Use Case · MAIA®

A new AI feature is a governance decision, not just a technical one.

Introducing an AI feature, chatbot, or automated decision tool carries risks a standard IT change request does not capture — data exposure, unreliable output, and unclear accountability. XGRC® gives organisations a structured way to assess, approve, and monitor AI-related change.

Book a demo
The problem

A standard change form does not ask the questions AI risk requires.

Most change management processes were built for infrastructure and application changes. They do not prompt anyone to confirm what data an AI service sees, whether a vendor trains on it, or what happens when the model gets something wrong. Those gaps only surface after go-live.

AI features are introduced through the standard change process, which does not ask about data flow, model training, or bias

Nobody has confirmed whether the AI output is advisory or triggers automated actions

Users are not warned against entering confidential or personal information into an AI tool

There is no rollback plan if the AI feature produces unreliable or unsafe output

The XGRC® approach

A risk-based process for AI-related change.

01

Classify the change by AI use case and risk rating before approval

02

Assess data privacy, data flow, and cross-border transfer up front

03

Review vendor terms, security controls, and access management

04

Test for accuracy, bias, and unauthorised data exposure before go-live

05

Brief users and support teams, with clear disclaimers on AI output

06

Confirm a rollback plan and monitor the feature after launch

How it works

Tracked as a governed change, not left as a technical footnote.

  • The AI change checklist raised and tracked as an auditable change record
  • Approvals from business, technical, and security owners captured against the change
  • Actions arising from the review tracked through to verified closure
  • The same governance principles the checklist requires — audit trail, permission alignment, data boundary controls — built into MAIA®, XGRC®'s own AI capability

Governance that keeps pace with AI adoption

XGRC® links the AI change checklist to your existing change, risk, and action management processes, so an AI feature is approved, tested, and monitored with the same rigour as any other high-risk change — and MAIA®, XGRC®'s own AI capability, is built around those same governed-AI principles.

From manual to XGRC®

The same AI rollout, without the blind spots.

Manual approach
  • AI features approved through a generic change form
  • Data flow and vendor training use unconfirmed
  • No disclaimer or user guidance before go-live
  • No documented rollback plan
XGRC® approach
  • A dedicated AI risk classification and review process
  • Data flow, privacy, and vendor terms assessed before approval
  • User guidance and disclaimers issued with the change
  • Rollback plan and post-launch monitoring tracked to closure
Free resource

AI Change Management Checklist

  • Scope, ownership, and risk classification
  • AI use case and business impact
  • Data privacy and data flow
  • Vendor and security review
  • Testing and assurance
  • Rollout, rollback, and monitoring
PDF · Governance-focused · v1.0
Standards and frameworks

Govern AI change against the standards that are catching up to it.

  • ISO 42001
  • ISO 27001
  • POPIA
  • GDPR
  • AI Governance
  • Change Management
Scope of application

One process for every AI-related change.

  • New AI features and tools
  • Chatbots, copilots, and generative AI integrations
  • Automated decision and recommendation systems
  • Third-party AI vendor onboarding
Frequently asked

Common questions.

What is an AI change management checklist?

An AI change management checklist is a structured set of questions used to assess a new AI feature or tool before it goes live, covering data privacy, security, testing, and rollback — questions a standard IT change request does not ask.

Why can't I just use my normal change management process for an AI feature?

A standard change process checks technical readiness but rarely asks what data an AI service processes, whether a vendor trains on it, or how the feature is disabled if it produces unreliable output — gaps this checklist is built to close.

Does this checklist apply to third-party AI tools as well as custom-built ones?

Yes. The same questions apply whether the AI capability is a vendor product, an embedded copilot, or a custom integration, because the data flow and accountability risks are the same regardless of who built the model.

How does XGRC® relate to AI governance?

XGRC® tracks the AI change checklist as an auditable change record with linked approvals and actions, and MAIA®, XGRC®'s own AI capability, is built around governed-AI principles including audit trails, permission alignment, and data boundary controls.

Bring AI change under the same governance as everything else.

Book a demo to see how XGRC® tracks AI-related change through classification, review, approval, and post-launch monitoring on one auditable platform.

Book a demo