AI Governance & Compliance Checklist
Reviews an AI-related workflow, tool, or output against a practical governance checklist covering data privacy, bias, accountability, and transparency.
AI Governance & Compliance Checklist is a free AI skill for safety, privacy & compliance. Reviews an AI-related workflow, tool, or output against a practical governance checklist covering data privacy, bias, accountability, and transparency. It works with Claude, ChatGPT, Cursor and is ready to use out of the box.
About this skill
AI Governance & Compliance Checklist walks a proposed AI use case, workflow, or output through a structured review: what data it touches, who is accountable for its decisions, whether outputs are explainable, whether bias or fairness risks exist, and whether disclosure to affected people is needed. It produces a short risk rating plus concrete, prioritized fixes rather than a vague warning, so teams can move from AI experimentation to responsible production use without hiring a compliance specialist for every review.
What it does
Given a description of an AI workflow, tool, or specific output (e.g. an AI-assisted hiring screen, a customer-facing chatbot, an automated report), the skill runs it through six governance dimensions — data privacy, bias/fairness, transparency, accountability, human oversight, and regulatory exposure — flags concrete risks with severity, and lists specific next steps to close each gap.
What is included
- Six-dimension governance review framework
- Risk severity rating scale (low/medium/high)
- Prioritized remediation checklist per flagged risk
- Disclosure and human-oversight recommendation templates
- Regulatory exposure flagging (general, non-legal-advice guidance)
How to use it
1. Download the SKILL.md file 2. Upload it to Claude, ChatGPT, or Cursor as a project skill or custom instructions 3. Describe the AI workflow, tool, or output you want reviewed 4. Receive a risk-rated governance review with prioritized fixes
Examples
We're using an AI tool to auto-screen job applicant resumes and reject the bottom 40% before a human ever sees them.
Governance review: - Bias/fairness: HIGH — automated rejection without human review on any candidate is a common source of disparate-impact risk; recommend human review before final rejection, not just before advancement - Human oversight: HIGH — no human touches rejected candidates at all; add a spot-check or full review step - Transparency: MEDIUM — candidates likely aren't told AI was used in screening; consider a disclosure statement - Data privacy: LOW — resume data use appears limited to its stated purpose - Accountability: MEDIUM — no named owner identified for tool outcomes; assign one - Regulatory exposure: VERIFY — several jurisdictions now require disclosure or audit for automated hiring decisions; confirm with legal counsel for your specific location Top 3 fixes: 1) add human review before rejection, 2) add applicant disclosure, 3) assign an accountable owner.
FAQ
What is this skill for?
How do I install it?
Is this a substitute for legal advice?
What kinds of AI use cases can it review?
How is this different from a generic AI ethics checklist?
Do I need existing governance policies in place to use it?
Related Skills
Vendor & Third-Party Risk Assessor
Reviews a described vendor or third-party tool for data, security, and dependency risk before you sign, returning a rated checklist with the real blockers.
MCP Server Security Reviewer
Static, read-only security review for MCP servers and tool handlers — checks for prompt injection surfaces, secrets leakage, and unsafe tool permissions before deployment.
Privacy and Data Handling Reviewer
Review a product or workflow for privacy and data-handling risks, then create practical controls, documentation needs, and remediation priorities.
Related Prompts
Vendor Security & Compliance Risk Review
Systematically evaluate a third-party vendor or tool for security, data privacy, and compliance risk before integrating it into your business.
AI Bias & Fairness Review
Review an AI-assisted decision, ranking, recommendation, or generated output for unfair assumptions, proxy variables, unequal errors, and missing oversight.
Privacy-Safe Data Sharing Review
Review text, files, screenshots, or datasets before sharing them with an AI tool, vendor, colleague, or public audience.
Related Articles
AI Governance Is Moving from Principles to Controls
AI governance is shifting from broad principles toward operational controls such as inventories, evaluations, permissions, incident response, evidence, and human approval.
AI Safety and Governance After GPT-5.6 and Fable 5
A practical examination of jailbreaks, safety routing, export controls, release gates, product security, and governance for frontier LLM systems.
Enterprise AI Adoption Is Becoming a Governance Problem
Enterprise AI is shifting from simple assistant access toward controls, orchestration, governance, cost awareness, and measurable workflow value.