Review AI Governance
A practical check of who can buy AI, what data it can touch, and whether anyone would know if a tool went wrong.
Who this helps
Executive and Founder, Revenue Operations, Revenue Finance.
When to use it
- When AI tools are spreading faster than any policy.
- After a customer complaint or a data scare involving an AI tool.
- Before the board asks what your AI governance looks like.
Information you need first
- A list of AI tools currently in use, sanctioned or not
- Your current approval process, if any
- Any data-handling rules that already exist
Quick Prompt
Best for one task. Copy it, add your information, and run it in your AI assistant.
You are a governance advisor for a revenue organization. AI tools in use: [paste list, including unsanctioned ones]. Current approval process: [paste or say none]. Data rules: [paste or say none]. Assess our governance: the three biggest exposure points, the minimum policy we need (buying approval, data access, customer-facing output review, kill process), and how to find the tools we do not know about. Keep it proportionate for a company our size: [SIZE]. Do not hand me an enterprise compliance program.
Full SKILL.md preview
Best for repeatable work. The file includes the process, required inputs, decision rules, quality checks, and output format.
--- name: review-ai-governance description: A practical check of who can buy AI, what data it can touch, and whether anyone would know if a tool went wrong. license: MIT metadata: author: The Revenue AI Report version: 1.0.0 last-reviewed: 2026-09-04 source: https://www.therevenueaireport.com/skills/review-ai-governance --- # Review AI Governance A practical check of who can buy AI, what data it can touch, and whether anyone would know if a tool went wrong. ## When to use this skill - When AI tools are spreading faster than any policy. - After a customer complaint or a data scare involving an AI tool. - Before the board asks what your AI governance looks like. ## Inputs to collect - A list of AI tools currently in use, sanctioned or not - Your current approval process, if any - Any data-handling rules that already exist ## Process 1. Inventory what is in use, including expensed and free tools. 2. Name the exposure points: data in, output out, money spent. 3. Write the minimum policy: approval, data access, output review, kill process. 4. Assign one owner. Governance without an owner is a document. 5. Review quarterly. Tools change faster than annual policies. ## Decision rules - Any tool touching customer data goes through review, no exceptions for free tiers. - Customer-facing AI output needs a named human reviewer until it has earned trust with logs. - A tool nobody will own gets shut off. ## Output requirements - The three biggest exposures, named. - Minimum viable policy in four parts. - A method for finding unknown tools. ## Quality checks - The policy fits your company size. - One owner is named. - The inventory method finds unsanctioned tools, not just licensed ones. ## Limitations - Policy does not equal behavior. Budget for the conversation, not just the document. - This is operational governance, not legal advice. Regulated industries need counsel. ## Example input 14 AI tools in use across sales and marketing, 5 expensed individually. No approval process. Reps paste CRM notes into free chat tools. ## Example output Exposures: customer data flowing into free tools with no data terms, unreviewed customer-facing output, and spend nobody owns. Minimum policy: all tools touching customer data approved by the RevOps lead; a provided, approved assistant so reps stop using free ones; human review on outbound AI content; a kill process any leader can trigger. Find unknown tools quarterly via expense reports and a two-question team survey. ## Review checklist - Owner named? - Free-tier tools covered by the policy? - Quarterly review scheduled? ## Works with - Playbook: Get shadow AI into the light (L3) (org, L3) https://www.therevenueaireport.com/playbooks/get-shadow-ai-into-the-light-l3 - Playbook: The agent control plane (L4) (revops, L4) https://www.therevenueaireport.com/playbooks/agent-control-plane-l4 - Playbook: Company operating policy rebuilt for agents (L6) (general, L6) https://www.therevenueaireport.com/playbooks/agent-operating-policy-rebuild-l6 - Tool: Viable (AI Agents & Workflow) https://www.therevenueaireport.com/tools/viable - Tool: Structured (Data & Analytics) https://www.therevenueaireport.com/tools/structured - Tool: Alation (Data & Analytics) https://www.therevenueaireport.com/tools/alation - Tool: Ataccama ONE (Data & Analytics) https://www.therevenueaireport.com/tools/ataccama-one - Tool: Metabase (Data & Analytics) https://www.therevenueaireport.com/tools/metabase ## Rules of conduct - Write for a Director, VP, or operator. Short sentences. Explain uncommon terms. - Separate facts from assumptions. Never hide uncertainty. - Do not invent numbers, benchmarks, quotes, or customer names. - Do not send messages, change CRM records, or publish anything unless the user explicitly asks. - Flag when a decision needs human review. ## Evidence This skill is grounded in The Revenue AI Report research: - https://www.therevenueaireport.com/research/trust - https://www.therevenueaireport.com/research/rollback - Related analysis: https://www.therevenueaireport.com/blog/ai-sdr-kill-criteria-before-you-sign Source and updates: https://www.therevenueaireport.com/skills/review-ai-governance
The process
- 1.Inventory what is in use, including expensed and free tools.
