As AI tools become integral to your operations, finance workflows, and customer-facing systems, your compliance now hinges on controls you didn't design. With 88% of organizations using AI in at least one business function, auditors will ask how you govern these systems. This checklist helps you prepare to answer those questions with evidence, not promises.
This checklist focuses on AI governance readiness across three compliance dimensions: risk identification, control design, and evidence collection. Use it before your next SOC 2 Type II or ISO/IEC 27001 surveillance audit to identify gaps in managing AI-enabled processes.
Prerequisites
Before you begin, ensure you have:
- Access to your current asset inventory (ISO/IEC 27001 Clause 8.1 requires documented information on assets supporting the ISMS)
- Your risk register and treatment plan (Clause 6.1.2 and 6.1.3 outputs)
- Documentation of your change management process (SOC 2 CC8.1 requires system changes be authorized and tested)
- Current user access reviews (SOC 2 CC6.2 and ISO/IEC 27001 Control 5.18 both require periodic access reviews)
Without these foundational documents, AI governance becomes speculative rather than evidence-based.
Checklist Items
1. Inventory all AI-enabled tools and integrations across business functions.
Document every AI service your organization uses: LLM-powered customer support, AI coding assistants, document processing tools, browser extensions, and any third-party service that applies machine learning to your data. Include SaaS tools with embedded AI features you didn't explicitly enable.
Good looks like: A spreadsheet listing each AI tool, its business owner, data classifications it processes, and the vendor's SOC 2 or ISO/IEC 27001 certification status. Your inventory distinguishes between AI tools that consume sensitive data and those that don't.
2. Classify which AI workflows process sensitive or regulated data.
Map your AI tools to the data classifications they touch. An AI assistant summarizing support tickets processes customer PII. A coding assistant trained on your repository may expose proprietary logic.
Good looks like: Each AI tool in your inventory is tagged with applicable data classifications (confidential, PII, PHI, payment card data). You can trace which AI services are in-scope for your SOC 2 or ISO/IEC 27001 certification.
3. Define approval requirements for high-risk AI actions.
Identify which AI-driven actions require human review before execution: system configuration changes, bulk data exports, automated vendor approvals, or customer communications. This addresses the risk of malicious instructions embedded in external inputs manipulating internal workflows.
Good looks like: A documented policy stating that AI-suggested system changes require approval from a named role before implementation. Your change log shows evidence of this approval gate being enforced (SOC 2 CC8.1).
4. Implement input validation for AI workflows that ingest external content.
If your AI tools process customer support requests, vendor submissions, or any external documents, you need controls to sanitize and validate that input before it influences AI behavior.
Good looks like: Technological Controls that strip executable content from uploaded documents, validate file types against allowlists, and isolate external inputs in sandboxed environments before AI processing. Your secure development lifecycle documentation describes these validation steps.
5. Strengthen document verification beyond visual inspection.
AI-generated forgeries can bypass visual review of identity documents, invoices, or compliance certificates. If your processes rely on document submission for vendor onboarding, employee verification, or financial approvals, you need verification techniques that detect synthetic content.
Good looks like: You've implemented metadata analysis, cross-reference checks against authoritative sources, or third-party verification services for high-risk documents. Your vendor onboarding procedure explicitly requires verification beyond visual inspection.
6. Restrict installation of AI extensions and plugins to an approved list.
Users can't install browser AI extensions, IDE plugins, or productivity tools without IT approval. Trusted extensions can be modified to hide malicious behavior.
Good looks like: Technological Controls (application allowlisting, MDM policies) prevent unauthorized software installation. Your acceptable use policy explicitly prohibits unapproved AI tools. You maintain an approved AI tools list that users can reference.
7. Assess third-party AI services for security controls.
For each AI vendor in your inventory, review their security documentation. Don't assume a vendor's AI service inherits the security posture of their parent company.
Good looks like: You've collected SOC 2 Type II reports or ISO/IEC 27001 certificates for AI vendors processing sensitive data. Where vendors can't provide attestations, document compensating controls or accept the risk formally in your risk treatment plan (ISO/IEC 27001 Clause 6.2).
8. Document human oversight requirements in your ISMS or control descriptions.
Your ISO/IEC 27001 Statement of Applicability or SOC 2 system description should address AI governance. Auditors need to see that you've considered AI-specific risks in your control design.
Good looks like: Your risk assessment explicitly identifies AI-related threats (prompt injection, synthetic document fraud, malicious AI services). Your Statement of Applicability or control matrix shows which controls address these risks. You can trace from risk to control to evidence.
9. Train users on AI-specific security risks.
Security awareness training now covers AI threats: how to recognize AI-generated phishing, why they shouldn't paste sensitive data into public AI tools, and what approval is required before adopting new AI services.
Good looks like: Training completion records showing users completed AI security modules. Your training content specifically addresses the risks in this checklist (ISO/IEC 27001 Control 6.3 requires awareness training on information security).
10. Establish a review cadence for your AI inventory and risk assessment.
AI adoption moves faster than annual audit cycles. You need a mechanism to identify new AI tools and reassess risk as your usage evolves.
Good looks like: Quarterly reviews of your AI inventory with business unit leaders. Meeting minutes showing you identified new AI tools and updated your risk assessment accordingly. This satisfies ISO/IEC 27001 Clause 9.3 (management review) requirements.
Common Mistakes
Treating AI tools as standard SaaS applications. AI services introduce unique risks (prompt injection, model manipulation, synthetic content generation) that your existing third-party risk assessment may not address. Don't rely solely on a vendor's SOC 2 report; ask specific questions about their AI security controls.
Assuming your data loss prevention (DLP) controls cover AI risks. Traditional DLP monitors file transfers and email. It won't catch a user pasting proprietary code into an AI coding assistant or a malicious prompt hidden after a # symbol in a URL.
Waiting for your auditor to ask about AI governance. If you're using AI in-scope systems, your auditor will evaluate whether you've designed controls around those risks. Discovering gaps during fieldwork creates remediation pressure and potential findings.
Next Steps
If you've completed fewer than seven items on this checklist, prioritize the inventory (item 1) and data classification (item 2) before your next audit. These form the foundation for demonstrating you've identified AI-related risks per ISO/IEC 27001 Clause 6.1.2.
For items you can't complete before your audit, document the gap in your risk treatment plan with a timeline for implementation. A documented plan with management approval satisfies the risk treatment requirement even if controls aren't fully deployed.
Finally, review your current control testing procedures. If your auditor samples access reviews or change approvals, ensure your test population now includes AI-enabled workflows. Controls that don't address your actual AI usage won't provide assurance.



