checklist
Small Team AI Security Checklist
A practical checklist for approving AI tools, protecting customer data, and setting guardrails for small teams.
This post may contain affiliate links. If you buy through these links, Cybergiz may earn a commission at no extra cost to you. Read our affiliate disclosure.
Download status
The MVP checklist is available on this page as a web version and as a downloadable Markdown template:
Download the Small Team AI Security Checklist template
The template is designed to be copied into Notion, Google Docs, Confluence, or an internal wiki. A PDF and email capture flow can be added after analytics show enough interest.
Want the editable policy bundle next? The Small Team AI Security Policy Kit validation page explains the planned $29 Stripe Payment Link test, refund/support terms, and early-access path.
Who should use this
This checklist is for a 1-50 person company that uses ChatGPT, Claude, Cursor, Notion AI, AI meeting bots, browser extensions, AI agents, or similar tools and needs a practical baseline before a formal security program exists.
The goal is to answer four operating questions:
- Which AI tools are approved?
- What data can employees use?
- Which settings must be enabled before rollout?
- What happens when something goes wrong?
This checklist follows the same practical logic as NIST Cybersecurity Framework 2.0: set governance, identify assets and data, protect accounts and systems, detect problems, respond to incidents, and recover.
30-minute setup checklist
Do these first, even before you finish a longer policy:
| Task | Owner | Done |
|---|---|---|
| Name one AI security owner and one backup. | Founder or operations lead | [ ] |
| Create an approved AI tools list. | Policy owner | [ ] |
| Ban shared AI accounts and shared API keys. | Admin owner | [ ] |
| Require MFA for AI workspaces, email, password manager, GitHub, CRM, and cloud storage. | Admin owner | [ ] |
| Move work use from personal AI accounts into managed workspaces where possible. | Admin owner | [ ] |
| Publish a one-page AI usage policy. | Policy owner | [ ] |
| Decide whether customer data is blocked, masked, or explicitly approved. | Policy owner | [ ] |
| Review AI browser extensions and remove broad-permission extensions that are not approved. | Technical lead | [ ] |
| Decide whether AI meeting bots are allowed in customer or hiring calls. | Policy owner | [ ] |
| Create an incident contact path for accidental data exposure. | Founder or operations lead | [ ] |
If you only complete this section, your team will still be in a better position than an unmanaged “everyone uses whatever AI tool they want” setup.
Data handling checklist
Use these defaults until a customer contract, regulator, or counsel requires stricter rules:
| Data type | Default rule |
|---|---|
| Public content | Allowed in approved tools. |
| Internal non-sensitive notes | Allowed in managed tools. |
| Customer data | Mask or require explicit approval. |
| Customer contracts, support exports, CRM records, and transcripts | Approval required before upload or sync. |
| Source code | Approved developer tools only; private or customer code needs technical approval. |
| Credentials, API keys, private keys, recovery codes, and tokens | Prohibited. |
| Payment, health, legal, payroll, government ID, or regulated records | Prohibited unless formally approved. |
| Board materials, acquisition plans, layoffs, compensation, and financial forecasts | Avoid by default; approval required. |
Add these checks to every new tool request:
- What data will employees paste, upload, transcribe, or connect?
- Will the tool retain prompts, files, transcripts, audio, outputs, embeddings, logs, or metadata?
- Can the company delete retained data?
- Will the vendor use company or customer content to train models?
- Can the tool connect to email, Drive, Slack, GitHub, CRM, helpdesk, calendar, or meeting platforms?
- Does the use case create customer-facing, legal, financial, hiring, security, or production output?
Vendor approval checklist
Before approving an AI vendor, collect evidence for:
| Area | Question | Minimum answer |
|---|---|---|
| Account model | Is it a managed business workspace or a personal account? | Managed workspace for work data. |
| Training default | Is business data used to train models by default? | Documented no-training default or clear opt-out. |
| Retention | How long are prompts, files, transcripts, and outputs retained? | Known retention period and deletion path. |
| Admin access | Can admins add, remove, and review users? | Named admin owner can offboard users. |
| Sharing | Can outputs, files, agents, bots, or projects be shared broadly? | Default sharing is controlled. |
| Integrations | Are connectors admin-controlled? | Email, Drive, Slack, GitHub, CRM, and calendar connectors require approval. |
| Auditability | Is there an activity log, export, or usage visibility? | At least enough visibility for access review. |
| Security docs | Does the vendor publish security, privacy, or compliance documentation? | Current docs are linked in the approval record. |
| Incident process | Does the vendor publish a support/security contact? | Contact path recorded. |
For higher-risk tools, run the AI Tool Risk Checker and save the result with the approval note.
