Internal
AI Tools
Audit
By the time a larger company writes its first AI policy, staff may already use dozens of model accounts, browser extensions and meeting tools. We establish what is in use, what data reaches it and who should own each decision.
Find the AI tools
Check data and ownership
Keep, restrict or remove
Each tool has an owner and a clear decision.
Inventory
TOOLS WITHIN THE AGREED SCOPE
Data flows
ACCOUNTS, ACCESS AND PROVIDER TERMS
2 Aug 2026
AI ACT GENERALLY APPLICABLE
Standards and legal duties are mapped to the systems, data and territories in scope.
Internal AI use can outgrow the approved list
AI may enter the business through individual accounts, browser extensions, meeting tools and features added to existing software. Procurement records alone may miss some of it.
We combine agreed technical evidence with staff interviews to identify tools and the data they handle. The report records the coverage and any gaps.
Each identified use has an owner, permitted data types and actions to resolve unclear settings or contracts.
WHAT YOU THINK YOU HAVE
- "A few people using ChatGPT"
- An email saying "don't paste client data"
- Copilot "switched off in the tenant"
- A vendor list that ends at SaaS
- Nothing the board could sign off on
WHAT YOU'LL HAVE AFTER
- Named inventory of tools found within the agreed scope
- Acceptable-use policy your team will read
- Tenant settings reviewed, training opt-outs set
- Vendor checks for identified AI suppliers
- Audit trail mapped to NIST AI RMF and ISO 42001
Where shadow AI creates risk
The audit checks how staff access tools, what information they submit and what control the business has over those accounts.
Personal-account paste
Personal accounts can sit outside company administration and contractual controls. We check the actual provider terms, retention and training settings rather than assuming a paid account is suitable.
Copilot oversharing
Microsoft 365 Copilot respects the user's existing access. We review broad SharePoint and OneDrive permissions that could make sensitive material available to more people than intended.
Browser extensions
Chrome extensions that "summarise this page" or "rewrite this email". The audit checks browser permissions, vendor terms, DPA status and who you would name in a breach notice.
SaaS AI switched on
Slack AI, Notion AI, Atlassian Intelligence, Zoom AI Companion, HubSpot Breeze. Each has its own admin controls, data terms and opt-out path. Someone has to read them before the feature becomes normal work.
Agents and custom GPTs
Someone built a custom GPT for sales. It reads from a Google Drive folder. Nobody documented which folder, who can use the GPT, or what it returns. Now it's part of the workflow.
What belongs in the AI register
The register covers chat apps, coding tools, browser extensions, SaaS features and API calls. Each entry has an owner, data class and risk tier.
Chat assistants
ChatGPT, Claude, Gemini, Copilot, Perplexity, Mistral. Per account: free or paid, personal or corporate, training opt-out status.
Coding tools
Cursor, GitHub Copilot, Claude Code, Windsurf, Replit, Lovable, Bolt.new. Which repos they touch, what code they've pushed, who's been pasting in secrets.
Browser extensions
Page summarisers, meeting note-takers, email rewriters, sales copilots. Per extension: vendor, permissions, data leaving the browser.
SaaS AI features
M365 Copilot, Google Workspace Gemini, Slack AI, Notion AI, Atlassian Intelligence, HubSpot Breeze, Zoom AI Companion. Status, scope, training defaults.
Custom GPTs & agents
Internal GPTs, n8n / Zapier / Make automations, Claude Projects, anything your team has wired together. Owner, data sources, who can run it.
Meeting recorders
Otter, Fireflies, Granola, Read.ai, Tactiq. What gets recorded, where it's stored, which clients have given consent.
Image, audio & video
Midjourney, Runway, ElevenLabs, Suno, Veo, Sora. Per tool: licence terms, commercial use rights, who's paying.
API calls in your own apps
OpenAI, Anthropic, OpenRouter, Bedrock and Vertex calls inside your products. We record spend, models, system prompts and logged inputs.
What the review gives you
The core review produces the register, ownership model, policy changes and immediate controls. Ongoing checks are optional and separately scoped.
We do the discovery, interviews, tenant review and write-up. You get a short board paper and an IT action list. Timing depends on access and the size of the estate.
BOOK AN AUDIT CALLDiscover
SSO logs, expense reports, browser extensions, SaaS admin consoles, repo histories, the corporate card statement. Short interviews with the people using the tools. You see what's been bought, what's free, and what nobody's mentioned in a stand-up.
