API Governance Checklist
Use this form to review API governance readiness, standards, security, documentation, lifecycle, monitoring, and change management.
API Overview
API Name
*
API Description / Purpose
*
API Type
Internal
Partner
Public
Other
Business Unit / Team Responsible
*
Environment in Scope
Development
Test
Staging
Production
Review Date
*
 -
Month
 -
Day
Year
2 digit month, 2 digit day, 4 digit year
Date
Ownership and Governance
API owner name or team
*
Technical contact
*
Product or business owner
Governance status
*
Not started
In progress
Needs review
Compliant
Non-compliant
Approval or review notes
Standards and Design
Does the API follow naming conventions?
*
Yes
No
Partial
API specification format used
*
Please Select
OpenAPI
Swagger
RAML
GraphQL schema
Other
Is the versioning approach defined?
*
Yes
No
Is the breaking-change policy documented?
*
Yes
No
Consistency with organizational API standards
*
Not consistent
1
2
3
4
5
6
7
8
9
Fully consistent
10
1 is Not consistent, 10 is Fully consistent
Security and Access Controls
Authentication Method
*
None
API Key
OAuth 2.0
JWT
mTLS
Other
Authorization Model Defined
*
Yes
No
Rate Limiting/Throttling Enabled
*
Yes
No
Input Validation and Error Handling Defined
*
Yes
No
Security Review Result
*
Pass
Conditional Pass
Fail
Not Reviewed
Documentation and Lifecycle
Is public or internal documentation available?
*
Yes
No
How complete is the documentation?
*
Incomplete
1
2
3
4
5
6
7
8
9
Complete
10
1 is Incomplete, 10 is Complete
Are onboarding or developer instructions available?
*
Yes
No
Lifecycle stage
*
Please Select
Planned
Active
Deprecated
Retired
Is a deprecation or retirement plan documented?
*
Yes
No
Monitoring, Testing, and Change Management
Monitoring/logging in place
*
Yes
No
Alerting defined for failures and thresholds
*
Yes
No
Test coverage status
*
Please Select
Not started
Partial
Adequate
Strong
Change approval process defined
*
Yes
No
Operational checklist items
*
Submit Checklist
Should be Empty: