Back to Checklists
Checklist

AI Tool Due Diligence Checklist

Updated October 20266 min read

How to Use This Checklist

This is a starting point. Adapt it to your organization, the tools you use and the law where you work, and treat it as a set of questions to ask, not legal advice.

Name one owner, and have that person work with procurement, IT and program staff, because involving them makes the review more collaborative and effective. Run the list when you consider a new tool, and again when a product you already use adds or updates AI features. One reported case shows why: a nonprofit's chatbot gave misleading, harmful responses to vulnerable users after a product update switched on unexpected AI features.

In the aid sector, one report found that much AI adoption is driven by individual staff using large language models for daily tasks. So this list also applies to tools staff already use, and staff should use only tools the organization has approved.

For each item, write down the answer and where it came from, such as a vendor document, a screenshot of a setting or a test you ran. If you cannot find an answer, record "unknown" and treat it as a risk.

Purpose and Fit

Start by asking whether an AI system is appropriate at all for the task. Write down what you expect before you look at any specification.

  • The purpose, the expected benefits and the settings where the tool will be used are written down.
  • You have asked whether AI is appropriate for this task at all, or whether another method would serve better.
  • The laws and norms that apply to this use, in the places where the tool will be used, are listed.
  • The costs of errors, not only the purchase price, are examined and written down.
  • Staff who already use unapproved AI tools for work are identified.

Data Protection and Privacy

AI can create new privacy risks by letting someone infer who a person is or reveal private information about them. Read the tool's terms of use and privacy policy with that in mind.

  • You know what personal data the tool collects, stores and processes, and how the terms say it is handled and protected.
  • You have considered whether the tool could identify individuals or reveal private details, especially for health, location or biometric data.
  • The vendor says whether your data is used for model retraining or reviewed by its employees or partners, and where it is stored.
  • The vendor will support any access and deletion requests you are required to meet.
  • Controls limit what is sent outside your organization, such as a login and a confirmation before sensitive material is sent.
  • You have recorded that most model developers do not disclose what data their models were trained on, so you cannot be sure whether personal data was involved.
  • Staff have a written rule: no sensitive or confidential information goes into a prompt unless the data is processed locally or under proper access controls.

Security

Users typically lack the visibility and expertise to fully understand and address the risks of the systems they use. Ask the vendor what it can show you.

  • You have evaluated the provider's own security posture.
  • You have asked whether the vendor evaluated the system for security before release, for example by benchmarking or red teaming, and whether it is clear about known limitations.
  • You have asked whether you can get audit logs and other security information, and whether that costs extra.
  • You have asked what the vendor does about attacks such as prompt injection and data poisoning, since these tools widen the attack surface.

Vendor Terms and Dependency

Read the terms before you sign, and look for ways they could tie you to one provider.

  • Procurement and risk staff have agreed the criteria for approving third-party software or services that offer or add generative AI features.
  • You have read the terms of use and privacy policy.
  • You have checked whether recent updates switched on AI features or changed how data is handled.
  • You have considered whether depending on this provider could trap you in digital and financial dependency.
  • For mission-critical work, an alternative is ready if the tool does not meet your security criteria.

Accuracy, Bias and Accessibility

Generative tools can state false content with complete confidence. Test with realistic examples from your own program, with personal details removed, in the languages your users speak.

  • You have tested in the local languages of the people you serve, since performance can differ between languages and groups when training data is not representative.
  • You have checked for confidently stated false content, and for errors that could harm vulnerable users.
  • You have checked whether people with disabilities, or people affected by the digital divide, can use the tool.
  • You have looked for signs of discrimination, such as unrepresentative data or poor results for some groups.
  • The test examples and the results are written down.

Human Oversight and Staff Use

Interaction with these tools can lead to over-reliance, so define who checks the outputs and write the process down.

  • Staff have clear guidance on how they can and cannot use AI tools, rather than blanket bans by job title.
  • A rule says individuals remain responsible for the content they create and must independently verify AI output.
  • Your organization has stated when and how staff must disclose AI help in a work product.
  • Work that needs legally certified accuracy, such as financial reports, has human verification.
  • People affected by the tool can give feedback, appeal and have an output overridden.

Cost and Exit

Price is only part of the cost. Count what a wrong answer does to people, and what the tool consumes.

  • Costs are documented, including the non-monetary costs that result from errors.
  • You have noted that training and running AI systems uses significant energy and resources.
  • A process exists to phase the tool out safely, without increasing risk.
  • If the tool is high-risk, a contingency process covers failures or incidents.

Sign-Off

The owner decides after hearing from procurement, IT and program staff, and keeps the completed checklist with its evidence.

  • The decision is recorded: adopt, adopt with conditions, or do not adopt.
  • Anything marked "unknown" has an owner and a date, or is a stated reason for not adopting.
  • Someone is named to track regulatory and technical developments and keep your policies current.
  • A new review is set for when the product is updated or how you use it changes.