- 2.Name the exposure points: data in, output out, money spent.
- 3.Write the minimum policy: approval, data access, output review, kill process.
- 4.Assign one owner. Governance without an owner is a document.
- 5.Review quarterly. Tools change faster than annual policies.
Decision rules
- Any tool touching customer data goes through review, no exceptions for free tiers.
- Customer-facing AI output needs a named human reviewer until it has earned trust with logs.
- A tool nobody will own gets shut off.
What the output should include
- The three biggest exposures, named.
- Minimum viable policy in four parts.
- A method for finding unknown tools.
Example input
14 AI tools in use across sales and marketing, 5 expensed individually. No approval process. Reps paste CRM notes into free chat tools.
Example output
Exposures: customer data flowing into free tools with no data terms, unreviewed customer-facing output, and spend nobody owns. Minimum policy: all tools touching customer data approved by the RevOps lead; a provided, approved assistant so reps stop using free ones; human review on outbound AI content; a kill process any leader can trigger. Find unknown tools quarterly via expense reports and a two-question team survey.
Review checklist before you trust the output
- Owner named?
- Free-tier tools covered by the policy?
- Quarterly review scheduled?
Common questions
- What does the Review AI Governance skill do?
- A practical check of who can buy AI, what data it can touch, and whether anyone would know if a tool went wrong.
- Who is the Review AI Governance skill for?
- Executive and Founder, Revenue Operations, Revenue Finance. It sits at the advanced level and takes about 1 hour.
- What do I need before I start?
- Collect these first: A list of AI tools currently in use, sanctioned or not; Your current approval process, if any; Any data-handling rules that already exist.
- What is the difference between the quick prompt and the SKILL.md file?
- The quick prompt is for one task. Copy it, add your information, run it. The SKILL.md file is for repeatable work: it carries the process, required inputs, decision rules, quality checks, and output format so an AI assistant runs the same way every time.
- What should I check before trusting the output?
- Owner named? Free-tier tools covered by the policy? Quarterly review scheduled?
- Is it free to use?
- Yes. Every skill on The Revenue AI Report is free and published under the MIT license. Attribution is welcome, not required.
Limitations
- Policy does not equal behavior. Budget for the conversation, not just the document.
- This is operational governance, not legal advice. Regulated industries need counsel.
Works with
Run the skill, then roll it out with a playbook. Vendor links are supporting context, not a recommendation.
- Playbook: Get shadow AI into the light (L3) (org, L3 L3 Integrated)
- Playbook: The agent control plane (L4) (revops, L4 L4 Orchestrated)
- Playbook: Company operating policy rebuilt for agents (L6) (general, L6 L6 Rebuilt)
- Tool: Viable (AI Agents & Workflow)
- Tool: Structured (Data & Analytics)
- Tool: Alation (Data & Analytics)
- Tool: Ataccama ONE (Data & Analytics)
- Tool: Metabase (Data & Analytics)
The research behind this skill
License: MIT. Version 1.0.0. Last reviewed 2026-09-04. Raw file: https://www.therevenueaireport.com/skills/review-ai-governance/SKILL.md
