TL;DR: AI Governance Q3 Review Template: A Quarterly Audit Checklist for 2026, a practical compliance guide for enterprise and HR teams in 2026.
Quarterly governance reviews exist because compliance drift is gradual. A vendor quietly updates its model. A team member starts using an AI tool that wasn't in the register. A new state law passes with a 90-day effective date that nobody caught. None of these events trigger an alarm. They accumulate until the organization faces a regulatory inquiry or internal incident with no documentation to show.
The Q3 2026 review window runs from July 1 through September 30. It is the first quarter where enforcement under the EU AI Act applies to high-risk AI systems, with the December 2, 2027 deadline now active. Texas TRAIGA and several other US state laws are also in effect. Running a rigorous Q3 review is no longer a best practice. It is the baseline for demonstrating compliance in any jurisdiction that applies to your operations.
This template gives you a 30-point checklist organized by the four NIST AI Risk Management Framework functions (Govern, Map, Measure, Manage), documentation guidance for safe harbor purposes, a decision tree for off-cycle reviews, and scaling guidance for organizations of different sizes.
What to review each quarter
Before working through the checklist, the review team needs four inputs: (1) the current AI inventory or register, (2) all vendor contracts involving AI or automated decision-making, (3) the incident log from the previous quarter, and (4) training completion records for anyone who works with AI systems in a material way.
If any of these four documents do not exist in a retrievable form, that fact itself is a finding. It should be recorded and assigned an owner before the checklist is started.
The scope of a quarterly review covers all AI systems currently in production, all AI systems that were retired or paused during the quarter, all new AI systems that were piloted even informally, and any changes to existing systems. "AI system" for this purpose means any automated process that makes or substantially influences a consequential decision, not only systems labeled "AI" by the vendor.
30-point Q3 2026 checklist
This checklist is organized by the four NIST AI RMF core functions. Each item maps to a specific governance activity. The "Owner" column should be filled in with a named individual, not a department.
Govern (organizational structures and policies)
| # | Item | Owner | Done |
|---|---|---|---|
| G-1 | Confirm AI governance policy is current and reviewed within the last 12 months | Compliance lead | [ ] |
| G-2 | Verify roles and responsibilities document names specific individuals for each AI system in production | Compliance lead | [ ] |
| G-3 | Confirm board or executive leadership received an AI risk summary in Q2 or has one scheduled for Q3 | CISO / GC | [ ] |
| G-4 | Check that acceptable use policy covers all AI tools currently in employee use, including tools adopted informally | HR / Legal | [ ] |
| G-5 | Review vendor AI clauses in all active contracts signed or renewed in Q2 2026; flag any without data processing agreements | Legal | [ ] |
| G-6 | Confirm a named person is responsible for tracking regulatory changes (EU AI Act, state laws, FTC guidance) | Compliance lead | [ ] |
| G-7 | Verify whistleblower or incident reporting channel is functional and employees know how to use it | HR | [ ] |
| G-8 | Check that AI governance policy applies to contractors and third-party staff who access production AI systems | Legal / Procurement | [ ] |
Map (context and risk identification)
| # | Item | Owner | Done |
|---|---|---|---|
| M-1 | Update the AI inventory to include all systems deployed, modified, or retired in Q2 2026 | AI Register owner | [ ] |
| M-2 | For each system added in Q2, document the intended use case, the data inputs, and the affected population | System owner | [ ] |
| M-3 | Classify each system in the inventory by risk tier (high / limited / minimal) using EU AI Act Annex III and state law criteria | Compliance lead | [ ] |
| M-4 | Identify any systems that may now qualify as high-risk under EU AI Act Article 6 given any changes to scope or deployment context | Compliance lead | [ ] |
| M-5 | Map each AI system to the third-party vendor or internal team responsible for it | Procurement | [ ] |
| M-6 | Confirm that each high-risk system has a designated human oversight owner who can intervene in automated outputs | System owner | [ ] |
| M-7 | Document any new regulatory requirements that apply to your AI systems based on Q2 2026 legislative developments | Legal | [ ] |
Measure (analysis and assessment)
| # | Item | Owner | Done |
|---|---|---|---|
| ME-1 | Review performance metrics for each high-risk AI system deployed in Q2; flag any accuracy or fairness drift from baseline | System owner | [ ] |
| ME-2 | Check whether bias or fairness testing was completed for any AI system used in hiring, lending, or benefits determination | Compliance lead | [ ] |
| ME-3 | Review the incident log for Q2: count incidents, categorize by severity, and confirm each has a documented resolution | Compliance lead | [ ] |
| ME-4 | Verify that logging and audit trail systems are functioning for each high-risk AI system (EU AI Act Article 12 requirement) | Engineering | [ ] |
| ME-5 | Confirm that accuracy and robustness testing was completed before any new high-risk system went to production in Q2 | Engineering | [ ] |
