AI governance. Put it into practice.
From a question to a researched briefing, practical controls,
and the evidence your team needs.
Turn the plan into evidence.
Assign an owner and record an evidence note. Internal audit validates the result independently.
Evidence notes are reported by your team, not independently verified. Save a workspace file to resume later. Notes stay in your browser unless you download them.
First 30 days
5 actionsInventory the AI system and its purposeAI system ownerTo do
Evidence to collect
Use case, business owner, model and version, data flows, users, vendor, jurisdictions and system boundaries.
What internal audit can test
Reconcile the inventory with procurement and approved software records; investigate unregistered AI use.
Map applicable local and sector rulesLegal and complianceTo do
Evidence to collect
Counsel-approved jurisdiction register covering privacy, employment, consumer protection and relevant sector rules.
What internal audit can test
Confirm where decisions affect people. This starter catalog does not cover every US state, UK rule or international obligation.
Assign decisions and escalation pathsAI governance leadTo do
Evidence to collect
Approved AI policy, accountable owner, approval thresholds, risk acceptance and incident escalation.
What internal audit can test
Trace one approval to the accountable decision maker and confirm independent challenge.
Train users and reviewers for their rolesLearning and developmentTo do
Evidence to collect
Role-based syllabus, attendance, practical assessment, approved-tool guidance and refresher plan.
What internal audit can test
Ask a user to recognize an unreliable output and demonstrate the reporting route.
Challenge the AI supplier and contractProcurement and third party riskTo do
Evidence to collect
Data-use terms, subprocessors, model-change notice, evaluation evidence, incident duties, audit rights and exit provisions.
What internal audit can test
Trace a vendor claim to evidence that covers the actual service, model version and contractual scope.
Days 31 to 60
3 actionsEvaluate outputs before releaseAI engineering and business ownerTo do
Evidence to collect
Representative test cases, known limitations, acceptance thresholds, evaluation results and human sign-off.
What internal audit can test
Reperform a sample including incorrect answers, unusual inputs and materially affected user groups.
Test prompt injection and data boundariesInformation securityTo do
Evidence to collect
Threat model, authorization design, adversarial test results and resolved defects.
What internal audit can test
Use synthetic content to test whether untrusted instructions can override access boundaries or disclose restricted material.
Monitor changes and prepare incident responseAI operationsTo do
Evidence to collect
Model-change register, evaluation triggers, incident runbook, rollback procedure and a tested escalation route.
What internal audit can test
Simulate a failed model update and verify detection, rollback and accountable sign-off.
Days 61 to 90
1 actionRun an independent audit and report gapsInternal auditTo do
Evidence to collect
Risk and control matrix, audit scope, samples, workpapers, findings and remediation owners.
What internal audit can test
Distinguish control design from operating effectiveness; report unsupported assertions as evidence gaps.