AI Control Review Checklist Template
This checklist is used to perform a structured review of an AI use case before approval, pilot, production deployment, major change, or continued operation.
It is designed as a practical checklist for architecture, security, risk, data governance, privacy, legal, vendor risk, audit, and business owners.
Use this checklist when a full control assessment is not required, or as a lightweight review before deeper assessment.
1. Review Information
AI Use Case Name
[Enter AI use case name]
Review Date
[Enter date]
Review Type
Select one:
[ ] Initial review
[ ] Pilot review
[ ] Production readiness review
[ ] Major change review
[ ] Vendor AI feature review
[ ] Agentic AI review
[ ] Exception review
[ ] Post-incident review
[ ] Periodic review
Reviewer
Name:
Function:
Email:
Business Owner
Name:
Function:
Email:
Technical Owner
Name:
Function:
Email:
Assigned Risk Tier
Select one:
[ ] Tier 1: Low-risk productivity or public-data use
[ ] Tier 2: Internal productivity with enterprise data
[ ] Tier 3: Decision-supporting AI
[ ] Tier 4: Action-capable AI
[ ] Tier 5: High-impact autonomous or regulated AI
[ ] Unknown
2. Intake and Inventory Checklist
Inventory Review Notes
[Document inventory and classification findings]
3. Identity and Access Checklist
Identity and Access Review Notes
[Document identity, access, delegation, privilege, and revocation findings]
4. Data Boundary Checklist
Data Boundary Review Notes
[Document data access, retrieval, retention, reuse, and vendor processing findings]
5. Prompt and Input Checklist
Prompt and Input Review Notes
[Document prompt, input, system prompt, context, and prompt injection findings]
6. Output and Decision Checklist
Output and Decision Review Notes
[Document output validation, decision, review, generated record, and downstream use findings]
7. Tool and Action Checklist
Tool and Action Review Notes
[Document tool, action, approval, boundary, logging, kill switch, and rollback findings]
8. Human Accountability Checklist
Human Accountability Review Notes
[Document ownership, decision authority, approval, escalation, override, and risk acceptance findings]
9. Assurance and Testing Checklist
Assurance Review Notes
[Document testing, validation, assurance, finding, and regression requirements]
10. Monitoring, Logging, and Evidence Checklist
Monitoring and Evidence Review Notes
[Document logging, monitoring, evidence, retention, reconstruction, and audit findings]
11. Incident Containment and Recovery Checklist
Incident Review Notes
[Document incident, containment, recovery, vendor escalation, and evidence preservation findings]
12. Vendor AI Checklist
Complete this section if a vendor AI capability is involved.
Vendor Review Notes
[Document vendor AI findings, gaps, evidence limits, and required conditions]
13. Review Outcome
Overall Review Result
Select one:
[ ] Approved
[ ] Approved with conditions
[ ] Approved for pilot only
[ ] Requires remediation before approval
[ ] Requires exception approval
[ ] Requires additional review
[ ] Rejected
[ ] Deferred
Key Findings
Required Conditions
[List conditions that must be met before approval, production deployment, scaling, or continued operation]
Exceptions Required?
[ ] No
[ ] Yes
[ ] Unknown
Residual Risk
[Describe residual risk after controls and conditions]
14. Approval
Reviewer Decision
Name:
Decision:
Date:
Notes:
Business Owner Decision
Name:
Decision:
Date:
Notes:
Architecture / Security Decision
Name or forum:
Decision:
Date:
Notes:
Risk / Governance Decision
Name or forum:
Decision:
Date:
Notes:
15. Summary
Use case:
Review type:
Risk tier:
Overall result:
Key gaps:
Required conditions:
Exceptions:
Residual risk:
Approval status:
Next review date: