AI Ethics, Privacy & Risk Management Checklist

An actionable, fillable pre-deployment and periodic review checklist to evaluate data provenance, privacy, model risk, explainability, human oversight, monitoring, vendor risk, retention, and incident readiness. Includes a simple risk-tier rubric, owner and review fields, and a notes section so teams can save a documented decision and follow up on mitigations.

Interactive Tool

AI Ethics, Privacy & Risk Management Checklist

This interactive checklist helps teams quickly evaluate the ethical, privacy and operational risks of an AI model or automation before deployment and during scheduled reviews. Answer each question, add concise comments where needed, assign an owner, and capture overall risk and readiness. Use the risk-tier rubric below to prioritize follow-up actions.

Risk-tier rubric

  • Low: Minimal privacy or safety exposure; mitigations trivial to implement.
  • Moderate: Some potential for user impact, privacy exposure, or bias; monitoring and mitigations required.
  • High: Significant potential for safety, privacy, legal, or reputational harm; deployment should be restricted until mitigations are in place.
  • Critical: Likely to produce high-impact harms (safety, legal, privacy, discrimination); do not deploy without major redesign.
Clear name so records and owners can be matched to deployments.
Who is accountable for completing mitigations and tracking progress.
Planned review date (ISO format recommended, e.g., 2026-09-30).
Includes origin, collection method, preprocessing steps, and any sampling or labeling processes.
Describe missing items or links to documentation (if any).
Identify whether data contains personal identifiers, health, financial, or other sensitive attributes.
Anonymization, pseudonymization, or minimization steps required.
Cite consent scope, contracts, or legal assessments. If not applicable, explain why.
Link to consent records, DPA, or legal memo.
Include storage and transit protections and role-based access limits.
List gaps or remediation steps.
Confirm only required attributes are retained and retention/deletion rules exist.
Describe retention periods and deletion procedures.
Include metrics, acceptance criteria, and if datasets reflect production populations.
List protected attributes considered and mitigation steps (if any).
Include links to experiment notebooks or validation reports.
Describe explanation type (global, local), intended audience, and evidence of interpretability.
Provide links to explainability artifacts or UI designs.
Include test coverage and outcomes.
List remaining test gaps and scheduled tests.
Specify where humans review, override, or validate outputs and how they are trained.
List roles and escalation paths.
Who signs off on deployment and who monitors post-deploy?
Include names, teams, or job titles.
Define metrics, alert thresholds, and owners for continuous monitoring.
Link to dashboards, metrics, or scheduled reports.
Includes detection, containment, rollback, communication, and remediation steps.
Indicate last test date and lessons learned.
Include vendor questionnaires, SOC reports, or contractual clauses.
List unresolved vendor risks and mitigation commitments.
Record model versions, training data snapshots, and inference logs where appropriate.
Where logs are stored and retention policies.
Select the team's assessed risk tier to prioritize follow-up.
Quick numeric summary to support sorting and dashboards.
1.0 10.0
Select the team's recommended readiness status.
List prioritized mitigation actions, owners, and target dates.
Freeform space for context, links, or reviewer comments.
Who approves deployment given current mitigations.
You can explore this tool now. Sign in or create an account to save your responses and return to them later.
Make this tool part of your work

Save a personal copy, bring it to your team, or tailor the questions and workflow to fit what you are hungry to improve.

Member customization and team collaboration are coming soon.

Discussion

Comments and conversation will live here.