Checklist · The AboveBoard Standard v1.0 · Printable

The 40-point AI governance checklist

Every control in the AboveBoard Standard, grouped by domain, with the evidence that proves each one. It is the same question bank the assessment uses and the same rubric an independent reviewer scores against, so ticking a box here means something only if you could hand over the document beside it. Print it, score it, and see where the gaps are before anyone else does.

How to use it

Tick a box only if you could hand a stranger the evidence named beside it today. If the honest answer is "we do that, but nothing is written down," leave it blank; that is the difference between a 1 and a 2 in the scoring below, and between a practice and a proof. The three controls marked gating override everything else: a zero on any of them means a firm cannot be listed in the registry at any level, because they are the three things every regulator, insurer and client questionnaire asks about first.

Most firms complete the checklist in under an hour with the right people in the room: whoever owns compliance or quality, whoever runs IT, and one partner. Templates for the most common gaps (the AI acceptable-use policy, the approved-tools register, the acknowledgment form) are free on this site.

Domain 1: Governance & Accountability 20 points

Who owns AI at your firm, what tools are in use, and whether leadership actually oversees it.

Domain 2: Data Security & Privacy 20 points

What client data touches AI tools, and the controls that keep it confidential.

Domain 3: Operational Controls 20 points

Human review, quality checks, incident response and vendor oversight in day-to-day work.

Domain 4: Workforce Capability & Training 20 points

Whether your people know the rules, have been trained for their role, and refresh that training.

Domain 5: Transparency & Client Trust 20 points

How you disclose AI use to clients, control marketing claims, and handle complaints.

How scoring works

A tick on this page is a yes-or-no proxy. The Standard scores each control on four levels, and the difference between them is almost always documentation and review:

LevelMeaningTypical evidence
0Not in placeNothing to show
1InformalAn email, a verbal rule, "everyone knows"
2DefinedWritten, approved, communicated
3Managed and reviewedWritten, enforced, evidenced in records, reviewed or tested in the last 12 months

Eight controls per domain give a raw score of 0 to 24, scaled to 20 points. Five domains sum to an AboveBoard Score of 0 to 100. Verified is 60–74, Advanced 75–89 and Leading 90–100; below 60 is "not yet verified," which stays private and comes with a prioritized gap plan. A self-scored result is a provisional score. A verified score is what an independent reviewer confirms from the evidence, and only verified scores appear in the registry with a year-stamped badge.

Two things the score does not do. It does not certify that any AI output is accurate; it verifies that the practices which catch errors exist and are evidenced. And it is not an ISO certification, a CPA audit or a regulatory approval; it is a score and a verification under a private, voluntary standard mapped to the NIST AI RMF and cross-walked to ISO/IEC 42001. The full rubric, with all four levels for every control and the framework mapping, is published in full. What the numbers mean in your industry is on the industry pages, and what closing the gaps costs compared with the alternatives is in How much does an AI audit cost?

Questions

What is an AI governance checklist?

A structured list of the controls an organization should have in place to govern its use of AI, each paired with the evidence that proves it exists. This one contains the 40 controls of the AboveBoard Standard v1.0 across five domains: governance and accountability, data security and privacy, operational controls, workforce capability and training, and transparency and client trust. It is the same question bank the AboveBoard assessment uses.

What are the 6 pillars of AI governance?

Different frameworks count differently. Six-pillar lists typically cover accountability, transparency, fairness, privacy and security, safety and reliability, and human oversight. The AboveBoard Standard organizes the same ground into five scored domains built for firms that use AI rather than build it: governance and accountability, data security and privacy, operational controls (including human oversight and incident response), workforce capability and training, and transparency and client trust. Each domain is worth 20 points.

What are the five pillars of AI readiness?

For a firm that uses AI, readiness means five things you can prove: someone accountable with a written policy and an inventory; client data classified and vendor terms reviewed; a human reviewing AI output with an incident plan behind them; staff trained for their roles and acknowledging the rules; and clients told how AI is used with marketing claims that hold up. Those are the five domains of the AboveBoard Standard, and the free Snapshot scores two questions in each.

How is the AboveBoard Score calculated?

Each of the 40 controls is scored 0 to 3: not in place, informal, defined, or managed and reviewed. The eight controls in each domain give a raw score of 0 to 24, scaled to 20 points. The five domains sum to a score of 0 to 100. Verified 60 to 74, Advanced 75 to 89 and Leading 90 to 100 are listed publicly; below 60 stays private with a gap plan. Three gating controls (G1, D3, O1) must be above zero for any listing.

What is a good AI governance score?

Sixty is the threshold for Verified, which means written and defined practices across all five domains with evidence behind them. Most firms starting from informal guidance score in the 30s to 50s on their first Snapshot and reach Verified within one remediation window, typically by adopting a policy, approving tools with reviewed terms, writing a human-review rule and rolling out training. Advanced (75 to 89) and Leading (90 to 100) require managed, reviewed and tested practices.