PRIVINOTCH / Focus areas / Due diligence checklist
The AI governance due diligence checklist
Forty questions across eight areas, each with the evidence to ask for and a simple scoring guide. Use it to assess a target, a supplier or your own organisation.
Free. A PDF you can use straight away.
Eight areas, forty questions
Each question has a yes, partly or no scale and a prompt for the evidence you should expect to see.
Strategy and accountability
Who owns AI risk, what the board sees, and whether policy is real.
AI inventory and classification
Whether the organisation knows where AI is used and how it is risk-rated.
Data, IP and rights
Provenance of data, licences and ownership of models and outputs.
Risk and impact assessment
How risk, bias and impact are identified, rated and treated.
Models, testing and oversight
Validation, monitoring, explainability and meaningful human oversight.
Third parties and dependencies
Supplier and foundation-model oversight, and concentration risk.
Security, incidents and monitoring
AI-specific threats, logging and incident response.
Regulatory and standards alignment
Readiness for the EU AI Act, UK GDPR and recognised frameworks.
Download it free
Tell us where to send it. The download link appears as soon as you submit the form.
- A scoring guide to turn answers into a view of maturity
- Evidence prompts for every question
- Useful for buy-side, sell-side and internal reviews