Practical AI and SaaS for Business

Shadow AI Audit Checklist for Australian SMBs: 10 Steps to Take This Quarter

Staff are using AI tools your business never approved. This 10-step shadow AI audit checklist helps Australian SMBs find every tool in use, assess the risks, and build a register they can act on.

Last verified: 18 July 2026. References checked against current legislation.

Editorial Perspective

You're a business owner who already knows shadow AI is a risk. You want the checklist, not the theory. Staff are already using AI tools you haven't reviewed, and every day that goes undocumented is a day you're carrying risk you can't see. This gives you ten concrete steps, a ready-to-use register template, and risk ratings, so you finish with every tool documented and a decision made. No IT background needed. Set aside an afternoon and start.

This article summarises publicly available guidance from regulators and official sources. It is general educational information only and does not constitute legal or professional advice. Requirements vary by jurisdiction. Consult your regional authority or a qualified professional for advice specific to your situation.

If your staff are using AI tools at work and you have no idea which ones, you are not unusual. Most Australian small businesses are in the same position. The problem is not that AI tools exist, it is that unmanaged AI use creates real risk: client data sent to overseas servers, outputs used without verification, tools that do not comply with your insurance or professional obligations.

This checklist walks you through 10 practical steps to audit what is actually happening in your business. By the end, you will have a shadow AI register, a clear picture of your risk exposure, and a short list of actions to take. No specialist IT knowledge required. See our full guide to shadow AI in Australian businesses for the broader context before you start.

In short: Shadow AI is any AI tool your staff use for work that the business has not reviewed or approved. This audit helps you find those tools, record them in a register, assess the risks under the Privacy Act 1988, and decide which to approve, restrict, or ban. Plan two to four hours to complete the full audit for a business of 5 to 30 people.

This article is general information, not legal advice. For advice on your specific Privacy Act obligations, consult a qualified privacy professional.

What Is Shadow AI and Why Does It Matter for Your Business

Shadow AI refers to AI tools that employees use in their work without the business formally reviewing or approving them. This includes free-tier tools like ChatGPT, Gemini, or Grammarly, as well as AI features built into software you already pay for, like Microsoft 365 Copilot or the AI assistant in your CRM.

The risk is not that staff are using AI. The risk is that without a record, you cannot assess whether client data is being sent to overseas servers, whether outputs are being used without human checks, or whether the tool's terms of service conflict with your professional or legal obligations. For businesses that handle personal information under the Privacy Act 1988, that gap is a compliance problem, not just an operational one.

A shadow AI audit closes that gap. It produces a register of every AI tool in use, with enough information to make a decision about each one.

Privacy Act 1988 note: If your business handles personal information about clients, customers, or employees, you have obligations under the Australian Privacy Principles (APPs). APP 8 applies when personal information is disclosed overseas, which happens automatically when staff use AI tools hosted on US or European servers. This audit helps you identify where that is occurring. See our guide on the Privacy Act ADM deadline for upcoming changes that affect how automated decisions using AI must be handled.

Before You Start: What You Will Need

This audit does not require technical tools or specialist knowledge. You need a way to take notes (a spreadsheet works well), 30 to 60 minutes for the discovery steps, and another 60 to 90 minutes to complete the register and risk assessment. For a business with more than 15 staff, allow more time for the interview step.

Useful to have on hand: your existing software subscriptions list, your IT spend summary for the last 12 months, and contact details for whoever manages your business software (an office manager, IT contractor, or department heads if relevant).

The 10-Step Shadow AI Audit

Step 1: List Every Software Tool Your Business Currently Uses

Start with a complete list of every software subscription and tool your business pays for or uses through a free plan. Pull from your credit card or bank statements for the past 12 months, your email inbox for subscription receipts, and any IT or software tracking your business already maintains.

Do not try to identify AI tools yet. Just build the complete list. Include tools that individual staff members have signed up for themselves, even if the business does not pay for them directly. The goal is to know everything that is in use before you assess any of it.

Output: A master software list. This becomes the foundation for your shadow AI register.

