AgenTomte

July 28, 2026 · 7 min read

The AI audit checklist to run before you pay anyone

By Anna, co-founder, build and content

A real AI audit checklist covers three things, in order: whether your own business has enough data and process surface to justify paying for one, a fixed set of questions for any vendor about method and ownership, and a written spec for what a finished audit must hand you. Most of what gets sold as an “AI audit” skips straight to the third item and never checks the first two. That order matters more than anything on the checklist itself.

What does the checklist actually look like?

In brief: check your own readiness before you check a vendor’s pitch deck. Ask whether the vendor names a real external standard instead of a private method. Ask what you own when the engagement ends, and what happens if the audit finds nothing. Then define, before you sign, exactly what a completed audit must contain.

That is five checks, not fifty. A checklist that runs to three pages is usually padding designed to look thorough. The list below expands each of the five, and tells you which questions you answer yourself and which ones you put to a vendor in writing.

  • Are you big enough, and messy enough, to need a paid audit yet?
  • Is your data actually ready for someone to audit it?
  • Does the vendor point to a real standard, or a private framework only they understand?
  • Who does the work, and is the price fixed or hourly?
  • What do you own at the end, and can you walk away with it?

Are you even big enough to need a paid audit yet?

Most small businesses are not, and the honest answer is to wait. The US Census Bureau’s Business Trends and Outlook Survey, published in May 2026, put the national business AI use rate at 19.8% as of early May 2026. Firms with fewer than 20 employees stayed under that 20% mark with no significant movement between December 2025 and May 2026, while firms of 250 or more employees had already reached 37%.

That gap is the whole story. An audit scoped for a 250-person operation assumes a volume of process, data, and headcount that a 12-person business does not have. If a vendor’s pitch reads like it was written for an enterprise buyer, and your team is closer to the small end of that Census data, you are being sold a scope you cannot use. Wait until you have enough repeatable, documented work for an audit to find anything worth ranking. Buying early does not accelerate that. It just moves the invoice earlier.

Is your data ready for anyone to audit it?

Usually not, and this is the question most buyers skip. Gartner reported in February 2025 that 63% of organizations either lack, or are unsure whether they have, the data management practices an AI project needs, and predicted that 60% of AI projects would be abandoned through 2026 for exactly that reason: data that was never actually ready.

Ask yourself before you ask a vendor: do you know where your core operational data lives, who owns each source, and whether it is consistent enough for a human to reconcile by hand in an afternoon? If the honest answer is no, an audit’s first real deliverable is a data readiness map, not a build list. A vendor who skips straight to “here is what to automate” without checking this first is guessing, and Gartner’s 63% figure says the guess fails more often than it works.

Does the vendor cite a real standard, or their own private method?

A credible audit is anchored to a published external framework you could hand to a different consultant next year, not a proprietary “N-step method” only one firm understands. The NIST AI Risk Management Framework, released in 2023, already specifies this discipline: its GOVERN function names third-party software and data risk directly, and its MANAGE function covers accountability for third-party entities. Vendor due diligence is not a novel idea. It is written into a federal standard.

Ask the vendor to name the framework they align to. NIST’s AI RMF and ISO/IEC 42001:2023, the international standard for AI management systems, are both public documents with named reference controls. Either is a fair answer. “Our proprietary framework” is not, because a private method locks the deliverable to that one vendor’s language, and you cannot check their work against anything external. Portability is the point: if the method is public, any second opinion can audit the auditor.

Watch for the word “agentic” here too. Gartner’s June 2025 research counted roughly 130 vendors with a genuine agentic AI product, against thousands of companies now using the label, and predicted that over 40% of agentic AI projects will be cancelled by the end of 2027. If a vendor’s whole pitch rests on the word “agentic” and they cannot explain what makes their product different from a scripted workflow, that is the same gap Gartner is describing.

Who does the work, and is the price fixed or a day rate?

This is the question that determines your total cost more than anything else on the checklist. A fixed-price audit forces the vendor to scope the work before you pay, so the risk of overrun sits with them. A day rate rewards the opposite: every extra interview, every extra meeting, is more revenue for the firm running the clock. Ask directly who does the analysis, a senior person or a junior researcher billed at a senior rate, and get the answer in writing before you sign anything.

We wrote a full breakdown of what that pricing spread actually looks like across the market in how much an AI audit costs in 2026. The short version: the difference between a $1,900 fixed engagement and a $30,000 hourly one is rarely a difference in the quality of the finding. It is a difference in who carries the billing risk.

What must a finished audit hand you?

A finished audit is not a strategy memo. For every workflow it recommends touching, it must name a baseline metric measured today, a target delta, a stated method for measuring that delta, a named owner, and a review date. McKinsey’s State of AI 2025 survey found that fewer than one in five organizations track well-defined KPIs for their generative AI work, and that although 88% of organizations use AI in at least one function, only about 39% report any enterprise-level EBIT impact from it. A deliverable without a baseline and a review date is how a business ends up inside that gap.

Write the five fields into the contract before the audit starts: baseline, target, method, owner, date. If the vendor cannot commit to producing all five per workflow, you are not buying an audit. You are buying a slide deck with a diagnosis and no way to check it later.

How do you tell audit theatre from real audit work?

The tell is falsifiability. Real audit work produces a ranked list you can check against reality six months later. Audit theatre produces a narrative you cannot check against anything.

Audit theatreA real audit
Cites internal, proprietary methodology onlyNames an external standard (NIST AI RMF, ISO/IEC 42001)
Delivers a vision narrative or slide deckDelivers a ranked build list with effort and payback per item
Price scales with hours workedPrice is fixed before work starts
No stated owner or review dateNames an owner and a review date per workflow
Findings always recommend buying more from the same vendorWill tell you when there is nothing worth building yet

One more habit worth checking: where a vendor’s headline stat actually comes from. The widely quoted claim that 95% of AI pilots fail traces back to an MIT Media Lab Project NANDA preprint from July 2025, built on roughly 150 leader interviews and self-reported, directional data rather than audited financials, from a report that also promotes its own authors’ program. That does not make the number wrong. It makes it worth asking where a vendor got it before you let it justify their invoice.

We build our own AI operations audit against this exact test. It is scored the same way we scored the 41-agent fleet running our own companies, and if you want the fuller case for why most pilots die on the operations side rather than the model, we covered that separately in why AI pilots fail.

The plain version

Check yourself first. Check the vendor’s framework, price, and ownership terms second. Write the five deliverable fields into the contract before anything starts. If you are not ready, the right answer is to wait, and a vendor who tells you that is worth more than one who doesn’t.

Describe the workflow you are considering an audit for and you will get a straight answer on whether you need one yet, no meetings, a reply within one business day. Start async.

Tell us what you want automated

Describe the work in writing. You get a written reply within one business day: a fixed-price proposal, a scoping question, or an honest referral out.

Start at /start

▸ written reply within one business day · no call scheduled, ever

Doesn't fit a package? Tell us what you need anyway.

Questions? Ask in writing

no chatbot · a human replies

Ask us anything, in writing

A founder replies within one business day. That is the same promise clients get.