AI Boss Tools | Diagnostic 14 • Back to the Hub
Frameworks describe functions. Auditors ask for artefacts. This checklist scores the twelve concrete things an auditor, insurer, regulator, or enterprise customer will actually ask to see, drawn from ISO/IEC 42001 and the NIST AI RMF: the policy, the owner, the inventory, the controls, the training, and the evidence.
ISO/IEC 42001, published in December 2023, is the first international management system standard for AI. Like ISO 27001 before it, it turns good intentions into checkable artefacts: documents, roles, records, and reviews that either exist or do not. The EU AI Act adds legal force, including an AI literacy duty for staff that has applied since February 2025.
Most organisations are further behind than they think. IBM's 2025 breach study found 63 percent still have no AI governance policy at all, which means the other eleven artefacts on this list cannot exist either.
Each item scores from "does not exist" to "in place and maintained". If you want the maturity view of how well these functions operate, take the AI Governance Readiness Check after this one. This checklist tells you what is missing; that one tells you how well what exists actually works.
The first international AI management system standard, published December 2023. The artefact structure of this checklist follows its clauses: policy, roles, risk and impact assessment, lifecycle controls, and improvement.
The AI literacy obligation: providers and deployers must ensure staff have sufficient AI competence. In force since 2 February 2025.
63 percent of organisations have no AI governance policy. Ungoverned AI use measurably raises breach cost.
A scored breakdown across all four artefact groups, a median benchmark, the specific missing artefact to build next in each group, and a downloadable one-pager. Free once you enter your name and email.