This chapter distills the guidance from NIST, ISO/IEC 42001, Deloitte, PwC, McKinsey, and the regulatory requirements covered throughout this primer into a practical, sequenced checklist. You do not need to complete this in 90 days. You do need to start.
Step 1: Build Your AI Inventory (Days 1–30)
You cannot govern what you have not catalogued.
The first task is producing a complete, current inventory of every AI system your organization uses or relies on – including AI embedded in third-party software and vendor platforms. For each system, document:
- What the system does and what decisions or outputs it produces
- Which business function uses it and who is accountable for it
- What data it uses, including whether personal data or sensitive categories are involved
- What decisions it informs or automates, and their potential impact on individuals
- Whether the system was built internally or procured, and from whom
This inventory is the prerequisite for every subsequent governance step. It is also increasingly required by law: Quebec Law 25, OSFI Guideline E-23, and the EU AI Act all require organizations to know and document their AI deployments. The NIST AI RMF’s Map function provides a structured approach to this categorization exercise. The PwC three lines of defense model assigns responsibility for this work to first-line operational teams (IT, data, AI functions).
Tip for Canadian Organizations: Include an assessment of which AI systems interact with Quebec residents (triggering Law 25 obligations), which are used by FRFIs (triggering OSFI E-23 compliance), and which involve federal government automated decisions (triggering the Treasury Board Directive).
Step 2: Designate Accountability (Days 15–30)
The McKinsey 2025 State of AI report identifies CEO oversight of AI governance as one of the elements most correlated with higher bottom-line impact from AI investments. The McKinsey 2026 AI Trust Maturity Survey found that organizations with explicit accountability for responsible AI achieve significantly higher governance maturity scores – averaging 2.6 on the survey’s scale versus 1.8 for organizations without clear ownership.
Designate: – A named executive accountable for AI governance (commonly a Chief AI Officer, Chief Risk Officer, or delegated senior executive) – A cross-functional AI governance committee or review body, with representation from legal, compliance, privacy, IT, ethics, HR, and relevant business units – Clear escalation paths for high-risk AI decisions – Board-level reporting on AI governance as part of technology or risk committee responsibilities
Do not create a parallel “shadow” governance structure disconnected from existing risk management. The Deloitte 2026 State of AI report is explicit: “effective governance integrates with existing risk and oversight structures, not parallel functions.”
Step 3: Adopt a Recognized Framework (Days 20–60)
Select and formally adopt an internationally recognized AI governance framework as the backbone of your program. The choice of framework will depend on your sector, size, and regulatory obligations:
- For most Canadian organizations: The NIST AI RMF 1.0 is the most practical starting point – comprehensive, free, well-documented, and directly referenced in emerging legislation. Supplement with the NIST Generative AI Profile if you use ChatGPT, Copilot, or similar tools.
- For organizations seeking certification or EU market access: Pursue ISO/IEC 42001 It provides auditable, credentialed governance that regulators and enterprise clients increasingly expect.
- For federal government contractors: The Treasury Board Directive on Automated Decision-Making and the ISED Voluntary Code of Conduct are the relevant Canadian policy standards.
- For FRFIs: OSFI Guideline E-23 is mandatory by 2027 and should be integrated into model risk management programs now.
PwC’s 2025 Responsible AI Survey recommends applying the “three lines of defense” model: the first line (IT, engineering, AI teams) builds and operates responsibly; the second line (risk, legal, compliance) reviews and governs; the third line (internal audit) assures and audits.
Step 4: Assess Risks for High-Impact Systems (Days 30–75)
Using your AI inventory, identify which systems present the highest risk – those that make or substantially influence decisions affecting people’s employment, financial access, health outcomes, housing, or legal status; those that process sensitive personal data; and those that interact directly with the public.
For these high-risk systems, conduct a formal AI impact assessment (also called an Algorithmic Impact Assessment). This should include:
- A description of the system’s purpose, inputs, outputs, and affected population
- Identification of potential biases in training data or model design
- An assessment of what can go wrong and how likely and severe those outcomes are
- A review of whether adequate human oversight exists at decision points
- A determination of how the system’s outputs can be explained to affected individuals
- A plan for monitoring performance after deployment
The Treasury Board Guide on the Directive on Automated Decision-Making provides a practical AIA process applicable beyond the federal government context.
Step 5: Train Your Workforce (Days 45–90)
Governance frameworks and policies have no effect if the people building and using AI systems are unaware of them. The McKinsey 2026 AI Trust Survey identifies knowledge and training gaps as the leading barrier to responsible AI implementation.
Minimum training requirements include: – All staff: Awareness of which AI tools are approved for use, what “shadow AI” means and why it is prohibited, and how to report concerns – AI practitioners and developers: Responsible AI design principles, bias testing methods, documentation requirements – Managers and executives: Governance obligations, escalation procedures, regulatory requirements in their sector – Legal, compliance, privacy: Current regulatory landscape in relevant jurisdictions
For compliance professionals seeking formal credentials, the IAPP AIGP certification is the recognized benchmark in AI governance competency.
Step 6: Establish Monitoring and Incident Response (Days 60–90+)
AI systems are not static. Their performance changes as the data environment they operate in changes. A model that performs fairly at deployment can develop bias as patterns in the real world shift. Effective AI governance requires ongoing monitoring – not a one-time assessment.
Establish: – Defined performance and fairness metrics for each deployed AI system, with threshold triggers for escalation – A process for regularly reviewing model performance against those metrics – A named process for handling AI-related incidents, including customer-facing errors, regulatory inquiries, and suspected bias – A documented incident log (required by the ISED Voluntary Code of Conduct and OSFI E-23, among other frameworks) – A process for incorporating user feedback into model improvement
As Mastercard has publicly stated: “Every model must be explainable, governed and continuously monitored because the system depends on it.”
Summary Table: The Executive AI Governance Checklist
| Priority | Action | Timeframe | Key Reference |
| 1 | Build complete AI inventory | Days 1–30 | NIST AI RMF Map function |
| 2 | Designate named AI governance accountability | Days 15–30 | McKinsey 2025, ISO/IEC 42001 |
| 3 | Adopt a recognized governance framework | Days 20–60 | NIST AI RMF, ISO/IEC 42001 |
| 4 | Conduct impact assessments for high-risk systems | Days 30–75 | Treasury Board AIA Guide, OSFI E-23 |
| 5 | Train staff at all levels | Days 45–90 | IAPP AIGP, ISED Voluntary Code |
| 6 | Implement ongoing monitoring and incident response | Days 60–90+ | ISO/IEC 42001, OSFI E-23 |