A new AI feature is a governance decision, not just a technical one.
Introducing an AI feature, chatbot, or automated decision tool carries risks a standard IT change request does not capture — data exposure, unreliable output, and unclear accountability. XGRC® gives organisations a structured way to assess, approve, and monitor AI-related change.
A standard change form does not ask the questions AI risk requires.
Most change management processes were built for infrastructure and application changes. They do not prompt anyone to confirm what data an AI service sees, whether a vendor trains on it, or what happens when the model gets something wrong. Those gaps only surface after go-live.
AI features are introduced through the standard change process, which does not ask about data flow, model training, or bias
Nobody has confirmed whether the AI output is advisory or triggers automated actions
Users are not warned against entering confidential or personal information into an AI tool
There is no rollback plan if the AI feature produces unreliable or unsafe output
A risk-based process for AI-related change.
Classify the change by AI use case and risk rating before approval
Assess data privacy, data flow, and cross-border transfer up front
Review vendor terms, security controls, and access management
Test for accuracy, bias, and unauthorised data exposure before go-live
Brief users and support teams, with clear disclaimers on AI output
Confirm a rollback plan and monitor the feature after launch
Tracked as a governed change, not left as a technical footnote.
- The AI change checklist raised and tracked as an auditable change record
- Approvals from business, technical, and security owners captured against the change
- Actions arising from the review tracked through to verified closure
- The same governance principles the checklist requires — audit trail, permission alignment, data boundary controls — built into MAIA®, XGRC®'s own AI capability
Governance that keeps pace with AI adoption
XGRC® links the AI change checklist to your existing change, risk, and action management processes, so an AI feature is approved, tested, and monitored with the same rigour as any other high-risk change — and MAIA®, XGRC®'s own AI capability, is built around those same governed-AI principles.
The same AI rollout, without the blind spots.
AI Change Management Checklist
- Scope, ownership, and risk classification
- AI use case and business impact
- Data privacy and data flow
- Vendor and security review
- Testing and assurance
- Rollout, rollback, and monitoring
Govern AI change against the standards that are catching up to it.
- ISO 42001
- ISO 27001
- POPIA
- GDPR
- AI Governance
- Change Management
One process for every AI-related change.
- New AI features and tools
- Chatbots, copilots, and generative AI integrations
- Automated decision and recommendation systems
- Third-party AI vendor onboarding
Explore the connected platform.
MAIA®
Governed AI for GRC
Explore MAIA® → Use CaseRisk Management
XGRC® is risk management software that lets organisations identify, assess and manage risks in a structured, consistent way. It connects risks to controls, actions and assurance activities on a single platform, giving clear visibility of risk exposure across the organisation.
View use case → Use CaseVendor Management
XGRC® enables organisations to onboard, vet, and monitor suppliers and contractors through a structured process. Every vendor document, expiry date, and risk score is tracked in one place, so third-party compliance status is always known.
View use case → Use CaseInternal Controls
XGRC® is internal controls software that lets organisations design, implement, test, and assure controls in a structured way. Every control is linked to the risk it mitigates and the assurance provider testing it, so control effectiveness is demonstrable at any time.
View use case →Common questions.
What is an AI change management checklist?
An AI change management checklist is a structured set of questions used to assess a new AI feature or tool before it goes live, covering data privacy, security, testing, and rollback — questions a standard IT change request does not ask.
Why can't I just use my normal change management process for an AI feature?
A standard change process checks technical readiness but rarely asks what data an AI service processes, whether a vendor trains on it, or how the feature is disabled if it produces unreliable output — gaps this checklist is built to close.
Does this checklist apply to third-party AI tools as well as custom-built ones?
Yes. The same questions apply whether the AI capability is a vendor product, an embedded copilot, or a custom integration, because the data flow and accountability risks are the same regardless of who built the model.
How does XGRC® relate to AI governance?
XGRC® tracks the AI change checklist as an auditable change record with linked approvals and actions, and MAIA®, XGRC®'s own AI capability, is built around governed-AI principles including audit trails, permission alignment, and data boundary controls.
Bring AI change under the same governance as everything else.
Book a demo to see how XGRC® tracks AI-related change through classification, review, approval, and post-launch monitoring on one auditable platform.
Book a demoWhere should we send your download link?
Enter your details and we will email you the link to the checklist.
Your checklist is ready.
Click the button below to download the PDF. We have also sent this link to your email.
Download the checklist (PDF)