AI Risk Assessment Checklist
A practical checklist for evaluating a new AI tool or vendor feature before approval — the questions to ask before a use case moves forward.
This checklist is designed to be run against one specific tool or feature at a time, not as a general readiness assessment. Use it at the point a new AI use case enters review, whether it arrived through a deliberate purchase or a vendor's product update.
How to Use This Checklist
Work through each section for the specific tool under review. A "no" or "unclear" answer on a data exposure or vendor terms question is a signal to escalate to full review rather than a fast-path approval — it doesn't automatically mean decline.
Data Exposure
- What data does this tool or feature have access to?
- Does it process privileged material, PII, or unreleased corporate information?
- Is data sent to an external AI provider, or processed within an environment already covered by an existing agreement?
- Can the scope of data access be limited or configured?
Vendor and Model Terms
- Does the vendor disclose what the underlying AI model was trained on?
- Is customer data used to train or improve the model, and can that be opted out of?
- Are there subprocessors involved in AI processing, and are they identified?
- What does the vendor commit to regarding data retention for AI-processed requests?
Use Case and Reliance
- What decision or output does this tool support?
- Is human review built into the workflow before that output is relied upon?
- Could the output be client-facing, filed, or otherwise externally visible without further review?
- Is this a new category of use, or similar to something already approved?
Approval and Ongoing Monitoring
- Who has authority to approve this specific use case given its risk level?
- What conditions, if any, should attach to approval?
- What would trigger a reassessment — a vendor update, a scope change, or a fixed review date?
- Has the decision and its rationale been recorded?
The core issue
A checklist only protects the department if every "unclear" answer routes to someone who will actually chase it down. An unanswered question that quietly becomes a "no risk found" is worse than not running the checklist at all.
Run this before the contract is signed, not after
Vendor risk questions are far easier to get answered during procurement, when the vendor is motivated to close the deal, than after the agreement is in place and the feature is already live.
Next Step
This checklist supports the assessment stage of the governance workflow and pairs directly with the AI Vendor Risk Assessment guide for vendor-specific detail. Once a tool clears this checklist, the decision and its rationale should feed your governance reporting.
A checklist doesn't replace judgment. It makes sure the judgment gets applied consistently, every time, to every tool.

