AI Policy Desk · Workflows

A Lightweight AI Usage Audit Workflow for Small Teams

A step-by-step workflow to audit AI usage in your organisation—inventory, sampling, interviews, and follow-ups you can run without a compliance department.

Back to blog

A Lightweight AI Usage Audit Workflow for Small Teams

Audits sound enterprise-heavy. For a small team, an AI usage audit is simply a structured look at what people actually use, what data is involved, and whether that matches your written rules. This workflow fits a half-day to two-day effort the first time, then shorter quarterly updates.

If your policy and inventory are still empty, read How to Build an AI Governance Framework for a Small Team first—this audit assumes you have at least a draft AI policy and owner.

Outcomes you want

By the end you should have:

  1. An updated tool and use-case list aligned with reality.
  2. A short risk-ranked view (who, what data, which workflows).
  3. Action items: approvals, training, blocks, or vendor reviews—each with an owner and date.

Roles (can be part-time)

Phase 1 — Prepare (same week)

Phase 2 — Discover usage

Use three channels; you do not need all three every quarter.

  1. Survey — anonymous optional fields work well for sensitive tools. Ask: tools used, rough frequency, types of data, and whether usage matches policy awareness.
  2. Structured interviews — 20–30 minutes with team leads; ask for examples, not hypotheticals.
  3. Technical signals — SSO apps, browser extensions where allowed, expense lines for AI subscriptions.

Map findings to the same categories you use in shadow AI discussions: approved, tolerated-with-plan, or not allowed.

Phase 3 — Sample and verify

Pick three to five high-impact workflows (e.g. customer support replies, recruiting screens, code generation). For each:

Use your risk assessment criteria so sampling stays consistent over time.

Phase 4 — Decide and document

For each gap:

Record decisions in your governance repository—the same place you store incident and vendor reviews. Assign one owner per item and a due date within 30 days where possible.

Phase 5 — Communicate

Send a short summary: what you found, what will change, and how to request new tools. Link to the acceptable use expectations and a single contact for exceptions.

Cadence

Cadence Focus
Monthly High-risk tools only; quick inventory delta
Quarterly Full workflow above; refresh training hooks
After incidents Targeted re-audit of affected workflows