Back to Resources

    Practical checklist

    AI Accountability Readiness Checklist

    A practical 20-question conversation starter for material AI-enabled workflows.

    15 minutesBuildMoat executive resource

    How to use this checklist

    Use this checklist to identify where governance is clear and where accountability may be fragmented as AI moves from assistance toward recommendation, workflow initiation or bounded execution.

    It is not legal advice, an audit, regulatory certification or a compliance score. It is a structured starting point for conversation between business, Technology, Risk and Compliance.

    For each question, choose Yes, Partly or No. Yes means evidence exists and is current. Partly means some elements exist but are incomplete, inconsistent or not evidenced. No means the firm cannot currently demonstrate this.

    A. Authority

    1. Have we identified the AI-enabled workflows that can influence, initiate or execute a material action?
    2. Does each priority workflow have an explicitly approved business purpose and permitted-autonomy level?
    3. Are prohibited actions, escalation thresholds and human-approval requirements documented?
    4. Are authority limits defined for relevant customer, product, jurisdiction, transaction or operational-risk boundaries?

    B. Accountability

    1. Does each priority workflow have a named business owner accountable for the outcome?
    2. Is executive sponsorship and relevant senior accountability clear?
    3. Are first-line operation, Technology/Data ownership and independent Risk/Compliance challenge distinct?
    4. Is there documented authority for approving material changes, accepting exceptions and suspending use?

    C. Context and access

    1. Can we identify the model/provider, workflow version and material configuration used by each priority workflow?
    2. Are prompts, retrieval sources, data sources, APIs, tools and third parties documented?
    3. Are data and tool permissions bounded, reviewed and appropriate to the use case?
    4. Are material changes to models, prompts, data, tools, permissions or customer scope assessed before release?

    D. Evidence and assurance

    1. Can we capture or retrieve a record of material AI-enabled actions and relevant human decisions?
    2. Can we identify the applicable mandate, control boundary and approval state at the time of a material action?
    3. Can an independent reviewer reconstruct a material outcome without relying on informal recollection or a prolonged manual investigation?
    4. Are evidence access, protection and retention requirements defined proportionately?

    E. Intervention and learning

    1. Are there defined triggers for escalation, additional review or suspension of a workflow?
    2. Can a named individual or team restrict tools, access, authority or use of the workflow promptly?
    3. Is there a tested fallback, incident-management and customer-remediation approach where relevant?
    4. Does management receive useful information on exceptions, overrides, errors, complaints, incidents, changes and remediation?

    Results guidance

    Indicative resultInterpretationSuggested next step
    0–7Accountability is likely fragmented or largely undocumented.Establish an inventory, owners and basic autonomy classifications.
    7.5–13Governance foundations exist, but priority evidence or intervention gaps likely remain.Review one material workflow in depth and define a minimum accountability record.
    13.5–17The operating model is forming, but consistency and assurance require attention.Standardise controls, evidence and change governance.
    17.5–20Strong foundations for controlled autonomy.Test resilience, challenge effectiveness and ongoing outcome monitoring.

    Turn the checklist into an executive action plan

    BuildMoat’s AI Accountability Diagnostic applies this framework to your priority AI workflows, maps accountable ownership and provides a 90-day roadmap.

    This resource provides practical governance guidance for discussion and planning. It is not legal advice, an audit, regulatory certification, a compliance score or a substitute for your firm’s own legal, regulatory, risk and governance decisions.