AI governance checklist
A practical AI governance checklist for New Zealand organisations
A practical checklist for governing AI purpose, ownership, risk, privacy, data, security, suppliers, human oversight, testing, monitoring and change in New Zealand organisations.
Published by Hot Desk Consultancy Services Limited
Published
Make AI governance usable in everyday work
AI governance should help an organisation decide where AI is useful, what conditions must be met and who remains accountable. A policy can set direction, but governance becomes real through approved tools, decision rights, risk checks, testing, records, monitoring and clear ways to stop or change an unsafe use.
This checklist can be scaled to a single internal assistant, a purchased service, a customer-facing system or an AI-enabled workflow. The depth of review should reflect the possible impact on people, information, services, finances, safety and organisational trust.
1. Name the purpose and the decision
Write a short purpose statement before choosing a tool. Identify the problem, intended users, affected people, expected benefit, current process and the decision the work must support. Record what AI will do, what it will not do and why AI is preferable to a simpler change.
Set measurable success and risk conditions. A time saving alone is not enough if quality, privacy, fairness, security or service outcomes decline. Include a stop condition so that a pilot can end without pressure to proceed.
2. Assign accountability and decision rights
Name an accountable business owner with authority to accept or reject the use. Also identify the people responsible for data, privacy, security, legal or regulatory interpretation, technology, procurement, operations and affected services.
Define who can propose an AI use, approve a pilot, approve production, change the model or supplier, accept residual risk, review incidents and retire the service. A committee can advise, but named people still need clear accountability.
3. Maintain an AI use register
Record approved, pilot and discovered AI uses, including features embedded in existing software. A useful register can include:
- purpose, owner, users and affected groups;
- tool, model, supplier, deployment and material integrations;
- information used, created and retained;
- level of autonomy and human review;
- risk rating, approvals, conditions and review date;
- testing and assurance evidence;
- incidents, exceptions and material changes; and
- current status, including paused or retired uses.
The register gives leaders a factual view of AI activity and helps teams find unapproved or duplicated use. It should be easy to update and linked to normal technology, risk, privacy and procurement records rather than becoming an isolated spreadsheet.
4. Classify the risk before setting the controls
Use a proportionate risk assessment. Consider the scale and reversibility of harm, the people affected, the sensitivity of information, the degree of autonomy, the importance of the decision and the organisation's ability to detect and correct an error.
Treat a use as requiring stronger review when it can affect employment, eligibility, pricing, finances, rights, safety, essential services, vulnerable people or access to support. Increase scrutiny when the system acts across other systems, changes records, communicates externally or operates with limited human intervention.
Define mandatory controls that cannot be offset by a high benefit score. If a required privacy, security, legal, safety or human-accountability control fails, the use should not proceed until the condition is resolved or the scope changes.
5. Apply the New Zealand context
New Zealand's AI Strategy promotes responsible adoption aligned with the OECD AI Principles. The Government's current approach is light-touch, proportionate and risk-based, with existing legal and regulatory mechanisms preferred over a standalone AI law.
The accompanying Responsible AI Guidance for Businesses is voluntary guidance, not legislation. Existing obligations still apply to an AI-supported activity. Identify the laws, regulations, contracts, professional duties, records requirements and sector rules relevant to the particular use, and obtain qualified advice where interpretation is needed.
Do not treat compliance with one framework as proof that the complete use is lawful, fair, secure or fit for purpose. Record which obligations and guidance were considered, who interpreted them and what evidence supports the decision.
6. Govern privacy, information and data sovereignty
Map what information enters the service, how it is processed, what the model or supplier can retain, what outputs are created and where each part is stored or accessed. Include prompts, attachments, search indexes, logs, feedback, generated content and information passed into other systems.
The Office of the Privacy Commissioner states that the Privacy Act 2020 and Information Privacy Principles apply when AI tools collect, use or share personal information. The Commissioner recommends completing and regularly updating a Privacy Impact Assessment before using AI with personal information.
Set approved data classes and a clear do-not-enter list for each tool. Check collection purpose, necessity, accuracy, security, retention, access, correction and disclosure, including processing outside New Zealand. Where Māori data, iwi, hapū, whānau, Māori organisations or material effects on Māori communities are involved, identify the appropriate Māori governance and engagement before scaling. The Government's safe and smart AI guidance provides a practical starting point for these checks.
7. Assess security, architecture and suppliers
Review the complete service path: identities, permissions, devices, networks, data stores, models, prompts, retrieval, integrations, actions, logs, administration and support. Test both ordinary security controls and AI-specific risks such as malicious instructions in content, unintended data disclosure, unsafe tool use and excessive agent permissions.
The National Cyber Security Centre's AI data security guidance covers data used to train, test and operate AI systems. Apply security across the lifecycle and preserve the confidentiality, integrity and availability needed for the use.
For suppliers, record where data is processed, whether customer information can train or improve models, retention and deletion terms, sub-processors, model and service changes, audit evidence, incident notification, availability, support, exit arrangements and portability. Reassess material supplier changes rather than relying on the first procurement review.
