A practical AI governance, audit, and certification-readiness toolkit for evaluating how organizations develop, procure, deploy, and use artificial intelligence.
Organizations are adopting AI faster than many of them can govern it. A lot of guidance exists, but teams still need field-ready material they can actually use for audit, control testing, and certification readiness.
This project turns major AI governance and assurance frameworks into a usable audit toolkit.
- NIST AI RMF
- ISO/IEC 42001
- ISO/IEC 23894
- ISO/IEC 42005
- NIST AI RMF Generative AI Profile
- EU AI Act basics
- Full AI Audit Checklist & Certification Playbook in PDF and DOCX
- Governance and accountability checklist
- Generative AI control checklist
- AI vendor assurance checklist
- ISO/IEC 42001 certification readiness checklist
- Sample AI findings register
- Sample AI inventory register
- Project overview summary
- AI governance and accountability
- AI inventory and use-case classification
- Risk management and impact assessment
- Data governance and privacy
- Security, resilience, and misuse resistance
- Human oversight and decision controls
- Transparency and documentation
- Monitoring, evaluation, and incident response
- Third-party AI and vendor assurance
- Generative AI and LLM-specific control testing
- Certification readiness for an AI management system
- AI governance teams
- Internal audit teams
- GRC professionals
- Security and risk analysts
- Compliance teams
- Consultants
- Professionals preparing for AI assurance or certification-related work
ai-audit-certification-playbook/
├── docs/
├── checklists/
├── samples/
├── images/
├── README.md
└── PROJECT_OVERVIEW.md
## Project Artifacts
This repository includes a sample Excel-based AI audit workbook built as part of the AI Audit Checklist & Certification Playbook project.
**Included workbook sections:**
- Instructions
- AI Inventory
- Control Testing
- Findings Register
- Maturity Scoring
- 30-60-90 Plan
- Certification Readiness
- Summary Dashboard
> Disclaimer: This workbook is a personal project for learning and portfolio development. It does not represent a real audit, real client data, or real organizational information.