How to audit the AI tools your company uses

6 minute read · Updated 8 October 2026

Start by listing the AI tools your company uses, then record each tool’s purpose, responsible person, access, cost and next review date. Check the list against bills, company sign-in apps and team leads so you can decide what to keep, change or retire.

Already have a supported company AI account? Start with a connected-data AI review, then use this guide to complete the wider company picture.

1. Build one list of your AI tools

Start with a single list. You will not find everything on day one, and that is fine. Good places to look:

  • Expenses and card statements. Search for AI vendors and anything billed monthly that you do not recognise.
  • Your company sign-in. Google Workspace and Microsoft 365 both show which apps people have connected with their work account.
  • Team leads. Ask each team which AI tools they use every week and what they use them for.
  • Developer accounts. API accounts with OpenAI, Anthropic and similar providers often sit outside normal software buying.

With the appropriate admin access, check Google Workspace’s API controls → Manage App Access → Accessed apps, or Microsoft Entra’s Enterprise apps → All applications. These are places to look, not a complete AI inventory: personal accounts, direct subscriptions and tools without company sign-in can be missing. Do not change app permissions just to build the list.

For workspace subscriptions, use the Claude Team and ChatGPT Business admin checks to verify members, roles and paid seats separately. Put the results in the free AI tool register template or your maintained dashboard.

2. Record what each tool is for

For each tool, note what it is used for, which teams use it and who looks after the account. A one-line purpose is enough. This is what turns a list of names into something you can make decisions with.

3. Check who has access

Look at each tool's admin console. Who has a seat, who is an admin, and are there any shared logins? Pay particular attention to people who have left or changed role, and to invitations that were never accepted.

4. Check what it costs and how it bills

Note whether each tool charges per seat, by usage or both, and when it renews. Per-seat plans are predictable but easy to over-buy. Usage-based API billing can grow quietly if nobody is watching it. Renewal dates matter because they are your chance to change plans.

5. Check the security basics

  • Do people sign in with their company account rather than a personal one?
  • Is two-step verification turned on for those accounts?
  • Which API keys exist, what can they reach and when were they last used?
  • Have you reviewed each tool's data and retention settings in its admin console?

6. Decide what happens next

For each tool, decide whether to keep it, investigate an unanswered question, change how it is managed or retire it. Name the person responsible for the next action and set a date. Before removing access or cancelling a plan, check shared work, automation dependencies and how billing changes take effect.

Worked example: turn findings into a plan

Northwind Example Ltd is fictional. These invented findings show what to record after a review; they are not customer results or measured savings.

Fictional review dated 8 October 2026
What you foundNext actionOwner and date
Organisation-wide API keyCheck scope and dependenciesJordan
12 October
Four quiet paid seatsAsk users; check renewalSam
15 October
No named policy ownerAdapt and approve a policyJo
5 November

API key: establish what uses it and whether its access fits the job before planning a change. Last-use dates tell you about activity, not when a key was rotated.

Quiet seats: check whether the people still need them and what the contract allows. Low activity alone does not establish failed offboarding or a saving you can claim.

Company policy: use the copyable AI policy template to agree approved tasks, data rules, account ownership and incident reporting. Keep the approved tool register alongside it.

Complete the picture with your team

Connected data can show provider-reported activity and account settings. Ask the responsible people about the parts it cannot settle: who owns a tool, why the team needs it, what shared work depends on it and which company policy applies. Record unanswered questions as actions with an owner and date.

For a practical staff exercise, try the AI handover drill and worksheet. It helps a team separate record ownership, access, billing and automation dependencies before making changes.

Keep it current

Treat the audit as the start of a routine rather than a one-off project. A short review every quarter, plus a check whenever someone leaves or a renewal is due, keeps the picture accurate with very little effort.

Sources checked 6 October 2026

The discovery paths above were checked against Google Workspace’s app-access guidance and Microsoft’s enterprise-applications guidance. Required roles and the information shown depend on your account and provider; neither view establishes every tool your company uses.

Common questions

How often should we audit our AI tools?

Quarterly is a sensible starting point. Also check when someone leaves, when a renewal is due and when a team starts using a new tool.

Do I need admin access to every tool to start?

No. You can build the list and record purposes and owners straight away. Admin access is only needed when you want measured seat, usage and spend information from a tool.

See your company’s AI in one place.

Sign in with Google or Microsoft, name your organisation and add the tools you already use. Free, with no card.

Get started free
Help & support