Adapted from the Muuvment Labs governance toolkit for use alongside a real implementation. Copy the prompts into your working documents and assign owners. These are starting points, not completed policies, certification, or legal advice.
This web edition is a revised checklist-based adaptation, not a claim that it matches the separately circulated PDF. It removes universal scoring thresholds and fixed schedules: the controls and review frequency must fit the task.
01 · AI acceptable use policy
Define who may use which tools, for what purposes, with which information.
Fields to complete: Scope and owner; approved tools; prohibited uses; data boundaries; required review; training; incident reporting; review date.
Owner: ____________________ Review date: ____________________
02 · Project intake
Define the problem before selecting technology.
Fields to complete: Workflow; sponsor; users; baseline; intended benefit; alternatives; data requirements; acceptance criteria; budget and decision owner.
Owner: ____________________ Review date: ____________________
03 · Data readiness
Identify whether the necessary information can be used responsibly.
Fields to complete: Source owners; permissions; quality; missing information; sensitivity; retention; transfers; recovery; lineage where needed.
Owner: ____________________ Review date: ____________________
04 · Model and solution selection
Compare options against the actual task.
Fields to complete: Required controls first; representative test results; latency; integration; total operating cost; portability; staff capability.
Owner: ____________________ Review date: ____________________
05 · Risk assessment
Record risks and their owners in the specific workflow.
Fields to complete: Potential harm; likelihood; impact; existing controls; remaining risk; action; owner; approval; next review.
Owner: ____________________ Review date: ____________________
06 · Vendor assessment
Resolve supplier and data questions before commitment or sensitive-data transfer.
Fields to complete: Processing locations; access; model-training use; retention and deletion; assurance evidence; support; outages; export; contractual responsibilities.
Owner: ____________________ Review date: ____________________
07 · Ethics and release review
Check effects on people and readiness to introduce the workflow.
Fields to complete: Intended use; affected people; appropriate testing; reviewer authority; exceptions; reversal; monitoring; feedback; release decision.
Owner: ____________________ Review date: ____________________
08 · Governance responsibilities
Make decisions and escalation proportionate to the work.
Fields to complete: Decision rights; accountable owner; required technical and legal input; escalation route; review triggers; records; reporting.
Owner: ____________________ Review date: ____________________
Use the checks in the right order
Define the use case and required controls first. Resolve vendor, contractual, and data-use questions before sensitive information is transferred. Evaluate the workflow before release, and name the people responsible for monitoring, incidents, and change.
A weighted score cannot compensate for a failed mandatory requirement. Choose review dates and escalation triggers appropriate to risk and change rather than company size alone.
Start with the workflow checklist or see how these questions fit our delivery method.