AI Audit Checklist: What a Good Proposal Covers
By CodexierPublished 6 min read
An AI audit is only worth buying if it ends in a decision: build this, skip that, pilot the third. Many proposals promise strategy and deliver a slide deck. This checklist lists the deliverables that actually lead somewhere, so you can hold any offer, including ours, against the same bar.
The short answer
Process mapping and data inventory
AI does not attach to a company; it attaches to a task. An audit therefore has to start by writing down the tasks: who does them, how often, in which system, with what input and output. The mechanism is simple: automation needs a repeatable trigger and a structured result, and a map is the only way to see whether either exists.
The data inventory is the part most proposals skip. For every candidate task the auditor should record where the data lives (Fortnox, a CRM, a shared inbox, a spreadsheet on someone's desktop), whether it is reachable through an API, and how clean it is. A task with data locked in scanned PDFs is a different project from the same task with data in a database, and the estimate must reflect that.
- List of processes with owner, frequency and time per run
- Systems involved and whether each has an API or export
- Data quality notes: missing fields, duplicates, free text
- Volume: how many cases per week, and the peaks
Risk and GDPR assessment
Every use case that touches personal data needs a paragraph on lawful basis, on which supplier will process the data, and on where that supplier stores it. In Sweden the supervisory authority is IMY, and a processor agreement under Article 28 is required as soon as a third-party AI service handles customer or staff data. A proposal that says 'we take GDPR seriously' and nothing more has not done this work.
| Question the audit must answer | Why it matters |
|---|---|
| Which personal data does the use case process? | Decides whether a DPIA is needed and which safeguards apply |
| Where does the model provider store and process it? | Transfers outside the EU need a legal mechanism |
| Is the output a decision about a person? | Automated decisions with legal effect have extra rules |
| What happens when the model is wrong? | A human review step may be required, and it changes the time saved |
| Does the EU AI Act classify it as high risk? | HR screening and credit decisions carry obligations most small firms should avoid |
The point is not to block projects but to price them correctly: a use case that needs human review of every output saves far less than the demo suggests.
Prioritised use cases with estimates
This is the deliverable you are really paying for. Each use case should carry three numbers: what it costs to build, what it costs to run per month (model calls, tooling, a maintenance slot) and what it saves in hours or errors. The ranking should follow from those numbers, not from what is fashionable. Our ROI worksheet shows the arithmetic we expect to see.
Quick wins
Small build, clear data, no personal-data complications. Typically inbox sorting, document extraction, first-draft replies.
Strategic builds
Larger scope but a large recurring saving: quote generation, order intake, integration between two systems that staff currently bridge by hand.
Not now
Good idea, wrong moment: the data is not structured yet, or the process changes monthly. The audit should say so plainly.
A pilot plan you can act on
The audit should end with one pilot, not five. A usable pilot plan names the process, the person who owns it on your side, the success measure (minutes saved per case, error rate, response time), how long the pilot runs and what happens at the end. A pilot without a stopping rule becomes a permanent experiment nobody dares to cancel.
- Pick the use case with the best ratio of saving to risk, not the biggest saving.
- Define the baseline first: measure the task as it is today for two weeks.
- Run the pilot in parallel with the manual process so errors are caught.
- Set the decision date and the numbers that mean 'continue', 'fix' or 'stop'.
- Budget the running cost from month one so nobody is surprised by the invoice.
Warning signs in an audit offer
Some phrases should make you ask follow-up questions. 'AI transformation roadmap' without a process list usually means a generic deck. A fixed recommendation before anyone has looked at your data means the recommendation was written for someone else. And an audit priced as an open-ended hourly engagement has no incentive to end in a decision.
When you do not need an audit at all: if you have one obvious task, structured data and a small team, skip the audit and pilot directly; the cost of being wrong is small. An audit earns its fee when there are several candidates, personal data in play, or a budget large enough that choosing wrong is expensive. Our own audit is fixed-price at 9,990 kr, and we say on the intro call when we think you should not buy it.
Frequently asked questions
How long should an AI audit take?
For a small or mid-sized company, one to three weeks of elapsed time is realistic: a few interviews, access to the systems, a written report and a review meeting. Longer engagements usually mean the scope was never fixed. What matters more than duration is that the audit ends with a ranked list and a pilot plan.
Do I need an audit before buying a chatbot?
Usually not. A customer-service chatbot is a single, well-understood use case, and the questions that matter (which documents, which languages, what happens on handover) are answered during setup. An audit pays off when you have several possible uses and need to decide where the first budget goes.
What should the audit say about GDPR?
Per use case: which personal data is involved, what the lawful basis is, which supplier processes it and where, and whether a data protection impact assessment is needed. It should also state whether the use case falls under the EU AI Act's high-risk categories. General reassurance is not an assessment.
Can the audit be done by the same company that then builds the solution?
Yes, and it is common, but the estimates must be checkable. Ask for build and running costs per use case in writing, and compare them against at least one other quote before committing to the build. A good auditor is happy for you to do that.
Want a second opinion on an AI audit offer?
Bring the proposal you have, or none at all. In fifteen minutes we go through which of the five deliverables it covers and whether an audit is the right first purchase for you.
Book a free 15-minute call