Important: “AI audit” can describe different legal, technical and governance reviews. This article covers operational readiness and is not regulatory certification or legal advice.

Start with evidence, not assumptions

A business preparing for review often begins by writing a policy. That is useful, but it does not answer the first question: what AI is actually in use?

The official software list is rarely complete. AI can sit inside CRM, recruitment, finance, meeting, design and customer-support tools. Staff may also have personal accounts that procurement cannot see.

Build the inventory from several sources

Ask each team what it uses, but verify the answers. Search purchase receipts and welcome emails for subscriptions. Review recurring bank-card charges. Check Google or Microsoft connected applications, browser password managers, app-store subscriptions and the AI features enabled inside existing business platforms.

For every system, record the product, feature, purpose, owner, users, vendor, data involved and whether an important decision depends on its output. Include trials, dormant tools and systems used by contractors.

Define the scope clearly

State which business units, locations, systems and time period the review covers. Also say what is outside the review. An exclusion is simply something not assessed—for example, a US subsidiary, an experimental tool no longer accessible or a client-controlled system.

This prevents a limited review from being mistaken for proof that the whole organisation is compliant.

Map roles, data and decisions

For each AI use, decide whether the business provides the system, deploys it, imports it or distributes it. If personal data is involved, record whether the business is the controller or processes the information for someone else, why the data is used and the relevant lawful basis.

Pay particular attention to recruitment, worker management, credit, education, healthcare, essential services, biometrics and decisions that significantly affect a person. Those uses need earlier specialist review.

Collect the vendor evidence

Gather contracts, data-processing agreements, security information, data locations, retention settings, subprocessor lists and details of any international transfer mechanism. Record whether prompts or customer data can be used to train the vendor’s models and whether that setting can be disabled.

A vendor saying “enterprise-grade” is not evidence by itself. Keep the actual document, date reviewed and decision made.

Test the controls in practice

Do not stop at policy wording. Use a test record to see whether you can find, export and delete personal information. Trigger the human handover on a chatbot. Ask a reviewer to explain an AI-generated score. Confirm that a departing employee loses access. Test how staff report an unsafe output or accidental data disclosure.

Record the result, owner and corrective action. A failed test that produces a tracked improvement is more useful than an unchecked box.

Plain-English takeaway

An audit should leave you with decisions, owners and evidence.

If the result is only a score, it is difficult to defend and even harder to improve.

Your audit preparation folder

Official sources: EU AI Act ↗ · Irish DPC guidance on AI and data protection ↗ · European Commission enforcement overview ↗