Aug 5, 2026 · 6 min read
Inside the AI Risk Readiness Checklist: what a 12-point self-assessment actually catches
We built the AI Risk Readiness Checklist as the fastest honest answer to a question we hear on almost every first call: "Do we actually have a problem here, or are we fine?" It's twelve questions, organized around NIST's four functions, and it takes about ten minutes. Here's what each section is really testing — and where institutions most often discover a gap they didn't know they had.
Govern: three questions
The Govern section isn't asking whether you have an AI policy document — plenty of institutions have one sitting unused in a SharePoint folder. It's asking whether a specific person would be named if an examiner asked "who approved this model." Most community banks answer this one honestly on the first try, and most discover the honest answer is "nobody, formally."
Map: three questions
This is where the checklist earns its keep. The question that trips up almost every institution: "List every AI system currently in production, including ones embedded in vendor software." Compliance officers reliably list two or three systems on first pass — the chatbot, maybe the fraud tool. Then they go ask IT and product, and the list triples. Core banking platforms, loan origination software, and fraud vendors all ship AI features by default now, often without a formal procurement conversation ever happening.
Measure: three questions
These questions ask whether any system's outputs have been tested for disparate impact across protected classes, and whether that testing happens on a schedule or only once, at launch. This is the section with the widest gap between "we think we're fine" and the honest answer, because bias testing for AI systems is a newer discipline than the fair-lending testing most banks already run on traditional underwriting.
Manage: three questions
The last section asks about incident response specifically for AI: if a vendor pushes a model update tomorrow and your fraud false-positive rate doubles, what's the documented process? Most institutions have a general vendor-incident process but haven't thought through what's different about an AI model update versus a software patch.
What the score actually means
The checklist isn't pass/fail — it's a map of where to spend the next quarter's attention. A low Govern score with a high Map score usually means the technical inventory work is ahead of the accountability structure; the fix is organizational, not technical. The reverse — strong governance language with a thin inventory — usually means the policy was written before anyone did the legwork of finding every AI system actually in production.
If you haven't run it yet, the checklist is free and takes about ten minutes. Take the readiness check →