Skip to main content

Movahedi Control Atlas checklist

Find the AI you have, classify what matters, and govern it before it surprises you.

A first-pass checklist for privacy, security, legal, product, and risk teams moving from shadow AI discovery to accountable operation.

For general operational guidance only. It is not legal advice, an AI audit, or a security certification.

Seven operating moves

From shadow AI to governed AI

  1. 1

    Discover

    List models, agents, copilots, vendors, experiments, and embedded AI features. Name a business owner and technical owner for each.

  2. 2

    Classify

    Record purpose, affected people, data sensitivity, decision impact, scale, human involvement, and plausible harm.

  3. 3

    Trace dependencies

    Map prompts, training or retrieval data, model providers, subprocessors, integrations, access paths, retention, and transfers.

  4. 4

    Set usage controls

    Define approved tools, prohibited inputs, review gates, training expectations, exception handling, and escalation.

  5. 5

    Design oversight

    Specify who reviews outputs, when a person can challenge or stop an outcome, and how overrides are recorded.

  6. 6

    Evaluate and monitor

    Test quality, safety, privacy, bias, and security before release; monitor meaningful changes and performance after release.

  7. 7

    Prepare response

    Define detection, containment, investigation, notification, rollback, corrective action, and learning for harmful output or drift.

Keep the boundary clear

Usage controls are not application security

Usage controls

Approved tools, permitted data, staff training, exceptions, and escalation.

Application security

Identity, authorization, secrets, prompt handling, integrations, logging, testing, and runtime protection.

This checklist is maintained by Mohammad Movahedi as part of the Movahedi Control Atlas. Confirm current legal, regulatory, contractual, and security requirements for your facts and jurisdiction.