ChecklistAI Governance Compliance Checklist
Six steps across EU AI Act, SOC 2 and California AI rules — discovery, risk classification, sensitive-data detection, audit trail, pre-send policy, reporting. Mapped to deadlines with implementation guidance.
Read the full checklist → AssessmentShadow AI Risk Assessment
Four questions that establish whether you can see your shadow AI at all: which providers are in use, what data is going into prompts, which interactions exposed something, and whether you have an audit trail to prove it.
Start with the shadow AI guide → TemplateAI Acceptable Use Policy Template
Three-tier classification framework, monitor-coach-enforce model, department scoping. Ready to adapt for your organization.
Read the policy guide → FrameworkAI Asset Inventory Framework
Three discovery channels (workspace API audit, browser-level detection, network/DNS analysis), a two-axis risk scoring framework, and continuous discovery in place of point-in-time audits.
Read the inventory guide → ChecklistMCP Security Checklist (OWASP Top 10)
Four MCP risks explained in depth — tool poisoning, prompt injection via tool results, context spoofing, insecure memory references — from OWASP's MCP Top 10, plus a five-step governance framework for AI coding assistants.
Read the MCP security guide →