The Shadow AI Audit — a 90-minute checklist for ops leaders.
Most ops leaders running a 20–200 person team already know the headline: their team is using AI tools the company doesn't pay for, and paying for AI tools the team doesn't use. What they don't have is a 90-minute checklist that produces an actual inventory — not a Notion doc full of guesses.
This post is that checklist. It assumes you have no SaaS-management platform (you don't need one for this), no procurement system (this is upstream of procurement), and no IT helpdesk handing you reports (it doesn't help here either). What you need is a calendar block, three tabs open, and the willingness to ask a slightly awkward question.
Why "shadow AI" is the harder half of the audit
Your AP system can tell you what AI tools you pay for. That's the easy half. The harder half is what your team actually uses — including the personal ChatGPT account three of your engineers run, the Claude Pro subscription one of them expenses through a different category, the Grammarly Premium your marketing lead has billed to her personal card, and the Otter.ai bot two members of your sales team installed in their personal Zoom accounts.
None of those show up in procurement. All of them are part of your AI surface area — with the same training-privacy, sovereignty, and exit-portability risks the contracted tools have. The audit isn't worth the calendar block if it skips them.
The 90-minute, 4-step checklist
Run these in order. Don't skip Step 1 to get to the interesting part — the inventory is what makes Step 4 honest.
Pull what AP shows.
Open your accounting system or expense tool and filter the last 6 months for vendor names that include “AI,” “GPT,” “Copilot,” “Claude,” “Notion,” “Otter,” “Grammarly,” “Zapier,” “Make.” Then run a second pass for every line item under $50/month: that's where the personal-card-reimbursed AI subscriptions hide.
You want three columns: tool name, monthly cost, who signed up. The last column is the one most ops leaders skip and the one that makes Step 2 work.
Ask the awkward question.
Send three Slack DMs — one to your engineering lead, one to your marketing or content lead, one to your customer-facing lead (sales or support). Identical message:
Quick one. Doing a 30-day AI tool inventory. Can you reply with every AI tool you or your team uses at least weekly? Include personal accounts. No judgment, just trying to get to ground truth.
You will get three things back: (1) names of tools that match what's in AP, (2) names of tools that don't, (3) at least one tool you didn't know existed. The third bucket is where the audit pays for itself. Add everything to your inventory with a note: “reported by [name], not in AP.”
Score against the trust dimensions.
For each tool in the inventory, mark four things:
- Used daily, weekly, monthly, or never. (Self-reported from Step 2, cross-checked against any usage logs your tools expose.)
- Sovereignty: US-hosted, allied-hosted, or untracked? Tools without a clear answer get flagged.
- Training privacy: contractual zero-training, opt-out available, or default-on training? Most teams don't know — that's fine, mark it “unknown” and move on.
- Has SOC 2 Type II? Yes / no / unknown.
Don't try to be exhaustive in 15 minutes. You're flagging which tools need a follow-up review, not producing a final score. If you want this step automated, paste your tool list into the Rate my AI stack tool — it returns the same four answers for every tool already in our catalog, instantly.
Decide three things, in writing.
You should now have a list of 8–15 tools across four columns: name, cost, who uses it, four trust flags. Before you close the document, write three decisions — each one is something a reviewer can later ask you to evidence:
- Sanction or remove: every tool on the list is either an approved subprocessor or it is not. A tool nobody can name an owner or a business purpose for does not belong on your AI surface area, and leaving it undecided is the state you cannot defend to an auditor.
- Establish a transfer basis within 60 days: for every tool whose controlling entity sits outside your own jurisdiction, record the entity you contract with, the governing law of its terms, and the mechanism you rely on. Where that vendor also trains on customer data by default — or does not disclose its posture — note it; that is the pair a reviewer asks about together. The catalog carries what we have established per vendor.
- Record as answered: tools where you can already name the contracting entity, its country and the governing law, with a source. These are the rows you hand over unchanged the next time a customer's DPA arrives.
Save the document. Calendar a 30-minute repeat for 90 days from today. Done.
What this gets you in 90 minutes
An answer to the question you are going to be asked in writing. When a customer's data-processing agreement arrives, when a security questionnaire lands, or when an auditor asks which AI vendors process your data, the document you just built is the thing you reach for. Most teams do not have it, which is why the first response takes three weeks instead of an afternoon.
What it will not be is complete on the first pass. The tools you will miss are the ones bought on a personal card and never expensed, and the ones running inside a product you already pay for — the AI note-taker bundled into your meeting software is a subprocessor whether or not anyone chose it. Write down what you could not establish rather than leaving it blank. “Not disclosed” is a finding a reviewer can work with; a blank is not.
What this doesn't get you
Three things this checklist is honest about not producing:
- The full grade and tier per tool, with the trust dimensions that drove it. Step 3 flags risks. The full scoring (sovereignty, allied infrastructure, training privacy, conditional privacy, compliance, operational resilience, exit portability, real-world utility, caution flag) is what the Vannus manifesto publishes and what powers the catalog. A 90-minute self-audit can't get there.
- The contracting entity and governing law per vendor, quoted from the vendor’s own terms and dated. You'll know which vendors you cannot answer for. You won't have the clause, the source link, or the date it was read — which is the part a DPA reviewer actually reads.
- A 30/60/90-day plan where every step ends in a dated record. Three decisions in Step 4 is the floor. Sequencing them into something your compliance lead can execute inside their own authority is the next level.
Those three gaps are what the Vannus Concierge audit ($7,500, 14 days) closes — for the teams whose 90-minute version turned up rows they cannot answer and a deadline to answer them by. For everyone else, the 90 minutes you just spent is the highest-leverage ops work you'll do this quarter.
Part 1 (this post): The Shadow AI Audit — a 90-minute checklist for listing your AI subprocessors.
About Vannus — we're the jurisdiction record for AI vendors — we record who legally controls each vendor, and cite the vendor's own documents. No vendor influence, no paid placements. We're paid by buyers (reports and audits), not by the vendors we record. Read the methodology.