Skip to content
Academy
Marketing Academy · Field Work●AI in Marketing
CoreAudit· 45 minutes

The Governance Audit: Stress-Testing a One-Page AI Policy Against the Five-Stage Framework

Go Digit General Insurance

Objective: Given a draft one-page AI governance policy for an insurance company, audit it against the lesson's five required governance pillars and the Stage 3 human-review gate, identifying which pillars are missing or underspecified before the policy goes to legal sign-off.

You're the marketing operations manager at Go Digit General Insurance. Legal asked your team to draft the company's first AI governance policy; you've got a one-page draft and need to audit it against the lesson's framework before it goes upstream for sign-off.

Check the draft against all 5 governance-policy pillars from Stage 2, verify the human-review gate from Stage 3 is actually specified (not just named), and flag every pillar that's missing, vague, or unenforceable as written.

Before you start

What you'll need

Free path (everything below is enough to finish)

FreeTrack pillar-by-pillar audit findings and the review-gate rewrite

A checklist sheet is sufficient to document a policy audit against 5 pillars plus the review gate

The process

2 steps

Step 01 of 02

Auditing a governance policy against the five required pillars

Stage 2 requires a written policy covering 5 things: approved tools and use cases, what data can and cannot be fed to external AI, who is accountable per output category, how disclosures are triggered, and what happens after an incident, and notes only 22% of organizations cover all of them.

The draft policy says: '1) We use ChatGPT and Midjourney for marketing content. 2) Employees should be careful with customer data. 3) The marketing team is responsible for AI content.' That's 3 sentences covering parts of 3 pillars. What's missing or too vague to enforce?

Google Sheets— A checklist sheet with one row per governance pillar and a Present/Vague/Missing column.

Procedure

  1. List all 5 pillars as rows
  2. Mark Pillar 1 (approved tools/use cases) Present, since ChatGPT and Midjourney are named, but flag that 'use cases' aren't specified, are they approved for customer-facing claims, or only internal drafts?
  3. Mark Pillar 2 (data rules) Vague, 'be careful' is not an enforceable rule; it needs an explicit list of what's forbidden (customer PII, policy numbers, claims history)
  4. Mark Pillar 3 (accountability) Vague, 'the marketing team' is not a named accountable role for each output category, high-risk outputs need a specific owner
  5. Mark Pillar 4 (disclosure triggers) Missing entirely, not mentioned anywhere in the draft
  6. Mark Pillar 5 (incident response) Missing entirely, not mentioned anywhere in the draft
Sample output
Pillar | Status | Note
1. Approved tools/use cases | Present (partial) | Tools named, use cases not specified
2. Data rules | Vague | 'Be careful' isn't enforceable, needs an explicit forbidden-data list
3. Accountability | Vague | No named role per risk category
4. Disclosure triggers | Missing | Not addressed
5. Incident response | Missing | Not addressed

Healthy

All 5 pillars are checked individually, with 2+ correctly marked Missing or Vague rather than the whole policy being waved through.

Unhealthy

The audit concludes the policy is 'basically fine' because it mentions AI tools and a responsible team.

What this means

A policy that names tools and a team but skips data rules, disclosure triggers, and incident response has no actual teeth, it reads as governance without being enforceable governance.

So what do I do about it?

SymptomActionEffort
Policy draft has only 3 of 5 required pillars, and 2 of those are vagueAdd an explicit forbidden-data list, named per-category owners, and disclosure/incident sections before legal reviewhalf day
YouYou can do this yourself, no engineering access required.

Step 02 of 02

Verifying the human review gate is specified as a fact audit, not left implicit

Stage 3 defines the review gate as a fact audit with a specific checklist (sourced statistics, verified product claims, legal/medical sign-off triggers, copyright signals, tone-context fit), not a general 'someone reads it first' step, and only 27% of companies enforce it consistently.

The draft policy's only review-related line is: 'All AI content should be reviewed before publishing.' Does this satisfy Stage 3, and what needs to be added?

Google Sheets— The same checklist sheet, adding a row for the review gate specification.

Procedure

  1. Check whether the draft names WHO reviews (a role, not just 'someone')
  2. Check whether the draft names WHAT the reviewer checks (a specific checklist) versus a generic 'read it first'
  3. Check whether the draft distinguishes review depth by risk tier (high/medium/low, per Stage 1) or applies one flat process to everything
  4. Flag the line as underspecified and rewrite it with a named reviewer role, the 5-item Stage 3 checklist, and risk-tiered depth
Sample output
Original: 'All AI content should be reviewed before publishing.'
Audit finding: Underspecified, no named reviewer, no checklist, no risk tiering.
Rewrite: 'High-risk outputs (product claims, customer-facing testimonials) require review by a named Compliance Marketing Lead against the 5-item fact-audit checklist before publish. Medium-risk outputs require review by a trained content editor. Low-risk internal drafts require quarterly spot-checks.'

Healthy

The rewrite names a specific role, references the concrete checklist items, and ties review depth to risk tier.

Unhealthy

The audit accepts 'reviewed before publishing' as sufficient because a review step is technically mentioned.

What this means

A review step with no named owner and no checklist is the paper version of not having a review step, it exists on the page but produces nothing enforceable in practice.

So what do I do about it?

SymptomActionEffort
Review policy line has no named role, no checklist, no risk tieringRewrite with a named reviewer role, the Stage 3 checklist items, and risk-tiered review depth30 min
YouYou can do this yourself, no engineering access required.

Final deliverable

A pillar-by-pillar audit table (Present/Vague/Missing) plus a rewritten review-gate clause with a named role, checklist reference, and risk tiering.

See a reference example
Sample output
Utkarsh Small Finance Bank, draft AI policy audit (excerpt)

Pillar 4, disclosure triggers: MISSING. Draft never states when or how AI-use must be disclosed to customers. Recommend adding: 'Any AI-generated testimonial, chatbot response, or synthetic media must carry a visible AI-use disclosure per FTC and EU AI Act Article 50 requirements.'

Review gate: Original line 'content gets reviewed' rewritten to name a Compliance Marketing Lead as owner and reference the 5-item fact-audit checklist for all customer-facing claims.

Success criteria

You're done when you can:

  • Correctly marks at least 2 of the 5 governance pillars as Vague or Missing with a specific reason
  • Rewrites the review-gate clause to include a named role, the fact-audit checklist, and risk-tiered depth