CHECKLIST

AI tool security checklist

Adoption without a security review is signing a risk that was never estimated. These ten cover the questions a good security team asks — ordered from where most incidents begin.

Short Answer

Ten security items to evaluate AI tools: data destination and processing terms, authentication without password reliance, logging and audit, retention and deletion, tenant isolation, terms review, key management, offboarding path, model provenance, and privacy review.

THE CHECKLIST

AI tool security checklist

Ten questions you must answer before signing the adoption. Every item is an action and a verification criterion.

Tick this list with the technical and legal team — the gaps are the conditions you demand from the vendor before signing.

0 / 10

This page prints cleanly — suitable as a baseline for the tool review meeting.

EVALUATION QUESTIONS

Asked in every review.

Is this list sufficient as a substitute for a formal security assessment?

No — it is a starting point and quick reference. A formal assessment digs into your specific architecture; this list ensures the right questions are asked first.

What do we do when a vendor refuses to answer some items?

Refusal is a position — record it in the adoption decision. Unanswered items mean unestimated risks, which the decision-owner must know.

How often do we repeat this review for already-approved tools?

Annually at minimum, and at every material change to the terms of service or the underlying model. A model provider change requires an immediate review.

Adopt with open eyes.

Print the list and test your current tool — what you cannot answer is what you need to demand from the vendor before signing or renewing.