Free checklist

AI Agent Audit Checklist

Use this checklist for one agent or a full workspace. Record the answer and the evidence source; “we think so” should become a follow-up item.

1

1. Define the audit scope

Write down what is included before reviewing controls. A precise scope prevents a polished report from implying broader assurance than the work supports.

  • Name the organisation, workspace or business process.
  • List the agents included and excluded.
  • Record the review date and reviewers.
  • State that information is declared unless independently verified.
  • Identify the people who can confirm access and workflow behaviour.
2

2. Inventory each agent

Create one record per distinct workflow, even when several agents use the same model or automation platform.

  • Business purpose and lifecycle status.
  • Business owner and technical maintainer.
  • Department and affected users or customers.
  • Connected tools, service accounts and data sources.
  • Current review date and known changes since the last review.
3

3. Review access and autonomy

Describe the effective capability in plain language. “CRM access” is too broad to assess.

  • Can the agent read customer or employee data?
  • Can it create, update or delete records?
  • Can it send external messages?
  • Can it access source code, infrastructure or secrets?
  • Can it trigger payments, refunds or contractual steps?
  • Does it choose actions autonomously or follow a fixed sequence?
4

4. Check operational safeguards

Controls should work at the point where harm can occur, not only after the workflow finishes.

  • Human approval before high-impact actions.
  • Useful logs that identify agent actions.
  • Input and output validation where relevant.
  • Permission scopes limited to the stated purpose.
  • Rate, amount or destination limits.
  • A tested way to pause or revoke access.
5

5. Record findings and actions

For each gap, explain the impact, recommended change, priority and owner. If the team accepts a risk, record why and when the decision expires.

  • Link each finding to an observed permission or missing control.
  • Separate urgent high-impact issues from routine improvements.
  • Assign a person responsible for the next step.
  • Set a due date where the plan supports it.
  • Schedule the next review after meaningful changes.
6

Practical advice

Begin with agents that can affect customers, money, source code or sensitive records. Ask workflow owners to demonstrate the approval and stop process instead of only confirming that one exists.

Keep the final report honest about evidence. A declarative review is valuable, but it is not the same as testing production controls.

FAQ

Questions people ask before a review

Run the checklist in a workspace built for the review.

Keep inventory, findings, actions and the final report connected as you work.

Start an agent audit