AI Agent Governance Maturity Checklist
A self-assessment checklist for how mature your organization's AI governance actually is, from ad-hoc shadow AI use to a fully audited, policy-driven rollout.

Most organizations don't know where they actually sit on AI governance until something goes wrong. This checklist is meant to surface that before it does.
Quick Answer
AI governance maturity runs across four stages: Stage 1 (ad-hoc) - no approved tools list, no data rules, shadow AI likely widespread; Stage 2 (aware) - some tools approved, but no consistent data classification or audit trail; Stage 3 (managed) - approved tools list, data handling rules, and a review process exist; Stage 4 (audited) - all of the above, plus logging, regular policy review, and a fast path for approving new tools. Most organizations sit at Stage 1 or 2 without realizing it.
The checklist
Check off what's actually true today, not what's aspirational:
- We have a written list of AI tools approved for work use
- We have explicit rules for what data can and can't be shared with AI tools
- Someone reviews AI-generated content before it's used externally or in a regulated context
- We log which tools were used for what kind of work, at least at a basic level
- There's a fast, known process for requesting approval of a new AI tool
- We've reviewed our approved-tools list in the last quarter
- We know roughly how much shadow AI use exists on top of approved tools
Scoring yourself
0-2 checked: Stage 1 (ad-hoc). No structure yet - shadow AI use is very likely widespread. Start with a basic approved-tools list and data rules; see the AI governance policy template.
3-4 checked: Stage 2 (aware). Some structure exists, but gaps in data rules or audit trail remain. Focus next on logging and a clear data classification policy.
5-6 checked: Stage 3 (managed). A real governance process is in place. Focus on keeping the approved-tools list current and building the fast-approval path if it's missing.
7 checked: Stage 4 (audited). Governance is mature - the main risk now is complacency. Re-run this checklist quarterly, since new tools and use cases will keep testing it.
Why the "fast approval path" item matters more than it looks
A governance program can check every other box and still fail if employees can't get a new tool approved quickly. Without that path, people route around the policy the moment they need something not yet on the approved list - which is exactly how shadow AI starts in otherwise well-governed organizations.
Go deeper
What is AI agent governance? and what is shadow AI? cover the underlying concepts in full.
See how this applies in practice with Dapto Workbench - an AI work platform for reports, documents, data checks, and other repeatable business work.
Learn more