← All PostsAI Governance · Interactive Tool

AI Governance Comes Down to 25 Documents You Either Have or You Do Not

Adrian DunkleyJuly 23, 20268 min read
TLDRStrip the philosophy out of AI governance and what remains is a stack of 25 producible deliverables, from an AI charter to an emerging risk roadmap. An auditor, a regulator, an insurer, or an enterprise customer can ask for any one of them, and "we take AI governance seriously" is not an accepted file format. I have arranged the 25 as a bingo board, five themed rows of five, because the arrangement carries information the count alone does not: a complete line is a coherent capability, while the same five documents scattered across the board are just paper. You can now rate your organisation on an interactive 3D version of the board, tile by tile, and get a governance score built from your maturity and your completed lines. Play AI Governance Bingo here.

Somewhere in the second hour of a governance conversation, I ask the question that ends the philosophical portion of the meeting: can you show me the document? Not the intention, not the working group, not the slide that says "responsible AI" over a photograph of a lighthouse. The document. The approved policy pack, the inventory register with a last-updated date, the incident playbook someone has actually rehearsed. In more than 100 board-level engagements across the Caribbean, that one question has separated the organisations that govern AI from the organisations that talk about governing AI faster than any assessment I could run.

The reason the question works is that everyone who will ever test your AI governance from the outside thinks in documents. A regulator working through the EU AI Act's obligations asks for evidence of risk management and human oversight, which means the framework document and the oversight plan. An ISO/IEC 42001 certification audit walks a checklist of required artefacts. An insurer pricing your cyber and AI exposure wants the incident playbook and the vendor assessments. An enterprise customer's procurement team sends a questionnaire whose every row assumes a deliverable exists and asks you to attach it. None of them accepts sincerity as an attachment.

The Board: Five Rows of Five

So here is AI governance with the philosophy stripped out: 25 deliverables, arranged as a bingo board. The arrangement is doing real work. Each row is a theme, read left to right, and each theme is a question an outsider will eventually ask.

Row 1
Foundations
Purpose and objectives (an AI charter), stakeholder identification (a map and engagement plan), governance structure (a RACI and org structure), policies and standards (an approved AI policy pack), and an AI principles statement. The row that answers: who decided, and on what authority?
Row 2
Risk & Data
An AI risk management framework, a data governance plan with roles, an AI inventory register that is approved and current, an impact assessment template in actual use, and a bias and fairness assessment template. The row that answers: do you know what you are running and what it could do?
Row 3
Oversight
Transparency and explainability guidelines, a human oversight plan, security and safety requirements, and a regulatory compliance matrix, around the free centre square. The row that answers: when the system decides something, who can see it, question it, and stop it?
Row 4
Operations
A monitoring plan and dashboard spec, audit log requirements and retention policy, a KPI dashboard specification for value tracking, an AI incident response playbook, and an AI training curriculum with completion records. The row that answers: does governance survive contact with production?
Row 5
The Outside
A third-party AI risk assessment, a data residency and transfer assessment, a governance review report and action log, a governance reporting dashboard, and an emerging AI risk scan and roadmap. The row that answers: what happens where your control ends, and what happens next year?

Read the board vertically and you get a different insight. Every column crosses all five themes, so a complete column means the programme has depth at every layer: a foundation, a risk artefact, an oversight mechanism, an operational system, and an outward-facing control. A complete diagonal is the same idea wearing a sash.

"An auditor never asks whether you have 14 governance documents. They pick a theme and pull the thread until the evidence runs out. That is a bingo line, played against you."

Why the Arrangement Beats the Count

This is why I built the tool as bingo rather than a checklist, and it is the part most governance scoring gets wrong. Fourteen completed deliverables scattered randomly across the board describe an organisation that reacted to fourteen different external prompts: an auditor asked for this, a customer demanded that, a conference scared someone into a third thing. Fourteen completed deliverables that include two full rows describe an organisation that finished what it started, theme by theme. Same count, different organisation.

External scrutiny follows lines too. A regulator examining your risk posture will ask for the framework, then the inventory it depends on, then the impact assessments the framework mandates, then the fairness reviews the assessments require. That is row two, asked in order, and the questioning stops being comfortable at the first gap. An organisation with a complete row survives the thread-pull. An organisation with a scattered count does not, no matter how impressive the count looked on a maturity slide.

The interactive version of the board scores both dimensions. Each tile takes one of four ratings: not started, started, underway, or complete, where complete means approved, in use, and kept current, not "a draft exists on someone's laptop". Maturity across the 24 rateable tiles carries 70 of the 100 points. Every fully complete line, out of the 12 available across rows, columns, and both diagonals, adds 2.5 more. The centre square is free, as bingo tradition demands; it sends you to the AI Boss Assessment instead of asking for paperwork.

Play AI Governance Bingo →A 3D board of all 25 deliverables. Click each tile, rate how far along you are, and get a governance score from your maturity and your completed lines. Free, no signup, a few minutes.

The Standard Is "Approved and In Use", Not "Exists"

A warning from the rooms where I run this exercise: the strongest temptation is to rate a deliverable complete because a file with roughly the right name exists. The policy pack drafted in 2024 and never taken to the board is not complete. The inventory register that was accurate the week it was built and never touched again is not complete. Documents are evidence of governance only while somebody maintains them, and the outsiders who ask for your deliverables have a practised eye for paperwork that was generated the week before the audit.

