PLAYBOOK
Legal and security review playbook for AI tools
Legal and security reviews don't slow down because the teams are slow — they slow because every request starts from scratch. This playbook standardizes the questions and organizes the handoff.
The legal and security review playbook has four stations: request intake and triage (full review needed?), security review (ten-item checklist + vendor verification), legal review (terms, privacy, processing contract), and joint sign-off (a shared document with a unified decision). Each station has an owner and a window.
THE PATH
The four stations
The two teams work in parallel where possible — the joint sign-off at the end prevents two conflicting decisions.
1 DAY
Request intake and triage
Every approval request enters a unified form: tool name, vendor, proposed use case, estimated sensitivity, and requester. Triage determines: is a legal review required? And is the security review full or light?
3 BUSINESS DAYS
Security review
The ten-item security checklist + vendor verification (known incidents search, isolation model review, retention policy confirmation). Every unmet item is documented with an explicit decision.
3 BUSINESS DAYS
Legal review
Terms of service review (training clauses and data rights), privacy impact assessment if required, and processing contract. The legal team determines: are the terms acceptable? And do we need amendments before signing?
2 DAYS
Joint sign-off: one unified document, one decision
Security and legal sign one document with a unified decision — not two parallel decisions that may conflict. The document is stored in the tool registry and sent to the requester.
Security and legal reviews work in parallel where neither depends on the other's outputs — this reduces total elapsed time.
IN DETAIL
Each station detailed
Documentation at every station is not bureaucracy — it is organizational memory that prevents restarting from scratch.
1 DAY
Triage outputs
A completed form, documented triage decision, and notification to the requester with the path and expected window.
3 BUSINESS DAYS
Security review outputs
Security checklist report, vendor verification report, and security's position on approval (approve / conditional / reject).
3 BUSINESS DAYS
Legal review outputs
The legal team's position on the terms, list of required amendments if any, and the processing contract signed or with reservations listed.
2 DAYS
Joint sign-off outputs
A signed unified decision document, notification to the requester and leadership, and the tool added to the registry with its decision.
ROLES
Roles
Who leads, who approves, who reviews — and the joint sign-off puts both in one document.
- Who leads: The security lead drives the security review — legal counsel drives their review. The compliance lead follows up on the joint sign-off.
- Who approves: CISO + senior legal counsel — sign the joint sign-off document.
- Who reviews: The compliance officer — reviews the joint sign-off and ensures documentation is complete.
CLOSE
Close: the joint sign-off closes the gap between the two teams
Organizations that suffer from conflicting security and legal decisions don't have a personal dispute — they lack a joint sign-off stage. One document signed by both teams closes the loop and makes the decision defensible.
IMPLEMENTATION QUESTIONS
Asked in every launch.
Can the two teams work in full parallel?
For the security and legal reviews, yes — but the joint sign-off requires both to finish. Intake and triage is a prerequisite for both.
What if the two teams reach conflicting conclusions at joint sign-off?
The conflict is documented and escalated to the pre-named decision owner — usually CISO and general counsel together. The document reflects the conflict, the final decision, and its owner.
A standardized review starts with one form.
Print the playbook and start by designing the unified intake form — then bring the first tool sitting in the queue.