8. Keep human accountability meaningful
State what a person must review, what authority they have to intervene and what evidence they need. Human review is weak if a reviewer cannot see the source, understand material limits, challenge the output, reverse the action or has too little time to make a real decision.
Set stricter approval for outputs that affect people, money, safety, rights, employment or public services. Decide when AI may prepare a draft, make a recommendation, perform a bounded action or must not be used. Keep responsibility with the authorised person and organisation rather than transferring it to the tool or supplier.
Tell staff, customers and affected people when AI involvement is material to their interaction or outcome. Provide an understandable explanation, a contact route and a way to question or correct a result where appropriate.
9. Test the intended use and the failure paths
Use representative information, users, permissions and operating conditions. Test accuracy, source support, fairness, accessibility, security, privacy, usability and the effect on the complete process. Include groups that may experience the service differently.
Test missing, conflicting, outdated and misleading information; denied access; unavailable suppliers; unsafe prompts; incorrect outputs; excessive confidence; workflow failures and attempts to make the service act outside its authority. Record what fails safely, what needs human intervention and what cannot be accepted.
Define acceptance criteria before the final test. Keep separate results for quality, privacy, security, fairness, human oversight and operations so that a single score does not hide a mandatory failure.
10. Approve the whole operating model
A production decision should cover the people and processes around the tool. Confirm:
- the accountable owner and support responsibilities;
- approved users, data, purposes and prohibited uses;
- human review and escalation points;
- monitoring, logging and evidence retention;
- incident, complaint, correction and notification paths;
- supplier, model and configuration change controls;
- continuity, fallback and manual-work arrangements; and
- review, suspension and retirement conditions.
Record unresolved risks, accepted exceptions, expiry dates and the approving authority. Approval should relate to the tested purpose and configuration, not every future use of the same product.
11. Monitor use, change and outcomes
Review whether the service is being used for the approved purpose, whether people are bypassing controls and whether quality or risk conditions have changed. Sample outputs and decisions at a frequency suited to the impact. Track incidents, complaints, corrections, overrides, access failures and changes in affected groups.
Reassess when the model, data, supplier, integration, prompt, workflow, autonomy, users or purpose changes materially. Update the AI register, tests, assessments, training and public information where needed. Stop or narrow the use if monitoring cannot show that mandatory conditions still hold.
12. Train people and make escalation easy
Give staff approved tools, realistic examples and clear rules for information, output review, disclosure, records and incidents. Tailor training for general users, reviewers, administrators, developers, procurement staff, leaders and support teams.
Make it easy to ask before using an unapproved tool and to report a concern without blame. Governance works better when people have a safe route to experiment than when informal use is driven out of sight.
The minimum evidence pack
The following records provide a practical governance baseline:
- a purpose, scope and affected-people statement;
- an accountable owner and decision-rights record;
- an AI register entry and proportionate risk assessment;
- applicable-obligations and guidance assessment;
- data map, privacy assessment and sovereignty considerations;
- security, architecture and supplier assessment;
- human oversight, transparency and challenge design;
- test plan, results, defects and acceptance decision;
- operating, monitoring, incident and change plan; and
- approval, exceptions, review date and retirement conditions.
A small organisation can combine these records into a short pack. A high-impact or complex use may need specialist assessments and independent assurance. Proportionality should reduce unnecessary paperwork, not remove controls needed to protect people or information.
Additional public-service considerations
The Public Service AI Framework guides New Zealand public agencies towards inclusive and human-centred use, transparency, safety, security and accountability. It is intended for Public Service AI practitioners and decision-makers and is encouraged rather than binding by itself.
Public organisations should also identify agency-specific obligations and whether the Algorithm Charter for Aotearoa New Zealand applies to them. The Charter uses a risk-based approach for signatory agencies and focuses on transparency, accountability and uses that may create significant unintended harm. It does not replace privacy, security, records, accessibility, sector or Te Tiriti and Māori data considerations.
How Hot Desk can help
Hot Desk provides product-neutral AI policy, strategy, governance, readiness, pilot and implementation consulting. Work can include one area or a combined engagement, with deliverables selected for the client's needs.
Hot Desk has collaboratively developed AI policies, governance frameworks and supporting materials for two New Zealand public-sector organisations. The frameworks were formally approved and are currently adopted. The organisations remain anonymous, and this experience is not presented as a measured outcome or a guarantee for another client.
A recommendation may involve the client's current environment, another product, Pūnaha or no product implementation. Consultancy remains operationally separate from the dedicated Pūnaha team, which is responsible for Pūnaha implementation, configuration and product support.
Continue the discussion
Read how to evaluate enterprise AI search with your own knowledge, explore cyber security and assurance support, or discuss an AI governance assessment or policy engagement.
About this insight
This article is published by Hot Desk Consultancy Services Limited as general information. It is not legal, privacy, security, employment, regulatory or procurement advice and does not assess a particular organisation or AI use. Guidance and obligations can change, so confirm the current requirements that apply to your circumstances.
Start a conversation
Bring us the challenge, not a finished specification.
We will help clarify the current state, the decisions that matter and a practical next step.