Guide
AI governance checklist for companies
Twenty-four decisions, grouped into six areas, that a company has to make before — or shortly after — employees start using AI for work. Work through it in order; each section assumes the previous one is answered. Nothing here requires a specific vendor, including us.
By Botnea editorial team · Updated
How to use this checklist
Governance fails when it is written as a policy nobody can apply. This checklist is deliberately made of decisions rather than principles: each line has an owner and an answer that can be written in one sentence.
A realistic first pass takes about two hours with three people in the room: whoever owns IT or security, whoever owns the budget, and one person from a team that already uses AI daily. Leave items unanswered rather than guessing — an explicit 'not decided yet' is far more useful later than an aspiration.
Write down, for every item:
- The decision, in one sentence.
- Who owns it, by name and not by department.
- The date it was decided, and when it should be revisited.
1. Access
- Who is allowed to use AI for company work — everyone, specific teams, or by request?
- How is access granted, and who can grant it without escalating?
- How is access removed on the day someone leaves, and who verifies it happened?
- Are contractors and temporary staff in scope, and under which role?
The offboarding line is the one most often skipped and most often regretted. If access lives in personal accounts and personal payment methods, there is no offboarding step to perform — the history and the habit simply leave with the person.
2. Models and tools
- Which models or tools are approved for company work, and who maintains that list?
- Is the list enforced by configuration, or only written in a document?
- What is the process for someone to request an addition, and how long does it take?
- Who is told when the approved set changes?
3. Data and confidentiality
- Which categories of company information may be sent to an AI tool at all?
- Which categories are explicitly forbidden — for example customer personal data, credentials, unreleased financials?
- Where is that boundary written in language a non-specialist can apply on a Tuesday afternoon?
- Have you read and recorded each provider's published data-handling terms, with the date you read them?
Provider terms change. Record the date you checked, not just the conclusion, so that a claim made in a procurement review can be re-verified rather than trusted.
4. Behaviour and output quality
- What standing instructions apply to AI output produced on the company's behalf?
- Which company material should AI answers be grounded in, and who keeps it current?
- Which outputs require a human review step before they leave the company?
- How is AI-assisted work disclosed, internally and to customers, if at all?
5. Visibility and cost
- Can you currently answer who used AI last month, and on which models?
- Is AI spend a single line item, or scattered across personal expense claims?
- Who reviews usage, how often, and what decision does that review feed?
- What is measured to judge whether AI use should be expanded or narrowed?
Visibility is not surveillance of individuals. The useful unit is the team and the model: enough to make budget and access decisions, without reading people's conversations.
6. Review and ownership
- Who owns AI governance overall, as a named person?
- How often is the policy revisited — quarterly is a common, workable rhythm?
- What triggers an out-of-cycle review, such as a new model, a new team or an incident?
- How are employees told about changes, and how is that acknowledged?
If you can name the owner and the next review date, you are ahead of most companies of your size. If you cannot, the rest of the checklist will quietly go stale within a quarter.
A worked example
A 60-person services company, three teams already using AI on personal accounts. Their first pass looked like this — short, specific, and incomplete on purpose.
| Decision | Answer | Owner |
|---|---|---|
| Who may use AI | All permanent staff; contractors by request | Head of Operations |
| Approved tools | One managed workspace; no personal accounts for client work | Head of Operations |
| Forbidden data | Client personal data and signed contracts | Managing Director |
| Review of output | Anything sent to a client is read by a human first | Team leads |
| Usage review | Quarterly, by team and model | Finance |
| Retention terms | Not decided — to be confirmed with the vendor in writing | Head of Operations |
The last row is the honest one. A checklist that shows an open question is doing its job; one with no open questions after two hours has usually been filled in optimistically.
What this page does not claim
- This is operational guidance, not legal advice. Obligations differ by jurisdiction, sector and contract, and a lawyer should review any policy you publish to staff.
- No regulation, standard or framework is claimed to be satisfied by completing this checklist.
- No statistics on AI adoption or incidents are cited here, because we have no first-party research to publish and will not repeat unsourced figures.
See the security and data handling page for what Botnea does and does not attest to.
Questions buyers ask
- How long does a first pass take?
- About two hours with the three people who own IT, budget and daily AI use. Getting written answers to two thirds of the items in that session is a good result.
- Do we need a tool before we can govern AI use?
- No. Access, data boundaries and review ownership can be decided on paper. A tool matters when you want the decisions enforced by configuration and want a usage record rather than trust.
- Should we block AI tools until the policy is finished?
- Blocking rarely reduces use; it moves it to personal devices where nothing is visible. Deciding the data boundary first, and consolidating access second, tends to work better.
- How often should this be revisited?
- Quarterly, plus an out-of-cycle review when a new model, team or incident changes the picture.
Enforce the answers, not just record them
Once the checklist has owners and dates, the next step is making the decisions real: one workspace, roles that match the access answer, a model list that matches the approved set, and a usage record for the quarterly review.