what to have ready in an audit.

Framework / supervisory anchorWhat to evidence in an audit
NIST AI RMF (Govern)A current AI inventory with named owners, an approved AI policy, and defined roles, so accountability for every system is documented rather than assumed.
NIST AI RMF (Map / Measure / Manage)Risk-tiering for each use case, test and monitoring records including fairness review, and a documented risk-response and incident path tied to each system.
SR 26-2 (model risk)AI and ML models treated as models: inventory, tiering, development and validation documentation, and ongoing monitoring evidence, adapted for non-deterministic systems.
Third-party / vendor riskDue-diligence and monitoring records for AI vendors and model providers, with vendor certificates evaluated as inputs, never inherited as your own controls.
Fair lending (ECOA / Reg B)Where AI touches credit, bias and disparate-impact testing, adverse-action evidence, and documentation a supervisor can review.
ISO/IEC 42001AI management system clauses crosswalked onto controls you already evidence, the recognized standard procurement and board reviewers increasingly ask for.

A score is a starting point, not a verdict. If the checklist surfaces gaps you want help closing, the AI Governance Readiness engagement turns it into a defensible inventory, a gap assessment, and a 90-day roadmap.

§ Why DSE·senior-only · authored IP · named deliverables

The team behind the checklist.

Delivery
Senior-only bench
No junior churn and no rotating Big-4 staffing pyramid. The principal who scopes a governance engagement is the one who does the work, end to end.
Authored IP
mcp-warden
DSE authored mcp-warden, an open-source MCP supply-chain integrity gate, MIT-licensed with signed releases. The same depth backs the governance work. See the repo ↗
What you receive
Named deliverables
An engagement produces a defensible AI inventory, a risk classification, a control crosswalk onto your SOC 2 or ISO 27001, and a 90-day roadmap, fixed-fee and yours to keep.
§ What this is·and what it isn't

A self-assessment. Not certification.

The AI Governance Audit-Readiness Checklist is a self-scored readiness aid, not an audit, an attestation, or a certification. DSE is not an accredited certification body and does not issue ISO/IEC 42001 certificates or certify EU AI Act or NIST AI RMF compliance.

Completing the checklist does not guarantee passing an audit or avoiding enforcement, and it is not legal advice. Where it describes "mapping to" NIST AI RMF, ISO/IEC 42001, or US supervisory expectations, that means advisory alignment, not certification. For a scoped engagement, all work is governed by a signed SOW / MSA.