The AI data access audit checklist
Use this checklist before connecting AI to live company systems.
1. List approved AI tools and accounts
Name approved AI tools, account owners, whether business data can be entered, and whether personal accounts are allowed. If unapproved AI use is common, read the Shadow AI policy guide before expanding access.
2. Identify sensitive folders and records
Mark customer, staff, finance, legal, commercial, strategy, credential, and confidential project information. Decide whether each source is allowed, restricted, excluded, or human-summarised. If personal information is involved, run an AI Privacy Impact Assessment NZ before connecting tools.
3. Find “everyone” or broad staff permissions
Look for folders, drives, channels, dashboards, or exports visible to wider groups than intended. Broad access is convenient until AI makes search and summarisation easier.
4. Separate read-only access from edit, send, or publish access
Reading a source is not the same as changing it. Separate read, draft, recommend, update, send, publish, delete, admin, and blocked permissions with the AI Agent Permissions Checklist.
5. Decide what staff must not paste into AI tools
Write simple prompt rules for customer information, staff information, contracts, pricing, credentials, finance data, private disputes, and confidential strategy.
6. Set approval gates for customer-facing outputs
AI-prepared customer emails, proposal wording, public copy, pricing, promises, reports, legal wording, HR material, or privacy statements should stay human-approved. Use AI Approval Gates for Business Automation for the stop points.
7. Log exceptions and revoke unused access
Record unusual access, incorrect outputs, staff questions, incidents, and permissions no longer needed. Remove stale accounts, old contractors, unused integrations, and abandoned exports.