AI Governance Institute
All governance templates →What are the biggest AI governance challenges, and how do we address them?

Implementation Kit

AI Governance Gap Assessment and Ownership Audit Templates

A structured way to face the recurring hard problems: an obstacle assessment mapping each common challenge to your current state, a control enforcement audit comparing documented to verified, and an ownership gap log.

Who this is for: The governance lead doing an honest st-take of where the program is stuck.

Download the kit (Markdown) ↓3 artifacts. Every table also copies as CSV.

1. Governance obstacle assessment

Spreadsheet

The common challenges, each with your current status and the next action.

Template

ChallengeOur current statusImpact if unaddressedNext actionOwner
Shadow AI outpacing the inventory
Controls documented but not enforced
Second line lacks the technical depth to challenge
Ownership is diffuse; activities fall between teams
Regulatory change faster than remediation capacity
Agentic systems ahead of the governance model
Board sees status, not risk
Vendor dependencies not really governed

Worked example

ChallengeCurrent statusImpactNext actionOwner
Shadow AI outpacing inventoryquarterly survey + egress scan; still find new tools each cycleclassification gaps; DPA exposureadd SSO/OAuth grant review to the discovery setAI Gov Lead
Controls documented not enforcedaudit found 2 of 8 in this statefalse assuranceenforcement verification log; add CI checksRisk
Second line technical depth1 of 4 can question an eval reportrubber-stampingembed a technical advisor; trainingCRO
Diffuse ownership3 activities have no clear ownerthings not doneupdate the RACI; sign-offAI Gov Lead

Acceptance criteria

  • Every listed challenge has an honest current status, not aspirational.
  • Each has a concrete next action with an owner.
  • The assessment is revisited each quarter to show movement.

2. Control enforcement audit template

Spreadsheet

For each control, compare what the policy says to what the system actually does.

Template

ControlDocumented requirementVerification methodVerified behaviourEnforced?Gap action
<control>test / log review / config check / observationY / partial / N

Worked example

ControlDocumented requirementVerification methodVerified behaviourEnforced?Gap action
Deployment gateno model to prod without a complete registry entrycheck last 10 deploys against registry8 of 10 had complete entries at deploy timepartialmake the gate a pipeline block, not a checklist
Decision loggingevery decision logged at decision levelsample 25 decisionsall 25 fully loggedYnone
Retrieval scopingRAG constrained to the current customerred-team + code reviewone system unconstrained (fixed post-incident)partialadd a CI test for all RAG systems
Bias re-test cadencemonthly for people-affecting systemscheck test logslast test 7 weeks agoNautomate the schedule; alert on overdue

Acceptance criteria

  • Verification is by testing, log review, or config check, not by asking the owner.
  • Every "partial" or "N" has a specific gap action.
  • Results feed the maturity assessment and the obstacle assessment.

3. Governance ownership gap log

Spreadsheet

Activities with no clear owner, or contested ownership, tracked until resolved.

Template

ActivityCurrent owner (if any)ProblemProposed ownerResolvedDate
<activity>none / disputed / unclearY / N

Worked example

ActivityCurrent ownerProblemProposed ownerResolvedDate
Monitoring alerting setupnone"Platform vs DS" ambiguity; nobody built itML Platform (build), DS (thresholds)Y2026-09-10
Vendor requalification on model changedisputedProcurement thinks Security, Security thinks ProcurementVendor Risk ManagerY2026-09-12
Agent kill-switch testingunclearnew capability, no ownerSecurityNtarget 2026-09-30

Acceptance criteria

  • Every unowned or contested activity is logged with the specific problem.
  • Each is resolved by naming an owner in the RACI, with a date.
  • The log is reviewed in the governance committee until empty.

Governance controls this kit produces evidence for

Completing the artifacts above gives you a head start on the evidence requirements for these controls.

MGV-003
MGV-003

The obstacle assessment and its quarterly review are governance-program milestone tracking.

BRD-002
BRD-002

The ownership gap log resolves into the committee RACI and decision rights.

CMP-001
CMP-001

The jurisdictional-applicability challenge ties to multi-jurisdiction compliance mapping.

MGV-004
MGV-004

The enforcement audit is a continuous-assurance activity comparing documented to verified controls.

BRD-005
BRD-005

Enforcement audit results feed the governance maturity assessment.

This kit backs one playbook. Read the full guidance for the reasoning behind each artifact.

Decide what to implement next

Assess your governance gaps, then create an action plan with owners and target dates. Build and export without an account; sign in when you want to save your plan.

Start the AI governance assessment →