Skip to content

Checklist

AI Risk & Readiness Assessment Checklist

Before a board can oversee AI, it needs to know where the organization stands. This checklist walks through six areas — governance, strategy, data, legal, people, and vendors — so the board and management can score readiness honestly and close the gaps. Read it here, download the editable Word file, or print it.

Organization type

Swaps the content, guidance, and download to fit your board.

Corporate board — six-area readiness assessment

Organization

 

Assessment completed by

 

Date completed

 

Reviewed by board / committee on

 

  1. 1. How to use this assessment

    Management completes the checklist first, then the board or its AI oversight committee reviews it together. Mark each item In place, In progress, Not started, or N/A — and write the evidence, not just the status. The gaps become the work plan.

  2. 2. Scoring

    Count the items Not started or In progress in each area. Any area with more than two gaps deserves a named owner and a date. Re-run the assessment annually and compare.

1. Governance and oversight

#Checklist itemStatusEvidence / notes
1.1AI oversight is explicitly assigned to a board committee or the full board  
1.2The board has adopted a written AI use policy  
1.3A current inventory of AI tools in use across the company exists  
1.4AI risk is on the enterprise risk register  
1.5The board receives a regular AI report from management  

2. Strategy and opportunity

#Checklist itemStatusEvidence / notes
2.1Management has articulated where AI creates value in the strategy  
2.2Significant AI investments come to the board with a business case  
2.3The board has discussed how competitors are using AI  
2.4AI opportunities are weighed against risks in a written framework  

3. Data and security

#Checklist itemStatusEvidence / notes
3.1Rules exist for what data may enter AI tools — and are enforced  
3.2Customer and employee data is protected from public AI tools  
3.3Cybersecurity controls account for AI-enabled attacks (phishing, deepfakes)  
3.4Payment and wire-transfer verification is resistant to voice/video impersonation  

4. Legal and regulatory

#Checklist itemStatusEvidence / notes
4.1Counsel has reviewed AI use in regulated activities (hiring, lending, health)  
4.2Contracts address vendor AI use of company data  
4.3Intellectual property ownership of AI-assisted work is addressed  
4.4The company monitors AI regulation in its jurisdictions  

5. People and culture

#Checklist itemStatusEvidence / notes
5.1Employees have been trained on the AI use policy  
5.2Directors have had AI education in the last 12 months  
5.3Someone owns AI incident response  
5.4The workforce impact of AI is part of succession and talent planning  

6. Vendors and third parties

#Checklist itemStatusEvidence / notes
6.1Key vendors' AI features are inventoried and understood  
6.2Vendor contracts address data use by embedded AI  
6.3Vendor AI incidents are covered by incident-reporting requirements  

Guidance notes

  • Honest scoring beats reassuring scoring — the value of this exercise is the gaps it exposes.
  • Require evidence for every 'In place' answer. A policy nobody follows is not in place.
  • Every gap gets an owner and a date, or the assessment was a filing exercise.
  • Re-run annually and compare scores — progress is the point.
  • This checklist is a board tool, not a substitute for technical, legal, or cybersecurity review.

Before you use this checklist

Legal counsel review is recommended
Have qualified legal counsel licensed in your state or jurisdiction review and adapt this material before your board adopts or relies on it.
Educational model language only
This is a general model provided for educational purposes. It is not legal, tax, accounting, compensation, or compliance advice, and it does not create an attorney-client or advisory relationship.
Tailor to your governing documents and law
Align it with your articles of incorporation, bylaws, applicable state corporate or nonprofit statutes, employment law, and any regulatory requirements that apply to your organization.
Adopt and record formally
Approve the process by board vote or resolution, record it in the minutes, keep sensitive material confidential, and review it annually.

This resource is provided for educational purposes only and does not constitute legal, tax, accounting, compensation, or compliance advice, nor does it create an attorney-client or advisory relationship. Adapt it to your organization's governing documents and applicable law, and have qualified legal counsel review it before your board adopts or relies on it.

Want a facilitator for your board's AI conversation?

This checklist surfaces the gaps; closing them takes a plan. If your board could use a confidential, experienced facilitator for its AI readiness conversation, I'd be glad to talk.

Request a consultation