Govern AIAdvancedAbout 1 hourv1.0.0Last reviewed 2026-09-04

Review AI Governance

A practical check of who can buy AI, what data it can touch, and whether anyone would know if a tool went wrong.

Who this helps

Executive and Founder, Revenue Operations, Revenue Finance.

When to use it

  • When AI tools are spreading faster than any policy.
  • After a customer complaint or a data scare involving an AI tool.
  • Before the board asks what your AI governance looks like.

Information you need first

  • A list of AI tools currently in use, sanctioned or not
  • Your current approval process, if any
  • Any data-handling rules that already exist

Quick Prompt

Best for one task. Copy it, add your information, and run it in your AI assistant.

You are a governance advisor for a revenue organization. AI tools in use: [paste list, including unsanctioned ones]. Current approval process: [paste or say none]. Data rules: [paste or say none]. Assess our governance: the three biggest exposure points, the minimum policy we need (buying approval, data access, customer-facing output review, kill process), and how to find the tools we do not know about. Keep it proportionate for a company our size: [SIZE]. Do not hand me an enterprise compliance program.

Full SKILL.md preview

Best for repeatable work. The file includes the process, required inputs, decision rules, quality checks, and output format.

---
name: review-ai-governance
description: A practical check of who can buy AI, what data it can touch, and whether anyone would know if a tool went wrong.
license: MIT
metadata:
  author: The Revenue AI Report
  version: 1.0.0
  last-reviewed: 2026-09-04
  source: https://www.therevenueaireport.com/skills/review-ai-governance
---

# Review AI Governance

A practical check of who can buy AI, what data it can touch, and whether anyone would know if a tool went wrong.

## When to use this skill

- When AI tools are spreading faster than any policy.
- After a customer complaint or a data scare involving an AI tool.
- Before the board asks what your AI governance looks like.

## Inputs to collect

- A list of AI tools currently in use, sanctioned or not
- Your current approval process, if any
- Any data-handling rules that already exist

## Process

1. Inventory what is in use, including expensed and free tools.
2. Name the exposure points: data in, output out, money spent.
3. Write the minimum policy: approval, data access, output review, kill process.
4. Assign one owner. Governance without an owner is a document.
5. Review quarterly. Tools change faster than annual policies.

## Decision rules

- Any tool touching customer data goes through review, no exceptions for free tiers.
- Customer-facing AI output needs a named human reviewer until it has earned trust with logs.
- A tool nobody will own gets shut off.

## Output requirements

- The three biggest exposures, named.
- Minimum viable policy in four parts.
- A method for finding unknown tools.

## Quality checks

- The policy fits your company size.
- One owner is named.
- The inventory method finds unsanctioned tools, not just licensed ones.

## Limitations

- Policy does not equal behavior. Budget for the conversation, not just the document.
- This is operational governance, not legal advice. Regulated industries need counsel.

## Example input

14 AI tools in use across sales and marketing, 5 expensed individually. No approval process. Reps paste CRM notes into free chat tools.

## Example output

Exposures: customer data flowing into free tools with no data terms, unreviewed customer-facing output, and spend nobody owns. Minimum policy: all tools touching customer data approved by the RevOps lead; a provided, approved assistant so reps stop using free ones; human review on outbound AI content; a kill process any leader can trigger. Find unknown tools quarterly via expense reports and a two-question team survey.

## Review checklist

- Owner named?
- Free-tier tools covered by the policy?
- Quarterly review scheduled?

