How to use it
Tick a box only if you could hand a stranger the evidence named beside it today. If the honest answer is "we do that, but nothing is written down," leave it blank; that is the difference between a 1 and a 2 in the scoring below, and between a practice and a proof. The three controls marked gating override everything else: a zero on any of them means a firm cannot be listed in the registry at any level, because they are the three things every regulator, insurer and client questionnaire asks about first.
Most firms complete the checklist in under an hour with the right people in the room: whoever owns compliance or quality, whoever runs IT, and one partner. Templates for the most common gaps (the AI acceptable-use policy, the approved-tools register, the acknowledgment form) are free on this site.
Domain 1: Governance & Accountability 20 points
Who owns AI at your firm, what tools are in use, and whether leadership actually oversees it.
- ☐ G1. Is there a written AI policy covering acceptable use, prohibited uses, and consequences? gating
Evidence: AI policy (PDF) with approval date and acknowledgment records
- ☐ G2. Is a named senior person accountable for AI governance, with the authority to stop a tool or use case?
Evidence: Role description, org chart or board/partner resolution
- ☐ G3. Do you maintain an inventory (register) of AI tools and use cases, including who uses them and for what?
Evidence: AI inventory / register export
- ☐ G4. Are AI use cases risk-rated before adoption (client impact, data sensitivity, regulatory exposure)?
Evidence: Risk assessment template and two completed examples
- ☐ G5. Does leadership (partners, board, executive team) review AI risk and performance at least quarterly?
Evidence: Meeting minutes or agenda extracts (redacted is fine)
- ☐ G6. Are AI-related legal and regulatory obligations tracked for your jurisdictions and industry?
Evidence: Obligations register or compliance memo
- ☐ G7. Are AI policies and controls reviewed and updated on a schedule?
Evidence: Policy version history
- ☐ G8. Is AI governance integrated into existing quality, risk or compliance frameworks (e.g., quality management, SOC 2, ISO, peer review)?
Evidence: Relevant framework section or crosswalk
Domain 2: Data Security & Privacy 20 points
What client data touches AI tools, and the controls that keep it confidential.
- ☐ D1. Is client and personal data classified so staff know what may and may not be entered into AI tools?
Evidence: Data classification guidance
- ☐ D2. Do you maintain an approved AI tools list and restrict unapproved (shadow) tools?
Evidence: Approved tools list and enforcement evidence (e.g., web filtering config)
- ☐ D3. Have vendor terms for approved AI tools been reviewed for training-on-your-data, retention, sub-processors and confidentiality? gating
Evidence: Vendor terms review log, DPAs or enterprise agreements
- ☐ D4. Are AI tools accessed through managed accounts (SSO/MFA, role-based access) rather than personal logins?
Evidence: Identity/SSO configuration screenshot or admin export
- ☐ D5. Are retention and deletion rules applied to prompts, outputs and AI-generated documents?
Evidence: Retention settings and policy
- ☐ D6. Is client consent or notice handled where AI processing of their data requires it (contracts, privacy notices, regulated data)?
Evidence: Privacy notice or engagement clause
- ☐ D7. Are AI tools included in security assessments (vendor due diligence, penetration testing scope, cyber insurance disclosures)?
Evidence: Vendor due-diligence questionnaire or security review
- ☐ D8. Do you have a process for data subject or client requests involving AI-processed data (access, deletion, correction)?
Evidence: Request-handling procedure
Domain 3: Operational Controls 20 points
Human review, quality checks, incident response and vendor oversight in day-to-day work.
- ☐ O1. Is human review required before AI-generated content reaches a client, court, regulator or permanent file? gating
Evidence: Review procedure and sample sign-off
- ☐ O2. Are quality checks performed on AI outputs (accuracy, citations, bias, completeness) with results recorded?
Evidence: QA log or sampling report
- ☐ O3. Does the incident response plan explicitly cover AI incidents (data exposure, harmful output, vendor breach, misuse)?
Evidence: Incident response plan (AI section) and exercise record
- ☐ O4. Is there a log of AI incidents and near-misses, and are lessons applied?
Evidence: Incident/near-miss log (redacted)
- ☐ O5. Are AI vendors monitored after onboarding (terms changes, model changes, outages, security notices)?
Evidence: Vendor monitoring record
- ☐ O6. Are changes to AI tools, prompts, templates or automations controlled (approval, testing, rollback)?
Evidence: Change log
- ☐ O7. Are AI-assisted work products identifiable in records (who used what, on which matter, when)?
Evidence: Work-product tagging example or system export
- ☐ O8. Are business-continuity arrangements in place if a critical AI tool is unavailable or withdrawn?
Evidence: Continuity plan extract
Domain 4: Workforce Capability & Training 20 points
Whether your people know the rules, have been trained for their role, and refresh that training.
- ☐ W1. What percentage of staff completed AI awareness training in the last 12 months?
Evidence: LMS or training completion report
- ☐ W2. Is training role-specific (leaders, managers, client-facing staff, technical/IT, procurement)?
Evidence: Training curriculum / role matrix
- ☐ W3. Have all staff acknowledged the AI acceptable-use policy in writing?
