🟢AI Policy Readiness Checklist 🟢
(For public sector, health and education)
Score your gaps in 10 minutes. Red flags mean audit risk
# Question Check Now Yes/No
ISO 42001 Compliance & EU AI Act

Do you have a written AI policy or AI‑use guidelines?
YES ☐ NO ☐
Does the policy define high‑risk vs. low‑risk AI uses?
YES ☐ NO ☐
Are there clear rules for what AI can and cannot be used for?
YES ☐ NO ☐
Do you have an AI lead or governance group defined?
YES ☐ NO ☐
Is there a risk‑tiering process for new AI tools?
YES ☐ NO ☐
Do you maintain an AI inventory or algorithmic‑transparency register?
YES ☐ NO ☐
Is there mandatory staff training on AI policy?
YES ☐ NO ☐
Are there incident‑reporting routes for AI‑related issues?
YES ☐ NO ☐
Do you conduct regular AI‑risk assessments or DPIAs?
YES ☐ NO ☐
Is AI use aligned with data protection, equality, and security policies?
YES ☐ NO ☐
Do you have vendor‑due‑diligence processes for AI suppliers?
YES ☐ NO ☐
Is the AI policy reviewed annually or after significant changes?
YES ☐ NO ☐
SCORE: ___/12
10-12 🟢 Strong – Annual review recommended, 7-9 🟡 Watch – Fix yellow gaps in 30 days, <7 🔴 DANGER – Audit risk imminent.