| ME-6 | Check whether any vendor has disclosed a model change, data change, or accuracy change for a system you use in production | Procurement | [ ] |
| ME-7 | Review whether any third-party AI system produced an output that led to a consequential decision that was later reversed or appealed | Operations | [ ] |
| ME-8 | Confirm that post-market monitoring procedures are in place for each EU AI Act Annex III system (Article 72 requirement) | Compliance lead | [ ] |
Manage (response and improvement)
| # | Item | Owner | Done |
|---|---|---|---|
| MA-1 | Verify that each open finding from the Q2 review has an assigned owner and a target resolution date | Compliance lead | [ ] |
| MA-2 | Confirm incident response plan was tested or reviewed in Q2 or is scheduled for Q3 | CISO | [ ] |
| MA-3 | Check that any corrective actions from Q2 incidents have been implemented and verified | System owner | [ ] |
| MA-4 | Review training completion records; confirm that all employees using high-risk AI systems completed required training | HR | [ ] |
| MA-5 | Confirm that vendor contracts allow you to audit AI system performance and request documentation of model changes | Legal | [ ] |
| MA-6 | Check that the process for pausing or disabling a high-risk AI system is documented and has been tested | Engineering | [ ] |
| MA-7 | Review whether any planned Q3 AI deployments require a conformity assessment or impact assessment before launch | Compliance lead | [ ] |
How to document the review for safe harbor purposes
Several US state AI laws provide a safe harbor for organizations that conduct risk assessments consistent with a recognized framework. Texas TRAIGA Section 541.152 offers reduced liability if an organization can demonstrate it followed NIST AI RMF. Connecticut SB 5 references documented risk assessments. Colorado SB 26-189 (effective February 1, 2027) requires impact assessments for high-risk AI systems.
To satisfy these safe harbor provisions, the quarterly review documentation should include:
The review date, the names and titles of all participants, and the scope (which AI systems were covered). A copy of the completed checklist with each item marked and each owner named. A summary of findings, distinguishing between items that passed, items that failed, and items that are not applicable with a written justification for why. An action plan listing each finding that requires remediation, the assigned owner, and the target date.
For EU AI Act purposes, the quarterly review does not replace technical documentation under Article 11. It supplements it. The review should be stored alongside the technical documentation for each high-risk system and retained for the period specified in Article 18 (10 years for most high-risk systems).
Store the completed review in a location that can be produced in response to a regulatory request within a reasonable time frame. "Our files" is not an answer that satisfies a notified body or a state attorney general. A named folder in a document management system with access controls and version history is the minimum acceptable standard.
See the AI governance checklist 2026 for a parallel overview of the key annual governance requirements that sit above the quarterly cycle.
What triggers an off-cycle review
The quarterly schedule is not a ceiling. Off-cycle reviews should be triggered whenever a qualifying event occurs. The list below is concrete, not exhaustive.
A new AI system is deployed to production that was not on the inventory as of the last review. This includes systems where a team "tested" a tool that began influencing real decisions.
A vendor notifies you of a model update, a change to training data, or a change to pricing logic. Under the EU AI Act, provider obligations under Article 13 include notifying deployers of substantial modifications.
A company acquires or is acquired by another entity that operates AI systems. The surviving entity takes on the AI governance obligations of the acquired entity. A 60-day window is a reasonable target for completing a combined review.
A significant regulatory event occurs. December 2, 2027 was one such date. Others on the calendar include Colorado SB 26-189 effective February 1, 2027, and Connecticut SB 5 taking effect October 1, 2026. If a new state law is signed that applies to your operations, that should trigger a review of whether your current documentation satisfies the new requirements.
An incident occurs involving an AI system that resulted in harm or a regulatory inquiry. Post-incident reviews should be completed within 30 days of the incident being closed.
A staff member who owns a high-risk AI system leaves the organization. Until a replacement owner is named and confirmed, the system is technically ungoverned. An off-cycle review within two weeks of the staff change is appropriate.
For ongoing guidance on the AI tool register template that feeds into the inventory section of this review, see the linked resource.
Who should conduct the review
The right structure depends on organizational size. These recommendations assume a for-profit entity operating in at least one regulated jurisdiction.
For a solo compliance officer or a team of fewer than five people: the review can be conducted by one person who interviews the owners of each AI system and fills in the checklist. A one-person review is not ideal, but it is better than no review. The risk is confirmation bias. Mitigate it by having a non-owner review the completed checklist before it is finalized.
