The AI Governance Checklist: What to Put in Place First

RedHub AI Editorial5 min read

A hand setting the first of five blank cards on a boardroom table, the remaining four stacked under red light
Jump to a section7

TL;DR

  • What it is: a short, ordered checklist of what to set up first when you're starting AI governance from zero.
  • Who it's for: anyone told to "get AI governance in place" who needs a starting order, not a standard. See the starter bundle.
  • How it works: inventory → policy → training → risk classification → evidence. Do them in that order, not all at once.
  • Bottom line: the order matters more than the depth. Get the first version done, then improve it. A working aid, not legal advice.

What should be on an AI governance checklist?

A starter AI governance checklist has six items, in order: inventory the AI tools your team uses, write an acceptable-use policy, train your team on it by role, classify your AI uses by risk, run a readiness assessment on the higher-risk ones, and assemble the evidence into one pack. The trap is trying to do all six at once or starting in the middle — you can't write a policy for tools you haven't named, and you can't assess risk before you've classified. Done in order, a small business can complete a credible first pass in about 90 days.

Best for: teams starting from zero who want a checklist, not a consulting project — the AI Governance Starter Bundle runs it end to end. A working aid, not legal advice.


"Get AI governance in place" is a mandate, not a plan. The reason it feels overwhelming is that people picture the finished enterprise version instead of the first step. This checklist is the first step — six items in the order that makes each one possible.

The six-item starter checklist

  1. Inventory your AI tools. List every AI tool your team actually uses — including the unofficial ones. You can't govern what you haven't named, and this is usually where the surprises are.
  2. Write the acceptable-use policy. Approved tools, off-limits data, human-review rules, who to ask. Short and specific beats long and vague.
  3. Train the team by role. Different roles face different AI risks, so train each on the parts that apply — and log who completed it. That log is your first piece of evidence.
  4. Classify uses by risk. Sort your AI uses into buckets — a chatbot writing marketing copy is low-risk; one touching customer data or making decisions about people is not. Risk classification tells you where to spend the rest of your effort.
  5. Assess the higher-risk uses. Run a readiness assessment on the uses that landed in the higher-risk buckets. This is where a real regulation, if one applies to you, would focus.
  6. Assemble the evidence pack. Put the inventory, policy, training log, risk classification, and assessment in one place. That pack is your answer when someone asks "how do you govern AI?"

Key insight: the order is the whole trick. Each item depends on the one before it — no policy without an inventory, no risk assessment without a classification. Skip around and you'll redo work; go in order and each step sets up the next.

What to do first if you can only do one thing

If a mandate just landed and you have an afternoon, do item one: inventory your AI tools. It's fast, it's revealing, and everything else builds on it. Teams are almost always using more AI tools than leadership realizes, and you can't write a meaningful policy or assess any risk until you know what's actually in use.

If you would rather score the checklist than read it, the free AI Governance Gap Assessment covers the same ground in 22 questions and returns a verdict plus the one thing to fix first. It is your own answers, unverified — not an audit, not a certification.

Run the whole checklist as one program

The AI Governance Starter Bundle turns this checklist into a sequenced 90-day program — policy, role-based training, and a readiness kit that produce the inventory, logs, and assessment for your evidence pack.

Get the AI Governance Starter Bundle — $399 →

Where teams get stuck

The stallWhy it happensThe fix
"Where do we even start?"Picturing the finished enterprise programDo item one — the inventory — this week
Policy with no teethWritten but never trained onTrain by role and log completion
Governing everything equallyNo risk classificationClassify first, then focus effort on high-risk
Nothing to show a reviewerNo evidence assembledKeep one evidence pack from day one

For the full context, read AI governance for small business in 90 days and the Policy-People-Proof framework.


Decision Guide

Use it if: you're starting AI governance from zero and need a concrete order of operations.

Skip it if: you already have an inventory, a trained-on policy, and an evidence pack in place.

Best first step: inventory your AI tools this week — it's fast, revealing, and everything else builds on it.

FAQ

What's the first step in AI governance?

Inventory the AI tools your team actually uses, including the unofficial ones. It's fast and revealing, and every other step depends on it — you can't write a policy or assess risk for tools you haven't named.

Why does the order of the checklist matter?

Because each item depends on the one before it. No policy without an inventory, no risk assessment without a classification, no evidence pack without the earlier outputs. Going in order means each step sets up the next; skipping around means redoing work.

How do I classify AI uses by risk?

Sort them by impact: a tool writing marketing copy is low-risk, while one touching customer data or making decisions about people is higher-risk. The classification tells you where to concentrate effort — you assess and document the higher-risk uses, not every use equally.

How long does the checklist take?

About 90 days for a solid first pass: inventory and policy in the first month, training and classification in the second, assessment and evidence pack in the third. Smaller teams can move faster — the sequence matters more than the timeline.

Is this a compliance checklist or legal advice?

It's a practical starter checklist and a working aid — not legal advice or a conformity assessment. It helps you get organized and produce evidence, but where a specific regulation applies to you, a qualified professional owns that determination.

Do I need special software to do this?

No — you can run the checklist with documents and a spreadsheet. Tools like a policy builder, a training kit, and a readiness kit speed each step and keep the outputs consistent, but the checklist itself is a process, not a product.

Turn the mandate into a checklist

Inventory → policy → training → risk → assessment → evidence. Six steps, in order, done in 90 days. A working aid, not legal advice.

Get the AI Governance Starter Bundle — $399 →