12 things every organization should have in place before their next AI tool deployment. Use the checkboxes to track your progress.
0 of 12 items complete
A documented policy defining what employees may and may not do with AI tools — including which tools are approved, what data can enter them, and how outputs should be handled. Not a prohibition — a real policy with three tiers: permitted, requires approval, prohibited.
A named individual with defined responsibilities for AI governance: maintaining the approved tools list, reviewing exceptions, keeping the policy current, and receiving incident reports. Without an owner, no other policy measure works.
Training without sign-off is not enforceable. All employees who use AI tools should have reviewed the policy and signed (or digitally acknowledged) it. This is your audit evidence.
A documented list of AI tools approved for use, the conditions of approval (e.g., "approved for internal use only — no client data"), and the process to request approval for additional tools. Anything not on the list is unapproved.
A clear definition of what types of data may or may not enter AI tools. Use concrete terms employees understand: "client names with account numbers," "Social Security numbers," "internal salary information" — not just "sensitive data."
For each approved AI tool, a data processing agreement or equivalent is in place. This ensures the vendor is contractually bound to protect your data, not use it to train their models, and notify you of breaches. Consumer tiers rarely include these.
SOC 2 Type II report reviewed for each approved vendor. Key items to verify: data residency, model training policy for customer inputs, breach notification timeline, subprocessor list. For regulated industries, also check relevant compliance certifications (HIPAA, FedRAMP, etc.).
All employees who use AI tools have completed training covering: what risks AI tools pose, which tools are approved, what data is prohibited, how to recognize a potential AI-related incident, and how to report one. Training should be documented with completion records.
What should an employee do if they accidentally input prohibited data into an AI tool, receive a suspicious AI-generated output, or discover an unapproved AI tool in use? The answer should be in writing. This connects to your overall incident response plan.
A documented process for reviewing AI-generated outputs before they are used in client communications, deliverables, or decisions. Who reviews? What do they check? How is review documented? This protects against accuracy errors and unwanted disclosures.
Your AI Acceptable Use Policy should be reviewed by an attorney familiar with AI governance — not just standard IT counsel. This is especially important for regulated industries. Even a one-time review provides meaningful protection and credibility with examiners.
AI tools and regulations both change fast. A quarterly review cadence is recommended. At minimum, the policy should be reviewed annually — and any time a significant new regulation, enforcement action, or AI capability emerges that changes the risk landscape. Put it on the calendar.
The BulldogAI $250 AI Success Kit includes a custom AUP, security awareness training module, and employee onboarding guide — everything on this checklist, built for your organization.
Start with the Free Audit →