How to Do an AI Governance Review: What Are the Key Components of an AI Governance Policy?

Fast forward to 2027. If your Internal Audit team isn’t providing assurance and advice around your organization’s AI use and governance, will your role genuinely matter?
Internal Audit must take on this work to stay relevant in the age of AI. We have the right skills, mindset, and independent perspective. If we leave this work to consultants, what will they need us for?
As I write in the introduction of the Internal Audit Collective’s soon-to-be-released AI Governance Playbook for Internal Audit, “Internal Auditors should be actively providing advice and assurance over AI because it is the defining business topic of our time. If you’re not providing advice or assurance over AI, are you really risk-focused?”
I truly believe that Internal Audit’s ability to take on this work is central to ensuring our profession’s relevance. That’s why we’ve pulled together lessons learned, leading practices, example scopes, key project activities, and other insights from 50+ Internal Audit Collective members with real-world experience conducting AI governance assurance and advisory projects.
We are all learning as we go. Why not learn from each other?
The complete 50-page eBook will be available for download on Monday, July 27, 2026. We’re also holding a webinar in September 2026, featuring an incredible panel of Internal Audit leaders sharing their first-hand insights and experience conducting AI governance reviews.
In the meantime, here’s an excerpt from “Section Four: Key AI Governance Project Steps and Questions.” Every organization needs a solid AI policy, so we compiled the available guidance to come up with a list of 20 core components. As shown here, every AI governance project step is accompanied by real-world practitioner examples. Moving from theory to practice is what the eBook is all about.
AI Governance Policy Assessment: The Basics
An organizational policy for AI use and governance is obviously foundational. Your policy is ground zero for reducing risk, ensuring compliance, protecting people and data, increasing awareness, and promoting safe, responsible, ethical AI use. Of course, as use cases change and new technologies are introduced, your AI policy will necessarily evolve.
If you don’t have an AI policy, a cross-functional AI governance board should create one. Boards often include executive leadership, Legal, Compliance, Risk, IT, HR, Operations, Product, and other relevant teams, with senior leadership giving final sign off. Internal Audit can offer advice. NIST’s AI RMF, ISO/IEC 420001, and the OECD AI Principles are great resources for guiding policy creation.
AI policy should align with existing IT policies, so that the policies present a unified, coherent message. Your AI policy should also explicitly define what’s considered AI and other key terms.
20 Core AI Policy Components
1. Purpose
Why does the policy exist? Include the goals for AI use and risks the policy manages.
2. Scope
Who and what does the policy apply to? Include covered users, systems, and use cases; any jurisdiction-specific considerations; and shadow AI use of unsanctioned tools.
3. Definitions
What key terms and concepts must be defined to ensure policies are enforceable and interpretations are consistent? IAPP’s glossary is a good place to start.
4. Guiding Principles
What high-level governance principles must AI use follow? Examples: Reliability/safety, privacy/security, fairness, transparency, accountability.
5. Governance and Accountability
Who owns AI risk? Who is responsible for what? Define roles and specific responsibilities (e.g., approvals, risk classification, signoffs on high-risk use cases, incident investigation, compliance monitoring, inventory maintenance, documentation).
6. Approved and Prohibited Use Cases
What is and isn’t allowed? Clearly define permitted, restricted (i.e., approval required), and prohibited use cases.
7. Risk Classification
How are use cases classified to guide risk management and controls? Define tiers (e.g., high, medium, low) and specific requirements for each (e.g., approvals, testing, documentation, monitoring, human review, security/privacy controls).
8. Data Privacy
What data can be used with AI? Provide explicit rules for data classification (including permitted tool classes for each type), retention, deletion, storage, third-party use, etc.
9. Security
What security controls are required for AI tools and AI-enabled workflows? Examples: Authentication, SSO, encryption, access controls, logging/monitoring, secure API usage, environment segregation (testing vs. production), vulnerability management, incident escalation.
10. Human Review
When and how must humans validate AI outputs? Examples: Fact-checking, pre-deployment testing and validation, handling of low-confidence outputs. Reviews should be proportional to use cases’ risk and impact.
11. Fairness
What requirements support fairness and control bias? Especially critical if AI impacts people (e.g., access, eligibility, ranking, treatment).
12. Disclosure Requirements
When must AI use be disclosed internally or externally? Consider legal, regulatory, and sector-specific obligations.
13. Inventory and Documentation
What must be registered and how? Examples: Audit trail requirements, retention periods, metadata (e.g., owner, purpose, data used, risk level).
14. Training
What must employees do before using AI tools? Examples: Role-based training; acknowledge obligations (e.g., verify outputs, protect data, report issues); policy compliance.
15. Third-Party Management
How is risk managed if the organization uses third-party AI tools? Examples: Security/privacy due diligence, contract requirements, audit rights, incident notification.
16. AI Development Lifecycle (Optional)
If the organization develops its own AI, what lifecycle controls are required? Examples: Use case intake and approval, data sourcing/documentation, testing/validation, deployment approvals, monitoring, drift detection, retraining, decommissioning.
17. Compliance Monitoring
How will compliance be checked and enforced? Examples: Monitoring, audit rights, periodic reviews, metrics/KPIs, remediation, consequences for noncompliance.
18. Incident Response
How will AI-related incidents be reported and managed? Define what constitutes reportable incidents, how to report and to whom, who triages and remediates, etc.
19. Exceptions
Who can request a policy exception and how? Specify required documentation, approval authority, compensating controls, renewal requirements, and time limits.
20. Policy Ownership and Change Management
Who owns the policy, and how will it be reviewed and renewed? Define review frequency, triggers for interim updates, and employee notification.
AI Governance Policy Considerations: Real-World Examples
Many teams are finding that AI governance is blurring the traditional separation between the three lines, providing the opportunity to work alongside first- and second-line teams on key AI awareness, training, and risk documentation activities.
“We're all jumping in together, trying to figure out what makes sense and what's best-suited for our company — how we want to use AI, and more importantly, how we don't want to use it. Everyone’s rowing the same direction.” — Will Trice, Director of Internal Audit
Some Internal Audit leaders are fielding requests from the business for more specific policy guidance.
“Control owners want guidance on how to think through using AI in their controls. We have an AI governance policy, but control owners have been very hesitant to start using AI in a performance of a SOX control, because they don't want to have a deficiency and they don't have clear guidance on what to consider. So that's something worth thinking about: How can we make a policy for them?” — Danielle Psholka, Financial Control Risk Team Lead
THE LAST WORD: Take on AI Governance With Confidence
If you can believe it, the policy guidance above comprises only 2 of the eBook’s 50+ pages. While our goal was to keep the guidance simple enough not to be overwhelming, we were also determined to pack in as many real-world practitioner insights and leading practices as possible.
I honestly couldn’t be any prouder of this eBook.
The AI Governance Playbook for Internal Audit: A Practical Guide to Providing AI Assurance and Advisory Services is an exceptional representation of the Internal Audit Collective members’ commitment not only to helping each other, but to moving the profession forward.
Look for the announcement in your inbox and the Internal Audit Collective forum next week, July 27th. Not signed up for my newsletter? Change that today. Better yet, join the Internal Audit Collective and start helping us build a stronger future for Internal Audit.

Want to be updated as new blog posts are released? Subscribe to our newsletter.
Join 1K+ readers of The Enabling Positive Change Newsletter for tips, strategies, and resources to improve your approach to Internal Audit and SOX compliance.

