Skip to main content

AI GOVERNANCE RISK ASSESSMENT CHECKLIST

No Orphaned Risks. Every Risk Gets a Control.

Map each risk to a control tagged to NIST AI RMF, ISO 42001, or the EU AI Act, and a named owner.

You have run the assessments, but you cannot say with certainty that every identified risk actually maps to a control. Orphaned risks with no control entry and no documented exception are a common audit finding. So are controls mapped to a framework at the category level only, with no clause-specific reference, and control owners who are unaware of the responsibilities assigned to them.

60
Concrete controls, not vague principles you still have to operationalize
8
Governance domains, from use case intake through audit readiness
4
Frameworks anchored throughout: EU AI Act, NIST AI RMF, ISO 42001, SR 11-7

INSTANT ACCESS

Get instant access to the checklist

All 60 controls, with the evidence each one requires.
  • Risk-to-control coverage across the full assessment
  • Framework alignment: NIST AI RMF, ISO 42001, EU AI Act, SR 11-7
  • Named owners and the exact evidence artifact per control
AI Governance Risk Assessment Checklist

Download the 60-control checklist

A 21-page reference across eight governance domains.

Verifying you're human...

What's Included
Risk-to-control coverage: every risk item from the assessment carries at least one assigned control
Framework alignment to NIST AI RMF, ISO 42001, EU AI Act Annex, and SR 11-7
Named control owners who confirm accountability in writing or via system sign-off
A formal gap register plus compensating controls with expiry or reassessment dates
Control entry fields: control ID, risk reference, type, owner, and review frequency
Third-party and vendor-provided controls, with ownership clarified contractually
01
Intake
Clear eight mandatory fields before review begins.
02
Risk tiering
Classify against Annex I and Annex III on three documented dimensions.
03
Use case risk assessment
Enumerate harms and calculate residual risk.
04
Fundamental rights impact assessment
Run the FRIA for high-risk deployers.
05
Prioritization
Score, escalate, and assign a named risk owner.
06
Control mapping and audit readiness
Link every risk to a control and its evidence.

You over-assess nothing

The scoping table tells you which sections apply by use case profile, so low-stakes internal tooling does not get the full 60.

Audit trails are built in, not reconstructed later

Each control names the exact evidence artifact required before deployment, not retrospectively.

You can defend classifications to a third party

Tier rationale and treatment decisions trace to a named individual and a documented justification.

Reviewers work from a repeatable record

Every control captures an owner, a status, an evidence reference, and a review date.

Framework-anchored controls

Controls mapped to the EU AI Act (Annex I prohibited, Annex III high-risk, Article 12 logging) and NIST AI RMF 1.0 GOVERN and MAP subcategories.

Cross-regulatory references

References SR 11-7, ISO/IEC 42001, DORA, GDPR Article 22, and SS1/23.

Eight named domains

60 controls organized across eight named governance domains.

Coverage summary tables

Specify minimum questions and common gaps per domain.

Cited to the clause

Framework anchors cited by Title and Article, and by function and subcategory, throughout.

No. High-risk AI systems under EU AI Act Annex III require all 60, while general-purpose AI, internal tooling, and vendor models each map to a defined subset of sections in the scoping table.