Step 2: Flag Everything That Has an AI Feature or Component

Go through your master software list and mark any tool that includes AI features, even if AI is not the primary function. This includes tools where AI is a headline feature (ChatGPT, Jasper, Otter.ai), tools where AI is a built-in option (Microsoft 365 Copilot, Google Workspace AI features, Xero's document capture), and tools where AI may be active in the background (some email clients, CRM platforms, and customer service tools use AI for sorting or suggestions).

If you are not sure whether a tool has AI features, check the vendor's feature page or search the tool name plus "AI features" to confirm. When in doubt, include it and assess it later rather than leaving it out.

Output: A filtered list of AI-capable tools from your master software list.

Step 3: Ask Staff What AI Tools They Are Actually Using

This is the step most businesses skip, and it is the most important one. Staff surveys and short interviews consistently reveal AI tool usage that does not appear in any subscription records. This happens because many AI tools have a free tier, because staff sign up with personal email addresses, or because AI features inside existing tools are not thought of as a separate tool at all.

Send a short anonymous survey or hold brief 10-minute conversations with each team or department. Ask: What tools do you use to draft emails, documents, or social media posts? Do you use any AI tools to summarise, transcribe, or research? Have you used ChatGPT, Gemini, Copilot, or similar tools for any work task in the last three months? Keep the tone neutral. The goal is discovery, not audit-for-punishment.

Output: A list of staff-identified AI tools to add to your register. Expect to find tools that did not appear in step one.

Step 4: Check Browser Extensions and Mobile Apps

AI tools are often installed as browser extensions or mobile apps rather than full software subscriptions. Grammarly, Compose AI, Monica, and similar tools operate as extensions that may access content across every browser tab. Some email apps include AI writing assistants that activate automatically.

Ask staff to check their browser extensions list (in Chrome: Settings, Extensions; in Edge: Settings, Extensions) and list any they use for work. Do the same for any work-related mobile apps that may include AI features. Add any new findings to your growing list.

Output: Additional AI tools from browser extensions and mobile apps, added to the register.

Step 5: Record Each Tool in Your Shadow AI Register

Now consolidate everything into a formal register. The register is a simple table, one row per tool, with the information you need to make a decision about each one. The template below is a ready-to-use starting point.

For each tool, record: the tool name, which staff or teams use it, what they use it for, whether the business pays for it or it is a free personal account, and where the vendor is based (which indicates where data is likely to be processed and stored). You will complete the risk rating column in step 6.

Output: A completed shadow AI register. This is the primary deliverable of the audit.

AI Tools Register Template (copy and adapt)

Tool Name Used By Purpose Data Entered Vendor Country Paid / Free Risk Rating Decision
ChatGPT (free) Admin team Draft emails, summarise docs Client names, job details USA Free (personal) High Review
Grammarly All staff Spelling and grammar checks All text typed in browser USA Free (personal) Medium Policy needed
Otter.ai Sales team Meeting transcription Client conversations USA Free (personal) High Review
[Your tool] [Who uses it] [What for] [Data types] [Country] [Paid/Free] [H/M/L] [Approve/Review/Ban]

Copy this table into a spreadsheet. Add one row per tool. Complete the Risk Rating column in Step 6.

Step 6: Rate the Risk Level of Each Tool

For each tool in your register, assign a risk rating of High, Medium, or Low. Use these three questions to guide the rating.

First: what data does this tool receive? A tool that only sees anonymised or non-sensitive content (draft blog post ideas, internal process notes) is lower risk than a tool that receives client names, financial details, health information, or other personal information. Second: where is the data processed? Tools hosted on US or European servers trigger APP 8 cross-border disclosure obligations under the Privacy Act 1988. Third: is the tool used under a paid business account with a data processing agreement, or is it a free personal account with terms that allow training on user data?

Rate a tool High if it receives personal information about clients or employees and operates under a free-tier account with no data processing agreement. Rate it Medium if it receives business information but not personal information about clients. Rate it Low if it only receives generic, non-sensitive content and you have reviewed the vendor's privacy terms.

