AI Governance Assessment Tool

Sample governance report.

This public sample shows the type of human-review output the assessment workflow can generate: risk drivers, missing evidence, oversight steps, vendor questions, and approval conditions.

High risk

Executive summary

Based on the information provided, AI system to help prioritize grant applications is a preliminary high risk assessment with a total rule-based score of 31. The use case is at the Procurement stage in Canada and should be reviewed against official organizational, legal, privacy, security, and procurement requirements before deployment.

Risk register

RiskSeverityLikelihoodMitigationEvidence needed
Rights, benefits, services, or opportunities impact
The use case could influence access to services, rights, funding, employment, education, health, housing, immigration, justice, or similar interests.
SevereHighComplete impact assessment, legal/privacy review, and recourse design before deployment.Policy rationale, owner, controls, and review evidence.
Lack of testing
Testing, bias review, or post-deployment monitoring is incomplete or unclear.
SevereHighRun evaluation, bias, security, red-team, and monitoring tests before launch.Evaluation plan, test results, monitoring plan, incident process.
Sensitivity of data
The system may use sensitive or regulated data requiring privacy, security, and minimization controls.
HighHighApply data minimization, retention limits, access controls, and privacy impact review.PIA, data inventory, retention schedule, access controls.
Scale of deployment
Deployment scale is organization-wide.
HighHighPilot with monitoring and phased expansion before broader rollout.Policy rationale, owner, controls, and review evidence.
Vendor dependence
Vendor dependency appears limited or has not been specified.
HighHighClose contract, audit, data-use, incident, and subcontractor gaps.Vendor documentation, contract terms, audit logs, data processing terms.

Missing information

  • No items flagged.

Human oversight plan

  • Accountable owner: Grant Program Executive
  • Reviewer role: Human review is identified; document reviewer authority and independence.
  • Review frequency: Set review cadence based on deployment stage, risk level, and incident history.
  • Override mechanism: Create a documented override mechanism.
  • Escalation process: Define escalation for uncertain, disputed, or high-impact outputs.
  • Appeal or recourse process: Create challenge, correction, or appeal pathways where people may be affected.

Vendor due diligence

  • Model documentation or model card
  • Data usage, retention, and training terms
  • Audit logs and administrative visibility
  • Security certifications or security review evidence
  • Incident reporting timelines and responsibilities
  • Subcontractor list and change notification

Approval checklist

  • Complete missing intake information
  • Confirm accountable owner and human oversight responsibilities
  • Complete privacy, security, and legal review where required
  • Document testing results, bias review, and limitations
  • Finalize vendor due diligence and contract protections
  • Create incident logging, monitoring, rollback, and escalation processes

Responsible use note

This report is a structured review aid, not an automated approval decision. It is intended to support accountable human review, legal and privacy assessment, procurement checks, and ongoing monitoring.