Free Sample: AI Tool Approval Checklist Lite
Purpose: Lead magnet / free sample for validating interest in the full AI Guardrails Kit.
Intro copy
Employees are already using AI tools. Before deciding Conditional / Approved / Not approved for business use, answer a few practical questions:
- What will the tool be used for?
- What data will go into it?
- Can the vendor use that data for training?
- Are admin/security controls available?
- Is the output reviewed before use?
This lite checklist helps teams make a first-pass decision before using AI tools with company or customer information.
Note: This is a practical operational checklist, not legal, privacy, compliance, or security advice.
1. Tool summary
| Field | Response |
|---|---|
| Tool name | |
| Vendor | |
| Website | |
| Requester/team | |
| Intended use | |
| Users/teams | |
| Date |
2. Business use
What will this tool be used for?
- Brainstorming/research
- Drafting/revising text
- Summarizing documents/notes
- Meeting transcription/summaries
- Coding/development
- Customer support
- Sales/marketing
- Data analysis
- Image/audio/video generation
- Browser extension/plugin
- Integration with business systems
- Other: _______
Will outputs be used externally or with customers?
- No
- Yes, after human review
- Yes, with limited/no review
- Unsure
3. Data involved
What information may be entered, uploaded, recorded, or connected?
- Public information only
- Internal company information
- Customer/client data
- Personal information
- Employee/HR data
- Financial/payment data
- Contracts/legal information
- Source code
- Logs/security/vulnerability data
- Credentials/secrets/API keys/tokens
- Regulated data
- Meeting recordings/transcripts
- Unsure
Quick rule:
If customer, personal, HR, finance, legal, source code, security, credentials, or regulated data is involved, do not green-light casually (Conditional-first; Low ≠ auto-Approve). Escalate for review.
4. Vendor/data questions
| Question | Answer / Notes |
|---|---|
| Will prompts/files/outputs be used to train vendor models? | |
| Can training on business data be disabled? | |
| How long is data retained? | |
| Can data be deleted/exported? | |
| Is there a business/enterprise plan? | |
| Are admin controls available? | |
| Is SSO/MFA available? | |
| Are audit logs available? | |
| Does the tool connect to email, calendar, files, CRM, tickets, code, or other systems? | |
| Are browser extensions/plugins involved? |
5. First-pass risk rating
Choose one.
Low
- Public or generic non-sensitive data.
- No integrations.
- Limited users.
- Human-reviewed output.
Medium
- Internal data.
- Team-level use.
- Some business impact.
- Limited or no sensitive data.
High
- Customer, personal, confidential, source code, security, legal, HR, finance, or regulated data.
- Integrations with business systems.
- External/customer-facing output.
- Broad team usage.
Prohibited / stop
- Credentials, secrets, API keys, private keys, or tokens.
- Tool has unclear vendor/data practices and sensitive data is involved.
- Use violates customer contracts, law, policy, or security requirements.
Selected rating:
- Low
- Medium
- High
- Prohibited / stop
Reason:
-
6. Decision
Approved does not mean unrestricted. Prefer Conditionally approved for first intake / pilots. Use Approved only when scope is stable and required controls are already live — same Conditional-first rule as the full kit checklist.
How to choose the decision
| Decision | Use when… | Prefer instead when… |
|---|---|---|
| Approved | Scope is clear and stable; required controls are live/verified; normal quarterly review is enough | Path is still a pilot or controls are being proven → Conditionally approved |
| Conditionally approved | First intake / pilot; nearer forced check-in or exit criteria needed | Controls are proven and scope is stable → later Promote to Approved (full kit register + quarterly tracker) |
| Not approved / Prohibited | Unacceptable risk, personal/free accounts for any company work, duplicate of an approved path, or stop | You only need more vendor docs or a narrower scope → Needs more review |
| Needs more review | Missing DPA/security answers, unclear training/retention, or scope still undefined | Facts are clear enough to Approve, Conditionally approve, or Reject |
- Approved
- Conditionally approved
- Not approved
- Needs more review
- Prohibited
Approved use cases:
-
Do not use for:
-
Required conditions:
- Business account required
- SSO/MFA required
- Data training disabled
- No customer data
- No personal data
- No file uploads
- No meeting recordings
- No source code/logs/security data
- Human review required
- Legal/privacy/security review required
- Other: _______
Decision owner:
Date:
Next review date:
Upgrade note for full pack
The full AI Guardrails Kit includes:
- AI Acceptable Use Policy
- Full AI Tool Approval Checklist
- Shadow AI Discovery Survey
- Data Classification Quickstart
- Employee AI FAQ
- AI Policy Rollout Checklist
- Manager Briefing One-Pager
- AI Incident Triage Checklist
- Quarterly AI Review Tracker
- Conditional / Approved tool register (Conditional-first)
- MSP/Consultant Client Delivery Pack
The goal: practical AI usage guardrails without enterprise bureaucracy.
This material is provided for general operational and informational purposes only. It is not legal, compliance, privacy, security, HR, or professional advice. Review and adapt for your organization before use.