Somewhere in the second hour of a governance conversation, I ask the question that ends the philosophical portion of the meeting: can you show me the document? Not the intention, not the working group, not the slide that says "responsible AI" over a photograph of a lighthouse. The document. The approved policy pack, the inventory register with a last-updated date, the incident playbook someone has actually rehearsed. In more than 100 board-level engagements across the Caribbean, that one question has separated the organisations that govern AI from the organisations that talk about governing AI faster than any assessment I could run.
The reason the question works is that everyone who will ever test your AI governance from the outside thinks in documents. A regulator working through the EU AI Act's obligations asks for evidence of risk management and human oversight, which means the framework document and the oversight plan. An ISO/IEC 42001 certification audit walks a checklist of required artefacts. An insurer pricing your cyber and AI exposure wants the incident playbook and the vendor assessments. An enterprise customer's procurement team sends a questionnaire whose every row assumes a deliverable exists and asks you to attach it. None of them accepts sincerity as an attachment.
The Board: Five Rows of Five
So here is AI governance with the philosophy stripped out: 25 deliverables, arranged as a bingo board. The arrangement is doing real work. Each row is a theme, read left to right, and each theme is a question an outsider will eventually ask.
Foundations
Risk & Data
Oversight
Operations
The Outside
Read the board vertically and you get a different insight. Every column crosses all five themes, so a complete column means the programme has depth at every layer: a foundation, a risk artefact, an oversight mechanism, an operational system, and an outward-facing control. A complete diagonal is the same idea wearing a sash.
Why the Arrangement Beats the Count
This is why I built the tool as bingo rather than a checklist, and it is the part most governance scoring gets wrong. Fourteen completed deliverables scattered randomly across the board describe an organisation that reacted to fourteen different external prompts: an auditor asked for this, a customer demanded that, a conference scared someone into a third thing. Fourteen completed deliverables that include two full rows describe an organisation that finished what it started, theme by theme. Same count, different organisation.
External scrutiny follows lines too. A regulator examining your risk posture will ask for the framework, then the inventory it depends on, then the impact assessments the framework mandates, then the fairness reviews the assessments require. That is row two, asked in order, and the questioning stops being comfortable at the first gap. An organisation with a complete row survives the thread-pull. An organisation with a scattered count does not, no matter how impressive the count looked on a maturity slide.
The interactive version of the board scores both dimensions. Each tile takes one of four ratings: not started, started, underway, or complete, where complete means approved, in use, and kept current, not "a draft exists on someone's laptop". Maturity across the 24 rateable tiles carries 70 of the 100 points. Every fully complete line, out of the 12 available across rows, columns, and both diagonals, adds 2.5 more. The centre square is free, as bingo tradition demands; it sends you to the AI Boss Assessment instead of asking for paperwork.
Play AI Governance Bingo →A 3D board of all 25 deliverables. Click each tile, rate how far along you are, and get a governance score from your maturity and your completed lines. Free, no signup, a few minutes.The Standard Is "Approved and In Use", Not "Exists"
A warning from the rooms where I run this exercise: the strongest temptation is to rate a deliverable complete because a file with roughly the right name exists. The policy pack drafted in 2024 and never taken to the board is not complete. The inventory register that was accurate the week it was built and never touched again is not complete. Documents are evidence of governance only while somebody maintains them, and the outsiders who ask for your deliverables have a practised eye for paperwork that was generated the week before the audit.
The tool takes the same position. The gap between "underway" and "complete" is approval and adoption, and the scoring rewards crossing that gap more than it rewards opening another front. Converting one drafted deliverable into an approved one moves your score more than starting two new drafts, which mirrors what I tell every board that asks where to spend the next quarter: finish before you start.
There is a decay problem on the other side of completion. Registers go stale, training cohorts graduate and are replaced by untrained hires, and a governance review report from two years ago is closer to an archaeological find than a control. Boards that hold their score re-play the board quarterly and treat any tile that has not been touched in a year as suspect. Governance is a subscription, and the outside world checks whether you are still paying.
What I Do With the Data
Selections on the board are stored anonymously, and I want to be plain about why. The Caribbean has no regional picture of AI governance readiness: no dataset showing which deliverables organisations have, which they lack, and where the common gaps sit. Every play of the board contributes a data point to exactly that picture, which feeds the training and policy work I do through StarApple AI and the Caribbean AI Risk Management Council. Leave your email if you want the follow-up material; skip it if you do not. The board state is useful either way, and it is never tied to your name unless you choose to give one.
Boards that want more than a score have two places to go. The Board AI Audit examines whether your board can actually oversee the programme these 25 deliverables make up. And the Board AI Programme is the full engagement: the curriculum, the scorecard, and the build session that turns a bingo card of gaps into a working governance programme with named owners. Between the free board and the full programme sits a simple test you can run today: open the tool, rate honestly, and see whether you can call a single line. Most organisations cannot. The ones that can tend to already know exactly which line it is.
Adrian Dunkley, the Caribbean's leading AI expert, has led more than 100 board-level AI engagements through StarApple AI. Play AI Governance Bingo, explore the Board AI Programme, or write to insights@starapple.ai to talk about closing the gaps on your board.
Frequently Asked Questions
What are the 25 deliverables of AI governance?
They run in five themed rows of five. Foundations: an AI charter, a stakeholder map and engagement plan, a governance RACI, an approved AI policy pack, and an AI principles statement. Risk and data: an AI risk management framework, a data governance plan, an AI inventory register, an impact assessment template, and a bias and fairness assessment template. Oversight: transparency and explainability guidelines, a human oversight plan, security and safety requirements, and a regulatory compliance matrix. Operations: a monitoring plan, audit log requirements, a KPI dashboard specification, an incident response playbook, and a training curriculum with completion records. The outside world: a third-party AI risk assessment, a data residency and transfer assessment, a governance review report, a governance reporting dashboard, and an emerging AI risk scan and roadmap. Each is a document an auditor can request.
What is AI Governance Bingo and how is the score calculated?
AI Governance Bingo is a free interactive 3D tool that puts the 25 deliverables on a bingo board. You rate each tile as Not Started, Started, Underway, or Complete. Maturity across the 24 rated tiles carries 70 points, and each fully complete line of five, across 12 possible lines, adds 2.5 points, for a score out of 100 with a maturity band from Ad Hoc to Audit-Ready.
Why do completed lines matter in AI governance?
Because external scrutiny follows themes, not counts. The board's rows are themed, so a complete row means an auditor can pull the whole thread of a topic, from framework to evidence, without hitting a gap. Columns cross all five themes, so a complete column shows the programme has depth at every layer. Scattered documents with the same total count fail the same questioning quickly.
Who should play AI Governance Bingo?
Boards of directors, executives, and risk, compliance, and technology leaders accountable for AI use. It takes a few minutes and no technical background. Boards that want the deeper engagement can follow it with the Board AI Audit or the full Board AI Programme.