GOVERNANCE / SECURITY / INTERNAL AUDIT

AI governance. Put it into practice.

From a question to a researched briefing, practical controls,
and the evidence your team needs.

Free to use. No account required.
90 DAY IMPLEMENTATION WORKSPACE

Turn the plan into evidence.

Assign an owner and record an evidence note. Internal audit validates the result independently.

0 / 9tasks with evidence notes

Evidence notes are reported by your team, not independently verified. Save a workspace file to resume later. Notes stay in your browser unless you download them.

Planning windows below are targets, not legal deadlines.
1

First 30 days

5 actions
Inventory the AI system and its purposeAI system ownerTo do

Evidence to collect

Use case, business owner, model and version, data flows, users, vendor, jurisdictions and system boundaries.

What internal audit can test

Reconcile the inventory with procurement and approved software records; investigate unregistered AI use.

Map applicable local and sector rulesLegal and complianceTo do

Evidence to collect

Counsel-approved jurisdiction register covering privacy, employment, consumer protection and relevant sector rules.

What internal audit can test

Confirm where decisions affect people. This starter catalog does not cover every US state, UK rule or international obligation.

Assign decisions and escalation pathsAI governance leadTo do

Evidence to collect

Approved AI policy, accountable owner, approval thresholds, risk acceptance and incident escalation.

What internal audit can test

Trace one approval to the accountable decision maker and confirm independent challenge.

Train users and reviewers for their rolesLearning and developmentTo do

Evidence to collect

Role-based syllabus, attendance, practical assessment, approved-tool guidance and refresher plan.

What internal audit can test

Ask a user to recognize an unreliable output and demonstrate the reporting route.

Challenge the AI supplier and contractProcurement and third party riskTo do

Evidence to collect

Data-use terms, subprocessors, model-change notice, evaluation evidence, incident duties, audit rights and exit provisions.

What internal audit can test

Trace a vendor claim to evidence that covers the actual service, model version and contractual scope.

2

Days 31 to 60

3 actions
Evaluate outputs before releaseAI engineering and business ownerTo do

Evidence to collect

Representative test cases, known limitations, acceptance thresholds, evaluation results and human sign-off.

What internal audit can test

Reperform a sample including incorrect answers, unusual inputs and materially affected user groups.

Test prompt injection and data boundariesInformation securityTo do

Evidence to collect

Threat model, authorization design, adversarial test results and resolved defects.

What internal audit can test

Use synthetic content to test whether untrusted instructions can override access boundaries or disclose restricted material.

Monitor changes and prepare incident responseAI operationsTo do

Evidence to collect

Model-change register, evaluation triggers, incident runbook, rollback procedure and a tested escalation route.

What internal audit can test

Simulate a failed model update and verify detection, rollback and accountable sign-off.

3

Days 61 to 90

1 action
Run an independent audit and report gapsInternal auditTo do

Evidence to collect

Risk and control matrix, audit scope, samples, workpapers, findings and remediation owners.

What internal audit can test

Distinguish control design from operating effectiveness; report unsupported assertions as evidence gaps.