Admin controls checklist
Require these controls before work data is allowed:
| Control | Checklist |
|---|---|
| Named accounts | [ ] No shared AI accounts. |
| MFA | [ ] MFA enabled for AI workspaces and connected systems. |
| Workspace admin | [ ] At least one active admin and one backup. |
| Access review | [ ] Monthly review of users, guests, and integrations. |
| Offboarding | [ ] Departed users removed from AI tools, extensions, bots, and connected apps. |
| Data settings | [ ] Training, retention, sharing, and export settings documented. |
| Connectors | [ ] Email, Drive, Slack, GitHub, CRM, calendar, and meeting connectors approved before use. |
| Browser extensions | [ ] Extensions reviewed for page access, site access, and requested permissions. |
| Meeting bots | [ ] Recording, transcript retention, consent notice, and external-call rules defined. |
| API keys | [ ] Keys are named, scoped, rotated, and stored outside source code. |
| Backups | [ ] Important business data has a tested backup path. |
CISA’s small-business guidance emphasizes practical basics such as MFA and backups. AI tooling does not replace those basics; it increases the value of getting them right because AI tools often connect to the systems that already contain sensitive data.
Employee rules checklist
Every employee should be able to answer yes to these:
[ ]I know which AI tools are approved.[ ]I know what data I must not paste into AI tools.[ ]I use managed company accounts for work data.[ ]I do not install AI browser extensions for work without approval.[ ]I do not invite AI meeting bots to external or sensitive calls without approval.[ ]I review AI output before sending it to customers or using it in production.[ ]I do not use AI output as final legal, financial, hiring, security, or medical advice.[ ]I know who to notify if I paste restricted data into an AI tool by mistake.
Use the acknowledgement language in the AI usage policy playbook during onboarding.
Incident response checklist
If someone pastes, uploads, records, or syncs restricted data into an AI tool:
| Step | Action |
|---|---|
| 1 | Record the tool, account, time, data type, meeting or file name, and user. |
| 2 | Stop the activity: remove the bot, disconnect the connector, revoke the extension, or pause the workflow. |
| 3 | Delete prompts, files, transcripts, recordings, or outputs if the vendor supports deletion. |
| 4 | Rotate any credentials, API keys, tokens, or secrets that may have been exposed. |
| 5 | Check whether customer, employee, regulated, or contractual notification duties may apply. |
| 6 | Update the policy, approval workflow, or admin settings that allowed the mistake. |
| 7 | Document the final decision and owner. |
Do not punish fast reporting. The security goal is to contain exposure quickly and fix the workflow that allowed it.
30-day rollout plan
Use this schedule to turn the checklist into operations:
| Timeframe | Action |
|---|---|
| Day 1 | Name owners, publish the allowed data rules, and ban shared AI accounts. |
| Day 2-3 | Inventory current AI tools, browser extensions, meeting bots, and API keys. |
| Day 4-7 | Move work use into managed workspaces where possible and enable MFA. |
| Week 2 | Review connectors to email, Drive, Slack, GitHub, CRM, helpdesk, calendar, and meeting platforms. |
| Week 3 | Run top tools through the risk checker and record approval decisions. |
| Week 4 | Review access, retained transcripts/files, policy exceptions, and employee questions. |
| Monthly | Repeat access review, connector review, extension review, and incident review. |
Recommended starter stack
This checklist may include affiliate links in future versions. For now, small teams should evaluate:
- A managed AI workspace such as ChatGPT Business, Claude Team, Microsoft Copilot, or Google Gemini for Workspace when it fits the team’s existing suite.
- A password manager such as 1Password, NordPass, Keeper, Bitwarden, or an equivalent provider.
- Endpoint protection, device management, or backup tooling appropriate for the company’s devices and data.
- A source-code workflow with branch protection, secret scanning, and code review if developers use AI coding tools.
Do not buy tools before assigning owners and settings. A small team with boring controls usually has less risk than a small team with many security products and no owner.
Evidence checked
- NIST Cybersecurity Framework
- CISA Secure Your Business
- CISA Secure by Design
- FTC privacy and security business guidance
- FTC guidance on AI privacy and confidentiality commitments
FAQ
Is this checklist enough for compliance?
No. It is a small-team operating baseline. If you handle regulated data, customer security addenda, payment data, health data, student records, legal records, or government contracts, treat this as preparation for a stricter review.
Should we approve personal AI accounts?
Only for public or non-sensitive work if your policy allows it. Work data should default to managed company workspaces so admins can remove users, set data controls, and review integrations.
What is the highest-risk AI feature for small teams?
Connectors. A prompt box exposes what an employee enters. A connector to email, Drive, Slack, GitHub, CRM, helpdesk, or calendar can expose far more data than the employee intended.
How often should we review approved AI tools?
Monthly while the program is new. After the workflow is stable, keep at least a quarterly vendor and access review, plus an immediate review after incidents or major vendor changes.
What should we do next after completing this checklist?
Pick the top three AI tools employees already use, run each through the AI Tool Risk Checker, and document approve, restrict, or remove.
Next step
Run the AI Tool Risk Checker for the first tool your team wants to approve.
If your team needs editable policy, approval, vendor review, incident, and rollout templates, review the Small Team AI Security Policy Kit validation page.