Review your inventory
Use the assessment preview for a work-item export. Read the scoring methodology and report example to understand findings and limitations.
Practical guide · Updated 13 September 2026
AI governance is the way an organization assigns responsibility, sets rules and checks evidence for the artificial intelligence it builds, buys or uses. It connects a useful business purpose with decisions about data, risk, human oversight and ongoing operation.
A workable process answers four questions: What is this system allowed to do? Who could be affected? Who can approve or stop it? What evidence supports that decision?
Begin with one AI use case and its real workflow. A support assistant that drafts replies has different permissions and consequences from an agent that issues refunds. Record the purpose, users, data sources, supplier, deployment setting and accountable owner before selecting controls. If the technology is unfamiliar, read the introduction to artificial intelligence first.
Governance describes how an organization directs its work, makes decisions and holds people accountable. The Governance Institute of Australia includes ethics, risk management and compliance within that broader responsibility. AI governance applies those responsibilities to systems that infer outputs from data.
For an AI support assistant, an ordinary access review asks who can read customer records. An AI review also asks whether generated replies reveal those records, invent an answer or change after a model update. Keep the existing business owner and review process, then add evidence for those AI-specific failure modes.
A useful governance hub connects the AI inventory, risk register, decisions and review evidence. Begin with a shared use-case reference and an owner for each record, even when the records live in different systems. Our risk register template and decision log help prepare those records. Your team decides where to retain and link the exported evidence.
Illustrative example: a customer support assistant
The following is a proposed team workflow, not a customer case study. Its scope is an assistant that drafts answers from approved support articles; a person decides what reaches the customer.
Inventory the use case. Create reference SUP-AI-01. Record that the assistant receives a question and approved knowledge articles, produces a draft and has no refund or account-change permissions. Keep a link to the current system and supplier versions.
Describe the risks. The draft might invent a refund policy, expose customer details or use an outdated article. Add each concern to an AI risk register with affected people, impact, proposed controls and evidence still needed. An empty field needs investigation.
Assign owners. Give the support lead responsibility for the business decision, the engineering lead responsibility for access controls and a knowledge owner responsibility for article updates. Define who can pause the assistant and who covers absences.
Test before approval. Try incorrect premises, missing answers and attempts to request another customer's information. Compare drafts against approved articles. Keep test cases, observed failures and fixes. Define acceptable results for this use case before reviewing the outcome.
Record a bounded approval. If the evidence supports a limited pilot, record its audience, duration, restrictions and stop conditions in an AI governance decision log. Customer-facing messages still need a reviewer. The record should show who accepted the remaining risks.
Monitor and revisit. Sample draft accuracy, track complaints and confirm access permissions remain correct. Review after a model, supplier, data or permission change. A request to send messages automatically requires a new decision, not an assumption that the earlier approval covers it.
The voluntary NIST AI Risk Management Framework organizes activities into Govern, Map, Measure and Manage. Govern establishes responsibility; Map examines context; Measure evaluates risk; Manage prioritizes responses. These functions support ongoing work across the system lifecycle, rather than a single launch checklist. See the NIST AI RMF Core.
Use that structure to ask whether your team has a decision owner, understands the use case, has tested relevant failure modes and can act on what it finds. The six-step example above is our practical interpretation, not an official NIST sequence. A completed template does not establish certification or legal compliance.
Use the assessment preview for a work-item export. Read the scoring methodology and report example to understand findings and limitations.
The AI Agent Action Approval Planner helps describe approval gates, access limits and stop conditions. It creates a plan locally; it does not connect to or control an agent.
The AI Vendor Due Diligence Checklist identifies evidence gaps and questions. Your procurement, security and business reviewers verify the answers and make the decision.
Teams working in Jira can also explore the separate Jira governance workflow. Website exports and local planning tools do not automatically synchronize decisions into Jira.
Keep the use-case reference, source version, identified risk, control owner, test evidence, decision and next review date connected. Distinguish a planned control from one that has been implemented and tested. An assessment score helps prioritize questions; it cannot establish that every system was inventoried or that a control works.
For your first review, choose one use case, download a sample export and compare the fields with your records. Then use the tool directory to find the next step that matches the missing evidence.