The AI Audit checklist for finance teams.

The questions that make an AI Audit complete enough for a CIO, CISO, CFO, or board sponsor to act on.

An AI Audit checklist should cover the full operating estate: approved AI tools, Shadow AI, embedded SaaS AI, internal agents, usage depth, spend waste, risk exposure, policy coverage, eval evidence, and the next workstream to fund.

Inventory

Start with what is actually running.

The inventory has to include vendor tools, embedded features, developer tooling, and internally built agents. Procurement lists miss too much.

Approved AI tools and owner by business line.

Embedded AI features inside SaaS products.

Internal agents, copilots, scripts, and production workflows.

Shadow AI tools discovered outside the approved estate.

Measurement

Measure usage depth, not login counts.

Seat activation and logins do not prove adoption. The audit should measure whether AI is inside recurring work and whether the work improves.

Role-level usage depth and workflow integration.

Spend by tool, plan tier, duplicate capability, and unused seats.

Outcome evidence: cycle time, quality, throughput, error reduction, or risk reduction.

Risk

Map the risk that can block scale.

Finance teams need a risk read that names exposure clearly. The audit should distinguish data exposure, model-risk posture, policy gaps, eval gaps, and workforce fluency gaps.

Data exposure and regulated-workflow use.

Policy coverage, exception handling, and owner assignment.

Eval coverage for internal agents and high-risk workflows.

Material findings that should appear in a board-ready summary.

FAQ

AI Audit questions, answered plainly.

FAQ

Questions buyers actually ask.

It should include inventory, Shadow AI discovery, usage depth, spend waste, value evidence, risk exposure, policy coverage, eval evidence, and a sequenced recommendation.

Readiness asks whether the organization is prepared. An AI Audit checks what is already running and whether it is creating value, risk, or evidence gaps.

Internal agents and embedded SaaS AI are often missing. Many audits cover sanctioned tools but miss the AI features and agent workflows already touching production work.