Classify and tier
Each identified use case gets a data class and a practical risk tier. Where the EU AI Act applies, we record the relevant category, territorial scope and whether you are acting as a provider or deployer. The reasoning is written down so it survives the next staff change.
Fix and document
The report proposes account, permission and policy changes for your owners to approve. Implementation can include provider settings, extension removal and vendor agreements, with the affected teams involved.
Keep it current (optional, quarterly)
An optional review can update the register when teams adopt new tools or vendors change their features. Coverage, frequency and cancellation terms are agreed separately.
Frameworks the audit maps against
We map relevant findings to recognised frameworks so your security team can reuse the evidence. This supports an assurance process without certifying the organisation.
AI Management Systems
The first international standard for managing AI as a system. Published December 2023, certifiable. The register, policy and risk process we build map to Annex A controls.
Govern, Map, Measure, Manage
NIST's AI Risk Management Framework (January 2023) plus the Generative AI Profile (NIST AI 600-1, July 2024). The structure our audit report follows so the work is recognisable to security teams that already use NIST.
Regulation (EU) 2024/1689
The AI Act became generally applicable on 2 August 2026. The exact date depends on the duty: Annex III high-risk requirements apply from 2 December 2027 and product-related high-risk requirements from 2 August 2028. We record which rules apply to each use case instead of assigning risk from a product name alone.
ICO Guidance on AI & data protection
The ICO's AI and data protection guidance, AI audit toolkit, and lawful-basis, transparency and DPIA expectations that already apply to anything touching personal data. We flag where you owe a DPIA and draft the first one.
Prompt injection, supply chain, leakage
The 2025 edition of the OWASP Top 10 for LLM Applications. We use it as the technical checklist for any tool that takes prompts or runs agents inside your business.
Adversarial threat models
MITRE ATLAS covers adversary tactics against AI systems, while Google's Secure AI Framework provides practical controls. We use them when the audit includes your own products as well as employee tools.
Our own AI use is governed as an operating system
Raq.com gives our work shared accounts, permissions, tools and records. The same practical questions sit behind an internal audit: who is using what, with which data, under whose authority and at what cost.
When this is worth discussing
We work best when there is a real operating problem, enough volume to measure and people from the affected teams who can make decisions.
Usually a good fit
- An established UK business, usually with annual revenue above £10m
- A repeated process with a known cost, delay, error rate or capacity problem
- A senior sponsor and a day-to-day owner who understand the work
- Access to the relevant staff, systems, sample records and security requirements
We may point you elsewhere
- A standard product already covers the process well
- The requirement is a one-off small build with no wider operating case
- There is no owner or access to the people and data needed to test the result
- The plan relies on AI making high-impact decisions with nobody responsible for review
Questions from IT, legal and compliance
We're not a regulated business. Do we really need this?
If you process anyone's personal data, UK GDPR is already on you. If you provide or deploy AI systems used in the EU, the AI Act may be on you too. If your customers are enterprises, their next security questionnaire is likely to ask. The audit gets you the answers before the questionnaire arrives.
Aren't you just going to ban everything?
The outcome is a list of permitted uses, data restrictions and changes required. Some tools may stay as they are, others may need different settings, accounts or a replacement.
How long does it take?
Timing depends on the teams, tools and evidence in scope, including access to admin settings and staff availability. The proposal states those dependencies.
What do you need from us?
We agree read-only access to relevant identity, software, expense and endpoint records, plus interviews with representative users. Employee monitoring and privacy boundaries are settled before collection.
Will the team tell you?
We explain the review's purpose and privacy boundaries to staff, then compare interviews with the agreed logs and records. The report identifies remaining discovery gaps.
What about Microsoft Copilot? We've already paid for it.
Copilot inherits access from Microsoft 365, so existing SharePoint and OneDrive permissions are part of the review. We map what each role can retrieve, identify over-broad sharing and agree any permission changes with your Microsoft 365 owner.
Are you lawyers?
We provide the technical findings and draft operational controls. Your data-protection and legal advisers remain responsible for legal interpretation and policy approval.
How much does it cost?
The core review is fixed-fee against an agreed scope. Implementation and any recurring review are quoted separately.
Book an internal AI tools audit
Tell us how many teams and systems are in scope, whether a policy exists and what prompted the review. We will explain the evidence needed for a useful register and action plan.