AI Governance Institute
All governance templates →What are the AI governance best practices that actually hold up in practice?

Implementation Kit

AI Governance Best Practices Checklist and Gap Template

A baseline of practices that hold up under scrutiny, each mapped to a control domain and playbook, plus a way to verify they are real: an enforcement verification log and a ranked gap list.

Who this is for: The governance lead pressure-testing the program against a practical baseline.

Download the kit (Markdown) ↓3 artifacts. Every table also copies as CSV.

1. Best-practice baseline checklist

Spreadsheet

The practices to have in place, each tied to its domain and the playbook that explains it.

Template

PracticeDomainPlaybookIn place?Evidence
A complete, owned AI inventory with risk tiersinventorycomplete-ai-inventoryY / partial / N
A repeatable risk classification methodriskhow-to-perform-ai-risk-assessment
Signed risk assessments for all high-risk systemsriskhow-to-perform-ai-risk-assessment
Meaningful human oversight for consequential decisionsoversighthuman-oversight-for-high-risk-ai-decisions
Bias testing with a re-test cadence for people-affecting systemsmonitoringalgorithmic-bias-detection-and-mitigation
Decision-level logging you can reconstructauditai-decision-auditability
Production monitoring with thresholds and alertingmonitoringmodel-drift-monitoring
An incident runbook and register, drills runincidentai-incident-response
Vendor due diligence and monitoring for material AI vendorsthird-partythird-party-ai-vendor-due-diligence
A regulatory obligation map kept currentregulatoryregulatory-obligations-for-ai
Quarterly board reporting reconciled to sourceboardboard-ai-risk-reporting
Independent assurance of the program annuallyassuranceai-governance-auditing

Worked example

PracticeIn place?Evidence
Complete owned inventory with tierspartial2 systems found off-register in audit
Repeatable risk classificationYmethod doc + rubric
Signed assessments for all high-riskpartial1 of 3 unsigned
Meaningful human oversightNoversight is a formality (audit finding)
Bias testing with cadencepartialprotocol exists; last run 7 weeks ago
Decision-level loggingY25/25 sampled decisions fully logged
Monitoring with alertingNmetrics defined, no alerts
Incident runbook + register + drillsY1 drill run
Vendor DD + monitoringpartialDD done; monitoring cadence not enforced
Regulatory map currentpartialmapping in progress
Board reporting reconciledpartialtemplate + cadence; not reconciled
Annual independent assuranceYH1 internal audit complete

Acceptance criteria

  • Every practice is rated in place, partial, or not, with evidence for the rating.
  • Ratings come from verification, not self-assessment.
  • Each practice links to the domain and playbook a reader can go to for detail.

2. Enforcement verification log

Spreadsheet

A record of which practices were tested against actual system behaviour, not just policy review.

Template

PracticeVerification methodDateResultVerified by
<practice>behaviour test / log sample / config check / drill / interviewYYYY-MM-DDpass / partial / fail + note<name>

Worked example

PracticeVerification methodDateResultVerified by
Decision-level loggingsampled 25 decisions across 2 systems2026-09-08passInternal Audit
Human oversight is meaningful5 reviewer interviews + override-rate data2026-09-08fail (formality)Internal Audit
Deployment gate enforcedchecked last 10 deploys vs registry2026-09-09partial (8/10)Internal Audit
Incident runbook workstabletop of a data-exposure incident2026-08-30partial (no holding statement ready)Governance
Bias re-test cadencechecked test logs2026-09-08fail (overdue)Internal Audit

Acceptance criteria

  • Each entry names a verification method that tests behaviour or records, not a document read.
  • Failed and partial results carry a note on what was wrong.
  • Practices not yet verified are visible as blanks, not assumed to pass.

3. Ranked gap list

Spreadsheet

The gaps, ordered by whether a practice is missing entirely versus partially there, so effort goes to the worst first.

Template

RankPracticeStateWhy it ranks hereOwnerTarget
1missing / partialYYYY-MM-DD

Worked example

RankPracticeStateWhy it ranks hereOwnerTarget
1Meaningful human oversightpartial but failingHigh-tier, regulator-relevant, currently provides no protectionHead of Talent2026-11-15
2Monitoring with alertingmissingproduction models can degrade undetectedML Platform2026-11-01
3Bias re-test cadencepartialprotocol exists but lapsed; quick to fixDS team2026-10-01
4Signed assessments for all high-riskpartial1 of 3; the assessment is nearly doneCompliance2026-10-15
5Regulatory map currentpartialin progress; no imminent deadline missedCompliance2026-11-30

Acceptance criteria

  • Gaps are separated into "missing entirely" and "partially implemented".
  • Ranking weighs risk exposure and regulatory relevance, not just ease.
  • Every gap has an owner and a target date and is tracked to closure.

Governance controls this kit produces evidence for

Completing the artifacts above gives you a head start on the evidence requirements for these controls.

MGV-003
MGV-003

The baseline checklist and ranked gap list are a governance-program milestone and remediation plan.

BRD-005
BRD-005

The baseline assessment feeds the governance maturity assessment.

MGV-004
MGV-004

The enforcement verification log is continuous-assurance evidence that practices operate, not just exist.

HOC-004
HOC-004

Verifying oversight is meaningful tests the automation-bias control.

ALC-005
ALC-005

The verification log contributes to regulatory audit readiness.

This kit backs one playbook. Read the full guidance for the reasoning behind each artifact.

Decide what to implement next

Assess your governance gaps, then create an action plan with owners and target dates. Build and export without an account; sign in when you want to save your plan.

Start the AI governance assessment →