PLAYBOOK
AI tool approval playbook
Every organization has tools awaiting a decision — some waiting months because the path is unclear. This playbook makes the decision predictable and documented.
The tool approval playbook has four stations: initial triage (does it merit full review?), the security and legal review (checklist + processing contract), the approval decision (documented with reasons), and post-launch tracking (register measures actual usage versus declared justification). Each station has an owner and a window.
THE PATH
The four stations
Every tool passes the same path — and speed varies by sensitivity level, not by the requester's name.
2 DAYS
Initial triage: does it merit full review?
Five quick questions: does it process sensitive data? does it send data outside the system? does it need system privileges? is the category subject to regulatory restrictions? has it been requested by more than one department? Two "yes" answers open the full review.
5 BUSINESS DAYS
Security and legal review
The ten-item tool security checklist + terms of service review + processing contract (if required). Every unmet item is documented with a decision: accepted with condition / rejected for this reason.
2 DAYS
Approval decision: documented with reasons
The decision documents four elements: approved / not approved — for these reasons — under these conditions — and the next review has a date. A document that is stored, not a debate that is forgotten.
FIRST MONTH & QUARTERLY
Post-launch tracking: register tests the justification
One month after launch, the register is read: does actual usage match the declared justification? And did unexpected use cases emerge requiring additional security review?
Durations are illustrative — light-review paths may be faster depending on tool sensitivity level.
IN DETAIL
Each station detailed
What is documented prevents repeated debate — every tool ends with a document, not a memory.
2 DAYS
Initial triage outputs
A documented decision: full review / light review / direct rejection — with justification. And notification to the requester with the expected window.
5 BUSINESS DAYS
Review outputs
The security checklist report, the legal team's position on the terms, and the processing contract signed or with justification for its absence.
2 DAYS
Approval decision outputs
A signed decision document, notification to the requester and approvers, and addition of the tool to the approved or rejected registry.
FIRST MONTH & QUARTERLY
Tracking outputs
A monthly actual-usage report, a decision to review approval if reality diverges from justification, and notification to users of any change.
ROLES
Roles
Three roles suffice for most organizations — and the path works even with a small team.
- Who leads: The IT or procurement lead — handles initial triage and follows up on stages.
- Who approves: CISO + legal — sign the approval decision and its conditions.
- Who reviews: Compliance — reviews the quarterly tracking and raises a recommendation when reality diverges from justification.
CLOSE
Close: a documented path reduces debate and builds trust
Organizations that spend months on a single tool decision don't suffer from over-rigor — they suffer from a missing path. Standardized questions and a documented decision make a rejection respectable and an approval reassuring — and make the discussion start from facts, not fears.
IMPLEMENTATION QUESTIONS
Asked in every launch.
Does every tool go through the full path?
No — initial triage classifies tools: full review for high-sensitivity, light review for others. The criterion is the five questions, not the requester's name.
What if the vendor refuses to answer some security checklist items?
The refusal is documented in the decision document. Any approval that ignores unanswered items is a decision with accepted risk — it must be intentional and documented.
Standardize the questions. Speed the decision.
Print the playbook and apply its stations to the first tool waiting — then bring whatever you got stuck on.