## Works with

- Playbook: Get shadow AI into the light (L3) (org, L3) https://www.therevenueaireport.com/playbooks/get-shadow-ai-into-the-light-l3
- Playbook: The agent control plane (L4) (revops, L4) https://www.therevenueaireport.com/playbooks/agent-control-plane-l4
- Playbook: Company operating policy rebuilt for agents (L6) (general, L6) https://www.therevenueaireport.com/playbooks/agent-operating-policy-rebuild-l6
- Tool: Viable (AI Agents & Workflow) https://www.therevenueaireport.com/tools/viable
- Tool: Structured (Data & Analytics) https://www.therevenueaireport.com/tools/structured
- Tool: Alation (Data & Analytics) https://www.therevenueaireport.com/tools/alation
- Tool: Ataccama ONE (Data & Analytics) https://www.therevenueaireport.com/tools/ataccama-one
- Tool: Metabase (Data & Analytics) https://www.therevenueaireport.com/tools/metabase

## Rules of conduct

- Write for a Director, VP, or operator. Short sentences. Explain uncommon terms.
- Separate facts from assumptions. Never hide uncertainty.
- Do not invent numbers, benchmarks, quotes, or customer names.
- Do not send messages, change CRM records, or publish anything unless the user explicitly asks.
- Flag when a decision needs human review.

## Evidence

This skill is grounded in The Revenue AI Report research:
- https://www.therevenueaireport.com/research/trust
- https://www.therevenueaireport.com/research/rollback
- Related analysis: https://www.therevenueaireport.com/blog/ai-sdr-kill-criteria-before-you-sign




Source and updates: https://www.therevenueaireport.com/skills/review-ai-governance

The process

  1. 1.Inventory what is in use, including expensed and free tools.
  2. 2.Name the exposure points: data in, output out, money spent.
  3. 3.Write the minimum policy: approval, data access, output review, kill process.
  4. 4.Assign one owner. Governance without an owner is a document.
  5. 5.Review quarterly. Tools change faster than annual policies.

Decision rules

  • Any tool touching customer data goes through review, no exceptions for free tiers.
  • Customer-facing AI output needs a named human reviewer until it has earned trust with logs.
  • A tool nobody will own gets shut off.

What the output should include

  • The three biggest exposures, named.
  • Minimum viable policy in four parts.
  • A method for finding unknown tools.

Example input

14 AI tools in use across sales and marketing, 5 expensed individually. No approval process. Reps paste CRM notes into free chat tools.

Example output

Exposures: customer data flowing into free tools with no data terms, unreviewed customer-facing output, and spend nobody owns. Minimum policy: all tools touching customer data approved by the RevOps lead; a provided, approved assistant so reps stop using free ones; human review on outbound AI content; a kill process any leader can trigger. Find unknown tools quarterly via expense reports and a two-question team survey.

Review checklist before you trust the output

  • Owner named?
  • Free-tier tools covered by the policy?
  • Quarterly review scheduled?

Common questions

What does the Review AI Governance skill do?
A practical check of who can buy AI, what data it can touch, and whether anyone would know if a tool went wrong.
Who is the Review AI Governance skill for?
Executive and Founder, Revenue Operations, Revenue Finance. It sits at the advanced level and takes about 1 hour.
What do I need before I start?
Collect these first: A list of AI tools currently in use, sanctioned or not; Your current approval process, if any; Any data-handling rules that already exist.
What is the difference between the quick prompt and the SKILL.md file?
The quick prompt is for one task. Copy it, add your information, run it. The SKILL.md file is for repeatable work: it carries the process, required inputs, decision rules, quality checks, and output format so an AI assistant runs the same way every time.
What should I check before trusting the output?
Owner named? Free-tier tools covered by the policy? Quarterly review scheduled?
Is it free to use?
Yes. Every skill on The Revenue AI Report is free and published under the MIT license. Attribution is welcome, not required.

Limitations

  • Policy does not equal behavior. Budget for the conversation, not just the document.
  • This is operational governance, not legal advice. Regulated industries need counsel.

Works with

Run the skill, then roll it out with a playbook. Vendor links are supporting context, not a recommendation.

The research behind this skill

License: MIT. Version 1.0.0. Last reviewed 2026-09-04. Raw file: https://www.therevenueaireport.com/skills/review-ai-governance/SKILL.md

Share this skill

Posting to Instagram or TikTok? Copy the link, it carries the title, summary and share image.

Get the Report

The research behind these skills, weekly.

Arrives weekly by email. Free. Unsubscribe anytime. By subscribing you agree to our Privacy policy and Terms. We never sell or share the list.