Resource module

Secure AI Implementation Checklist

An editable Word checklist for deploying AI without creating a security or compliance problem. Five domains, critical and supporting controls, owner and evidence columns, and a sign-off block you can put in front of an auditor.

Download the checklist (.docx)
What's inside

Five domains, in the order they fail.

Identity & Access

Only the right people reach the tool, through your identity system, with access you can remove in one place.

  • SSO-provisioned access and enforced MFA, including admins
  • Deprovisioning tied to HR offboarding, same-day
  • Least-privilege roles and named, limited admin accounts
  • Managed secrets and rotation for API keys and service credentials

Data Protection

Know exactly what data enters the tool, where it goes, how long it stays, and whether it can train a model.

  • Written no-training terms for your inputs and outputs
  • Permitted data classes documented; regulated data authorized or blocked
  • Retention, encryption, residency, and subprocessors verified
  • Scoped connectors, logging, DLP coverage, and a tested deletion path

Approved Tools

A short, deliberate list people actually know about - and a working path for adding to it.

  • Tool register with owner, approved uses, and permitted data classes
  • Named decision-maker and a realistic approval turnaround
  • Discovery for unapproved tools and shadow AI spend
  • Inventory of AI features silently switched on inside existing platforms

Enterprise vs. Personal Accounts

Company work happens in the company tenant. This is the single most common failure point in real deployments.

  • Side-by-side comparison of enterprise and personal-tier risk
  • Personal-account use prohibited in policy and prevented in practice
  • Domain self-signups claimed or shut down
  • A defined remediation path when personal-account use is found

Compliance Considerations

The deployment holds up under an audit, a customer security questionnaire, or a contract review.

  • Framework mapping: CMMC, NIST 800-171, NIST AI RMF, ISO 42001, HIPAA, PCI, SOC 2, GDPR
  • Customer and agency flow-down clauses checked for AI and disclosure
  • Vendor assurance evidence collected and reviewed
  • Human review, disclosure, and incident response coverage

Plus a sign-off record

Business owner, security reviewer, compliance reviewer, decision, accepted risks, and the next review date - the documentation that proves the decision was deliberate.

Download template (.docx)
How to use it

Four passes, not one.

  1. 1

    Run the checklist before a pilot to catch anything that would block production later.

  2. 2

    Answer every Critical row before the tool touches real company data.

  3. 3

    Assign an owner and record evidence in the columns provided - that record is what auditors ask for.

  4. 4

    Re-run it annually, and any time the vendor changes terms, models, or subprocessors.

Bracketed fields are yours to replace. This is a starting point, not legal advice - have counsel and your compliance owner review anything that flows into a customer contract or regulated environment.

Pair it with

The governance documents behind the controls.

This checklist verifies your implementation. The AI Governance Policy Starter Kit gives you the policy, approval process, employee guidelines, and vendor review checklist those controls reference - and the readiness assessment tells you where to start.

Disclaimer

Nothing on this page or in any accompanying template, assessment, checklist, or report constitutes legal, financial, or compliance advice. These materials are general-purpose starting points drawn from professional experience. Review all information thoroughly against your own internal needs, company structure, contractual obligations, and regulatory environment, and have your legal counsel review anything you adopt before you rely on it.