Back to Knowledge Hub
Security & Compliance

The Enterprise AI Compliance Checklist

Twelve checks your DPO and CISO will run on any enterprise AI tool. GDPR, EU AI Act, residency, access control, and audit, in one list.

What does enterprise AI compliance cover?

Enterprise AI compliance comes down to twelve checks across four areas: data protection, the EU AI Act, access control, and auditability. If a vendor can answer all twelve without scheduling a follow-up meeting, you are in good shape.

The list below gives each check with what a good answer sounds like. Use it as an agenda for the vendor call, or as a quiet scorecard during one.

Data protection

1

Where is our data stored and processed?

A good answer: A named region you chose, in your own environment. Not "globally distributed for performance".

2

Is our data used to train models?

A good answer: No, stated in the contract. Not an opt-out toggle someone has to remember to switch.

3

Does any data leave the EU, and under what mechanism?

A good answer: Ideally: nothing leaves, so no transfer mechanism is needed. If something does leave, the vendor names the mechanism without hesitation.

EU AI Act

4

Which risk category do our use cases fall under?

A good answer: The vendor helps you classify per use case. Most internal assistant use is limited risk, but "most" is not "all".

5

Who owns each AI use case internally?

A good answer: A named owner per department, supported by the platform. Accountability that survives an audit is assigned, not assumed.

6

Is there human review where it matters?

A good answer: Decisions that affect people keep a human in the loop, and the platform makes that the easy path rather than the exception.

Access control

7

Does it use our identity provider?

A good answer: SSO against your existing directory. Joiners and leavers are handled by the process you already trust.

8

Can departments see each other's data?

A good answer: No. Isolated knowledge bases and conversation histories per department, unless someone explicitly grants access.

9

What can the vendor's own staff access?

A good answer: A specific, logged, and narrow answer. "Our engineers may access data for support" without conditions is not one.

Auditability and exit

10

Is there a complete audit trail?

A good answer: Who asked what, when, in which department, with which model. Exportable, not a screenshot in a support ticket.

11

Can IT see usage and cost per department?

A good answer: A dashboard with usage analytics and cost monitoring, so the platform stays governed after the honeymoon.

12

Can we leave?

A good answer: Your data exports cleanly, and switching models or providers does not mean rebuilding. Lock-in is a compliance risk too.

How the Plainsight AI Assistant scores

We built the platform to pass this list by architecture: it runs in your own environment, trains on nothing, isolates departments, uses your SSO, and logs everything. The deployment options, from your own cloud tenant to air-gapped, are on the sovereign AI page.

Want the wider vendor conversation beyond compliance? The CTO's AI buyer's guide widens the lens to sovereignty, cost, and operations.

Ready to see it in action?

Schedule a personalised demo and see how the Plainsight AI Assistant fits your organisation.

Request a demo