How to use this

If any item in the first group is true, talk to privacy or compliance before you build, not the week before launch. The second group can wait for a scheduled review, but put it in the plan. The third group is what makes that conversation short.

This is a prompt to ask, not a ruling. Your organisation's legal and privacy teams decide what applies; the point is to bring them in when a change is still cheap.

The security review checklist covers the technical side. Terms such as data residency, data classification and audit trail are in the glossary.

The checks

When to bring in a compliance review progress
  • The feature processes personal data in a new way, or personal data it did not touch before.

    Under GDPR and similar laws this usually means a data protection impact assessment before launch.

  • It handles special categories of data, such as health, biometrics, union membership, or data about children.

  • Its output contributes to decisions about people, such as hiring, credit, insurance, access to services or performance.

    Automated decision rules and the EU AI Act's high-risk categories apply here.

  • You are adding a new vendor or model provider that will receive company or customer data.

    New sub-processors usually need a contract review and a data processing agreement.

  • Data will be stored or processed in a country or region it was not before.

  • Customer data, prompts or outputs may be used to train or fine-tune a model.

  • The feature is customer-facing and will make claims, give advice or speak for the company.

  • You operate in a regulated sector (financial services, healthcare, public sector) or under a customer contract with AI clauses.

  • Users will interact with AI without obviously knowing it, so disclosure or labelling may be required.

  • Retention of prompts, outputs or logs changes, or logs move to a new system.

  • Employees' work will be monitored, scored or summarised by the system.

  • Generated content will be published externally, where copyright and attribution questions come up.

  • A data-flow diagram covering inputs, storage, the model provider, logs and outputs.

  • The purpose, the users, and what decisions the output feeds into.

  • The vendor's data processing terms, region, retention and training policy.

  • How a person can see, correct or contest an output that affects them.

  • Your evaluation results, known failure modes and the human oversight in place.

  • The retention period for every store, including traces and prompt logs.

Checklist · · 29 checks

Security review checklist for an AI feature

What to check before an assistant, RAG app or agent goes in front of real users. Grouped by area, ticked off locally; progress stays in your browser.