AI GOVERNANCE RISK ASSESSMENT CHECKLIST
No Orphaned Risks. Every Risk Gets a Control.
You have run the assessments, but you cannot say with certainty that every identified risk actually maps to a control. Orphaned risks with no control entry and no documented exception are a common audit finding. So are controls mapped to a framework at the category level only, with no clause-specific reference, and control owners who are unaware of the responsibilities assigned to them.
INSTANT ACCESS
Get instant access to the checklist
- Risk-to-control coverage across the full assessment
- Framework alignment: NIST AI RMF, ISO 42001, EU AI Act, SR 11-7
- Named owners and the exact evidence artifact per control
Download the 60-control checklist
Framework-anchored controls
Controls mapped to the EU AI Act (Annex I prohibited, Annex III high-risk, Article 12 logging) and NIST AI RMF 1.0 GOVERN and MAP subcategories.
Cross-regulatory references
References SR 11-7, ISO/IEC 42001, DORA, GDPR Article 22, and SS1/23.
Eight named domains
60 controls organized across eight named governance domains.
Coverage summary tables
Specify minimum questions and common gaps per domain.
Cited to the clause
Framework anchors cited by Title and Article, and by function and subcategory, throughout.
No. High-risk AI systems under EU AI Act Annex III require all 60, while general-purpose AI, internal tooling, and vendor models each map to a defined subset of sections in the scoping table.
It is logged in a formal gap register with a documented rationale and a remediation timeline, and where a primary control cannot be implemented, a compensating control is documented and formally approved.
Vendor-provided controls are included in the mapping with ownership clarified contractually, and vendor involvement is flagged at intake with a contract reference.
Reassessment triggers are configured for model updates, deployment or scope changes, new regulatory obligations, recorded incidents, and elapsed review intervals.
No. The checklist is for educational and operational planning only; consult qualified legal, compliance, privacy, and risk professionals when interpreting applicable regulatory obligations.