For a team of 5 to 50 people with at least one dedicated compliance or legal staff member: designate a review lead from compliance or legal. Have each AI system owner fill in their relevant sections before a two-hour consolidation meeting. The meeting should produce a single agreed-upon action plan. For the AI governance guide for small teams, see the linked article for additional context on building the governance function at this size.
For a mid-size organization with 50 to 500 employees: form a quarterly review committee that includes compliance, legal, engineering, HR, and procurement. Assign pre-work. The meeting should review only the findings, not rehash items that passed without issue. Executive sign-off on the action plan is appropriate at this size.
For an enterprise: the quarterly review should be part of a formal risk management cycle. Internal audit should independently verify at least a sample of the checklist items. The action plan should be tracked in a GRC (governance, risk, and compliance) platform. Findings should be reported to the board-level AI committee if one exists.
In all cases, the Texas TRAIGA safe harbor NIST AI RMF checklist provides a useful reference for confirming that your review activities map to the specific NIST controls that Texas regulators will examine.
Q3 2026-specific items to check
Several enforcement developments make Q3 2026 distinct from prior quarters.
EU AI Act enforcement is now active for high-risk systems as of December 2, 2027. If you deploy a system that falls under Annex III (biometrics, employment, credit, education, critical infrastructure, law enforcement, border control, or administration of justice), the conformity assessment should already be complete. If it is not, that is a priority finding for this review.
Maryland SB 571 (algorithmic pricing) took effect July 1, 2026. Any AI-assisted pricing system used in Maryland must comply. Connecticut SB 5 takes effect October 1, 2026, giving you a narrow window to prepare before Q3 closes.
The FTC's "AI and Your Business" guidance, issued in 2024, continues to be cited in enforcement actions. Q3 is a good moment to verify that marketing claims about AI capabilities are accurate, that data use disclosures for AI systems are current, and that bias testing records exist for any AI system used in consumer-facing decisions.
5 questions that reveal governance gaps faster than any audit
Checklists tell you what to verify. These five questions tell you whether the governance program is actually working. Ask them in any quarterly review before you start on the checklist items. If your team cannot answer them quickly and specifically, you have found the real gaps.
1. How many AI systems were added in the last quarter that weren't in the AI register at the time of use?
Shadow AI is a register problem, not just a policy problem. If the answer is "we don't know," the register process is not working. A register that only captures systems after someone thinks to add them is a historical document, not a governance tool. The correct answer to this question should be a specific number, ideally zero, with a short explanation of how you know.
2. What was the last time a model provider notified you of a model update, and how did you respond?
Vendors update models constantly, often without proactive notification to individual customers. If teams aren't reviewing model updates for risk impact, the risk assessment you completed six months ago may no longer reflect what the system actually does. A governance program that treats AI systems as static once assessed is already running behind. The answer here should include a specific date and a specific action taken, not "we monitor vendor announcements."
3. Which of your AI systems has never had a human review a sample of its outputs?
Human oversight requirements in the EU AI Act and multiple US state laws require meaningful human review, not just the technical ability to override. A system where the theoretical ability to intervene exists but nobody has actually looked at outputs in months is not meeting the spirit of those requirements. This question usually surfaces systems that passed their initial risk assessment and then went unmonitored.
4. What would happen if your primary AI vendor had an outage tomorrow?
Business continuity is an underweighted governance topic. AI tools have become load-bearing infrastructure for many teams faster than anyone planned for. If the answer is "everything stops," that is a risk to document and, for critical workflows, a risk to mitigate. The governance question is whether that dependency is visible, named, and tracked somewhere, not whether it is eliminated.
5. Has anyone filed a complaint or raised a concern about AI use in the last quarter?
Complaint mechanisms that don't produce complaints are usually mechanisms that nobody knows about or nobody trusts. Zero complaints may mean zero issues, or it may mean nobody feels safe reporting, nobody knows the channel exists, or complaints are being resolved informally and not recorded. Ask specifically whether the channel exists, where it is documented, whether employees were reminded of it in the last quarter, and what the last recorded complaint was and when.
Using this template across fiscal-year cycles
Most organizations run their governance year on a calendar-year basis, but the regulatory calendar does not align with fiscal quarters. Build two review schedules: one that covers the regulatory milestone calendar (when laws take effect, when certifications expire) and one that covers your internal fiscal quarters.
The Q3 review conducted in July-September should include a forward look at Q4 regulatory dates. In Q4 2026, the major milestone is Connecticut SB 5 taking effect on October 1. Building Q4 preparation into the Q3 action plan prevents last-minute compliance scrambles.
Retain completed quarterly reviews for at least three years, or longer if your jurisdiction requires it. EU AI Act Article 18 requires documentation for 10 years after the system leaves the market. US state laws vary, but most enforcement statutes of limitations run two to four years, making three-year retention a reasonable floor.
