Wrivio
Get Wrivio
5 min readBy Wrivio Team

How to Run an AI Tool Audit for Your Team

An AI tool audit has one goal: find out what is actually being used and what data has gone into it. It is not a disciplinary exercise, and the moment your team believes it is, you will get a clean sheet of paper and learn nothing.

Done well it takes about a week of part-time effort and usually produces two or three surprises worth acting on.

Say the Quiet Part First

Open with an explicit amnesty, in writing, before you ask anything.

I am putting together a list of the AI tools we are actually using so I can get the useful ones properly approved. This is not about catching anyone. Nothing anyone tells me here goes into a review or a personnel file. I would rather know about a tool and approve it than find out about it in an incident.

Say it once and then behave consistently with it. If the first honest answer someone gives you results in a talking-to, you will not get a second one from anyone.

Ask Three Questions

Keep the survey short enough that people finish it in two minutes.

Which AI tools have you used for work in the past three months? Free-text, not a checklist, because a checklist only surfaces the tools you already knew about.

What kinds of work text have you put into them? Give categories rather than asking for specifics: internal drafts, customer emails, contracts, code, financials, personal data, meeting recordings.

What would you stop doing if it went away tomorrow? This one tells you which tools are load-bearing and which are curiosity. It also tells you where to prioritize approval.

Check the Other Sources

Self-report is the main instrument, but it is not the only one. Three cheap checks:

Browser extension inventory on managed machines. Extensions are the most common uncontrolled path and the easiest to forget.

Expense reports for the last two quarters. Individual subscriptions on personal cards are extremely common and invisible to procurement.

Outbound network logs for known AI domains, if you have them and if your privacy policy permits. Use this to size the problem, not to identify individuals, and say in advance that this is what you are doing.

Classify by Exposure, Not Popularity

Once you have the list, sort by what went in, not by how many people use it.

Highest concern: tools that received customer personal data, contracts, credentials, health or financial records, or unreleased material. These need a decision this week.

Medium: tools handling internal drafts, meeting notes, and general work text. Worth approving properly and setting terms for.

Low: tools used on public information, published content, or personal learning. Note them and move on.

A tool used by one person on client contracts is a bigger problem than a tool used by twenty people on blog drafts.

Write the Findings So They Get Read

Audit write-ups die when they arrive as fourteen pages. Lead with the decision you need.

Before:

Following a comprehensive review of departmental artificial intelligence tool usage conducted over the preceding two-week period, a number of findings have emerged which may warrant further consideration by the leadership team in due course.

After:

Fourteen AI tools are in use across the team. Three received customer data, which we should stop this week. Six are useful enough to approve properly. The rest are low risk and can stay unmanaged. I need a decision on the three by Friday.

A Wrivio Context for this could say:

Rewrite this as an internal audit summary for leadership. Corporate register, complete sentences, no hedging. Lead with the count, the risk, and the decision needed by when. Keep it under one hundred and fifty words. Keep every number, tool name, and date exactly as written, and do not add findings or recommendations that are not in the original.

Press Ctrl+Shift+Space, paste the long version, and check the diff. In an audit summary, a rewrite that turns “three received customer data” into “some tools may have received customer data” has destroyed the entire point of the document.

Close the Loop

The audit is worthless without a visible outcome within two weeks. Approve something. Publish the approved list. If you found genuine problems, fix the workflow that caused them rather than reminding people to be careful.

And say thank you publicly to the people who reported the awkward things. That is the entire currency you have for the next audit.

Common Questions

How often should we repeat this?

Twice a year is enough for most teams, with a short check whenever a major new tool appears.

Should we audit personal devices?

You generally cannot and should not. What you can do is remove the reason people reach for them, which is usually a missing approved option.

What if we find a real data breach?

Stop the audit and follow your incident process. Notification timelines under GDPR and similar regimes are short and start when you become aware.

Download Wrivio for Windows to give your team an approved rewriting option that keeps text on the device, and take a whole category off the audit list.