PRIVINOTCH  /  Focus areas  /  Due diligence checklist

The AI governance due diligence checklist

Forty questions across eight areas, each with the evidence to ask for and a simple scoring guide. Use it to assess a target, a supplier or your own organisation.

Free. A PDF you can use straight away.

What is inside

Eight areas, forty questions

Each question has a yes, partly or no scale and a prompt for the evidence you should expect to see.

01

Strategy and accountability

Who owns AI risk, what the board sees, and whether policy is real.

02

AI inventory and classification

Whether the organisation knows where AI is used and how it is risk-rated.

03

Data, IP and rights

Provenance of data, licences and ownership of models and outputs.

04

Risk and impact assessment

How risk, bias and impact are identified, rated and treated.

05

Models, testing and oversight

Validation, monitoring, explainability and meaningful human oversight.

06

Third parties and dependencies

Supplier and foundation-model oversight, and concentration risk.

07

Security, incidents and monitoring

AI-specific threats, logging and incident response.

08

Regulatory and standards alignment

Readiness for the EU AI Act, UK GDPR and recognised frameworks.

Get the checklist

Download it free

Tell us where to send it. The download link appears as soon as you submit the form.

  • A scoring guide to turn answers into a view of maturity
  • Evidence prompts for every question
  • Useful for buy-side, sell-side and internal reviews

Thank you. Your checklist is ready. Download the PDF

We use your details to send you the checklist and, where relevant, to follow up about our services. See our Privacy Notice.

Questions

Frequently asked

Who is the checklist for?
Investors, acquirers, procurement and risk teams assessing a company that builds or relies on AI, and founders or leaders who want to see their own governance through that lens.
Is it free?
Yes. Enter your details and the download appears on this page.
How is it organised?
Eight sections covering strategy and accountability, AI inventory, data and IP, risk and impact, models and oversight, third parties, security and incidents, and regulatory alignment. Each question has an answer scale and a suggestion of evidence to ask for.
Is it legal advice?
No. It is a governance and risk tool. It does not determine legal compliance in any jurisdiction.
What will you do with my details?
We use them to send you the checklist and to follow up about our services where relevant. You can ask us to stop at any time. See our Privacy Notice for details.