How it works
The workpaper turns AI governance into auditable fields: system inventory, owner, intended purpose, data used, risk rating, governance responsibility, expected control, test step, evidence and result.
Use it for advisory readiness, internal audit assurance or pre-board review. In India, tailor the file to the approved audit plan, the DPDP Act and Rules where personal data is processed, sector regulation, contracts, cyber/security controls and the actual AI systems deployed by the entity.
Last reviewed: 2026-08-30 · For informational purposes only — not professional advice.