The tool takes the same position. The gap between "underway" and "complete" is approval and adoption, and the scoring rewards crossing that gap more than it rewards opening another front. Converting one drafted deliverable into an approved one moves your score more than starting two new drafts, which mirrors what I tell every board that asks where to spend the next quarter: finish before you start.

There is a decay problem on the other side of completion. Registers go stale, training cohorts graduate and are replaced by untrained hires, and a governance review report from two years ago is closer to an archaeological find than a control. Boards that hold their score re-play the board quarterly and treat any tile that has not been touched in a year as suspect. Governance is a subscription, and the outside world checks whether you are still paying.

What I Do With the Data

Selections on the board are stored anonymously, and I want to be plain about why. The Caribbean has no regional picture of AI governance readiness: no dataset showing which deliverables organisations have, which they lack, and where the common gaps sit. Every play of the board contributes a data point to exactly that picture, which feeds the training and policy work I do through StarApple AI and the Caribbean AI Risk Management Council. Leave your email if you want the follow-up material; skip it if you do not. The board state is useful either way, and it is never tied to your name unless you choose to give one.

Boards that want more than a score have two places to go. The Board AI Audit examines whether your board can actually oversee the programme these 25 deliverables make up. And the Board AI Programme is the full engagement: the curriculum, the scorecard, and the build session that turns a bingo card of gaps into a working governance programme with named owners. Between the free board and the full programme sits a simple test you can run today: open the tool, rate honestly, and see whether you can call a single line. Most organisations cannot. The ones that can tend to already know exactly which line it is.

Adrian Dunkley, the Caribbean's leading AI expert, has led more than 100 board-level AI engagements through StarApple AI. Play AI Governance Bingo, explore the Board AI Programme, or write to insights@starapple.ai to talk about closing the gaps on your board.

Frequently Asked Questions

What are the 25 deliverables of AI governance?

They run in five themed rows of five. Foundations: an AI charter, a stakeholder map and engagement plan, a governance RACI, an approved AI policy pack, and an AI principles statement. Risk and data: an AI risk management framework, a data governance plan, an AI inventory register, an impact assessment template, and a bias and fairness assessment template. Oversight: transparency and explainability guidelines, a human oversight plan, security and safety requirements, and a regulatory compliance matrix. Operations: a monitoring plan, audit log requirements, a KPI dashboard specification, an incident response playbook, and a training curriculum with completion records. The outside world: a third-party AI risk assessment, a data residency and transfer assessment, a governance review report, a governance reporting dashboard, and an emerging AI risk scan and roadmap. Each is a document an auditor can request.

What is AI Governance Bingo and how is the score calculated?

AI Governance Bingo is a free interactive 3D tool that puts the 25 deliverables on a bingo board. You rate each tile as Not Started, Started, Underway, or Complete. Maturity across the 24 rated tiles carries 70 points, and each fully complete line of five, across 12 possible lines, adds 2.5 points, for a score out of 100 with a maturity band from Ad Hoc to Audit-Ready.

Why do completed lines matter in AI governance?

Because external scrutiny follows themes, not counts. The board's rows are themed, so a complete row means an auditor can pull the whole thread of a topic, from framework to evidence, without hitting a gap. Columns cross all five themes, so a complete column shows the programme has depth at every layer. Scattered documents with the same total count fail the same questioning quickly.

Who should play AI Governance Bingo?

Boards of directors, executives, and risk, compliance, and technology leaders accountable for AI use. It takes a few minutes and no technical background. Boards that want the deeper engagement can follow it with the Board AI Audit or the full Board AI Programme.

AI GovernanceGovernance DeliverablesAI Governance BingoAI PolicyAI RiskBoards of DirectorsAI Boss Tools
About the Author: Adrian Dunkley, The AI Boss

Adrian Dunkley is the founder of the Caribbean's first AI company, a distinction that placed him at the frontier of the region's technology transformation nearly two decades ago. Known across the Caribbean and internationally as the AI Boss, and recognized widely as the Godfather of Caribbean AI for the thousands of Caribbeans he has trained in artificial intelligence, he has launched and supported dozens of AI ventures spanning climate resilience, education, healthcare, agriculture, finance, and public policy. His work building the Caribbean AI ecosystem stretches from boardrooms and CARICOM meeting rooms to community centres across the region, bringing AI literacy and economic opportunity to the people and places that need it most. He founded StarApple AI and chairs the Caribbean AI Risk Management Council, and his PhD research in Climate Physics focuses on GenAI-powered climate models built to give small island states the forecasting power that has historically belonged only to wealthy nations. Beyond business and research, Adrian leads nonprofit initiatives and philanthropy programs that have extended AI knowledge and access to underserved populations across the region for close to two decades. He is a sought-after advocate for Caribbean AI policy, a voice for the region in global technology conversations, and an unwavering believer that Caribbean resilience in the age of economic and climate volatility depends on Caribbean people owning the tools of that resilience, not merely consuming forecasts and price shocks built by someone else's crisis.

Connect ↗