Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

What belongs on an AI governance audit checklist?

Last verified

An AI governance audit checklist spans inventory, risk, transparency, and lifecycle controls — labelled by source: ISO 42001, NIST AI RMF, or EU AI Act. Not legal advice.

Audit checklist, last verified 10 September 2026 against ISO/IEC 42001:2023 Annex A, NIST AI RMF 1.0, and Regulation (EU) 2024/1689 themes. Standard vs regulation vs best practice labelled. Not legal advice.

Cross-source checklist

AI governance audit items with source labels (not legal advice)
ItemSourceKind of text
☐ AI system inventory maintainedISO 42001 Clause 4 / NIST GOVERN 1Standard / RMF best practice
☐ AI risk assessment documentedISO 42001 Clause 6 / NIST MAP 1Standard / RMF
☐ Impact assessment for high-impact systemsISO 42001 Annex A — impactsStandard — if applicable
☐ Roles and accountability assignedISO 42001 Annex A — internal organizationStandard — if applicable
☐ Lifecycle gates (design → deploy → retire)ISO 42001 Annex A — lifecycleStandard — if applicable
☐ Data provenance and quality controlsISO 42001 Annex A — dataStandard — if applicable
☐ Transparency to users and affected partiesISO 42001 Annex A — informationStandard — if applicable
☐ Human oversight for consequential decisionsEU AI Act Art. 14 theme / NIST GOVERNLegal if high-risk applies / RMF
☐ Technical documentation for high-risk AIEU AI Act Art. 11Legal requirement — if applicable
☐ GPAI provider documentation baselineEU AI Act Art. 53Legal requirement — if applicable
☐ Third-party AI supplier due diligenceISO 42001 Annex A — third-partyStandard — if applicable
☐ Monitoring and incident learning loopNIST MEASURE / EU AI Act Art. 73 themeRMF / legal if applicable

Standard vs regulation vs best practice

  • [ISO 42001] — voluntary standard control; required in YOUR SoA if applicable.
  • [NIST AI RMF] — US voluntary framework; Map/Measure/Manage/Govern functions.
  • [EU AI Act] — legal requirement only if Articles 2–3 apply to YOUR system.
  • [Best practice] — recommended even when not strictly required.

What to do now

  • Print the table and mark source column for each finding.
  • Pair with readiness-checklist for certification-specific gaps.
  • Escalate [EU AI Act] rows to counsel — this page does not classify YOUR systems.

Checklist

  • ☐ Every finding tagged with source label?
  • ☐ Legal rows reviewed by counsel?
  • ☐ CAPA owners assigned for gaps?

Where this shows up in ShipReady Metrics

AI inventory, AI risk register, AI-authored-code floor, and AI ROI scoring surfaces support checklist evidence. The crosswalk covers NIST AI RMF, ISO 42001, and eu_ai_act with density honesty. Signed-in surfaces only — no public demo path.

Frequently asked questions