Evidence: Acknowledgment records
- ☐ W4. Are staff who review AI output trained on how to review it (verification, citation checks, bias, confidentiality)?
Evidence: Reviewer training materials and completion
- ☐ W5. Have leadership and board members completed AI governance training in the last 12 months?
Evidence: Leadership training record
- ☐ W6. Is training refreshed on a schedule and updated for new tools, laws and incidents?
Evidence: Training schedule / content change log
- ☐ W7. Is there a way for staff to ask questions or raise AI concerns without fear (helpdesk, channel, named contact)?
Evidence: Policy section or channel evidence
- ☐ W8. Does at least one person hold a recognized AI governance credential or equivalent documented competence?
Evidence: Certificate
Domain 5: Transparency & Client Trust 20 points
How you disclose AI use to clients, control marketing claims, and handle complaints.
- ☐ T1. Do engagement letters, terms or client agreements address AI use?
Evidence: Engagement clause
- ☐ T2. Is there a public AI statement or client-facing explanation of how the firm uses and governs AI?
Evidence: URL or document
- ☐ T3. Are AI-related claims in marketing, proposals and RFP responses reviewed for substantiation?
Evidence: Claims review procedure
- ☐ T4. Can the firm answer client AI questionnaires and RFP AI sections consistently and quickly?
Evidence: Answer bank sample
- ☐ T5. Is there a documented path for client complaints or concerns about AI use, with escalation and response times?
Evidence: Complaints procedure
- ☐ T6. Are staff told what they may and may not say to clients and the public about AI use?
Evidence: Communications guidance
- ☐ T7. Is AI use disclosed to regulators, courts or professional bodies where required?
Evidence: Disclosure procedure
- ☐ T8. Does the firm avoid using AI in ways clients would reasonably object to without their knowledge (e.g., recording, profiling, automated decisions)?
Evidence: Use-case review record
How scoring works
A tick on this page is a yes-or-no proxy. The Standard scores each control on four levels, and the difference between them is almost always documentation and review:
| Level | Meaning | Typical evidence |
| 0 | Not in place | Nothing to show |
| 1 | Informal | An email, a verbal rule, "everyone knows" |
| 2 | Defined | Written, approved, communicated |
| 3 | Managed and reviewed | Written, enforced, evidenced in records, reviewed or tested in the last 12 months |
Eight controls per domain give a raw score of 0 to 24, scaled to 20 points. Five domains sum to an AboveBoard Score of 0 to 100. Verified is 60–74, Advanced 75–89 and Leading 90–100; below 60 is "not yet verified," which stays private and comes with a prioritized gap plan. A self-scored result is a provisional score. A verified score is what an independent reviewer confirms from the evidence, and only verified scores appear in the registry with a year-stamped badge.
Two things the score does not do. It does not certify that any AI output is accurate; it verifies that the practices which catch errors exist and are evidenced. And it is not an ISO certification, a CPA audit or a regulatory approval; it is a score and a verification under a private, voluntary standard mapped to the NIST AI RMF and cross-walked to ISO/IEC 42001. The full rubric, with all four levels for every control and the framework mapping, is published in full. What the numbers mean in your industry is on the industry pages, and what closing the gaps costs compared with the alternatives is in How much does an AI audit cost?
Questions
What is an AI governance checklist?
A structured list of the controls an organization should have in place to govern its use of AI, each paired with the evidence that proves it exists. This one contains the 40 controls of the AboveBoard Standard v1.0 across five domains: governance and accountability, data security and privacy, operational controls, workforce capability and training, and transparency and client trust. It is the same question bank the AboveBoard assessment uses.
What are the 6 pillars of AI governance?
Different frameworks count differently. Six-pillar lists typically cover accountability, transparency, fairness, privacy and security, safety and reliability, and human oversight. The AboveBoard Standard organizes the same ground into five scored domains built for firms that use AI rather than build it: governance and accountability, data security and privacy, operational controls (including human oversight and incident response), workforce capability and training, and transparency and client trust. Each domain is worth 20 points.
What are the five pillars of AI readiness?
For a firm that uses AI, readiness means five things you can prove: someone accountable with a written policy and an inventory; client data classified and vendor terms reviewed; a human reviewing AI output with an incident plan behind them; staff trained for their roles and acknowledging the rules; and clients told how AI is used with marketing claims that hold up. Those are the five domains of the AboveBoard Standard, and the free Snapshot scores two questions in each.
How is the AboveBoard Score calculated?
Each of the 40 controls is scored 0 to 3: not in place, informal, defined, or managed and reviewed. The eight controls in each domain give a raw score of 0 to 24, scaled to 20 points. The five domains sum to a score of 0 to 100. Verified 60 to 74, Advanced 75 to 89 and Leading 90 to 100 are listed publicly; below 60 stays private with a gap plan. Three gating controls (G1, D3, O1) must be above zero for any listing.
What is a good AI governance score?
Sixty is the threshold for Verified, which means written and defined practices across all five domains with evidence behind them. Most firms starting from informal guidance score in the 30s to 50s on their first Snapshot and reach Verified within one remediation window, typically by adopting a policy, approving tools with reviewed terms, writing a human-review rule and rolling out training. Advanced (75 to 89) and Leading (90 to 100) require managed, reviewed and tested practices.