Output: Risk ratings added to every row of your shadow AI register.

Step 7: Check Where Each Tool Stores and Processes Data

For every tool rated High or Medium, confirm where the vendor processes and stores data. This information is usually in the vendor's privacy policy or data processing terms. Look for the section on data storage locations or international data transfers.

Key things to record: whether data is stored in Australia, the US, the EU, or elsewhere; whether the vendor's terms allow data to be used for AI model training; and whether a business or enterprise plan is available that provides a data processing agreement and opts out of training data use. For some tools, upgrading from a free plan to a paid business plan substantially changes your privacy risk profile. Note this in the Decision column of your register.

Output: Data location confirmed for all High and Medium risk tools, with upgrade options noted where relevant.

Step 8: Assign a Decision to Each Tool

Now make a decision for each tool in your register. There are four options: Approve (tool is safe to use as-is), Approve with Conditions (tool is acceptable under specific rules, such as no client data to be entered), Upgrade Required (tool needs a paid business account before use is approved), or Ban (tool presents unacceptable risk and staff should stop using it).

For tools you are approving or approving with conditions, you will need to communicate the rules clearly to staff. This leads directly to your AI use policy. If your business does not yet have an AI use policy, the free AI staff policy template for Australia gives you a ready-to-customise starting point. The AI policy checklist for Australian businesses covers what a complete policy should include.

Output: Decision column completed for every tool in the register.

Step 9: Communicate the Decisions to Staff

A shadow AI register with no communication achieves nothing. Staff need to know which tools are approved, which are banned, and what the rules are for any conditional approvals. This does not need to be a formal training session. For a 15-person business, a brief all-staff email summarising the decisions, plus a one-page summary of the rules for approved tools, is usually sufficient to start.

Include three things in your communication: the list of approved tools and any conditions attached, the list of banned tools and a brief explanation of why (referencing client data or privacy risk is usually enough), and who to contact if staff want to use a new AI tool in future. That last point is important: you want staff to ask before adopting, not after.

Output: Staff communication sent, with approved tool list and policy summary attached.

Step 10: Schedule a Quarterly Review

AI tools change quickly. New tools appear, existing tools add AI features, and staff find new ways to use tools you have already approved. A shadow AI register that is reviewed once and never updated will be out of date within six months.

Put a calendar reminder in now for 90 days from today. The quarterly review is shorter than the initial audit: ask staff if they have started using any new AI tools, check whether any approved tools have changed their terms or added new AI features, and update the register accordingly. If you are in a regulated industry (accounting, legal, healthcare, financial advice), consider reviewing more frequently and noting the review date in your register as a record of due diligence.

Output: Quarterly review scheduled and a repeating process established to keep the register current.

Australian Privacy Act Obligations: What This Audit Covers

If your business has an annual turnover of $3 million or more, or handles health information, tax file numbers, or certain other categories of data, the Privacy Act 1988 applies to you directly. If your turnover is below that threshold, the Privacy Act may still apply depending on your industry or the type of data you handle, and many businesses below the threshold voluntarily follow the Australian Privacy Principles as a standard of care.

The two most relevant principles for shadow AI are APP 1 (which, under OAIC guidance, requires a clear privacy policy and privacy management practices) and APP 8 (which requires taking reasonable steps to ensure overseas recipients provide equivalent protections. See the OAIC's APP 8 guidance at oaic.gov.au). Every AI tool hosted overseas that receives personal information about your clients or staff is a potential APP 8 situation. The shadow AI register you create in this audit is the evidence that your business has identified and assessed that risk.

The Office of the Australian Information Commissioner (OAIC) has published guidance on AI and privacy. The OAIC position is that privacy obligations apply to the use of AI tools, not just to whether you built the AI yourself. See also the upcoming changes to the Privacy Act, including new automated decision-making transparency obligations, covered in our guide to the Privacy Act ADM deadline.

Industries With Additional Obligations

Some industries carry obligations beyond the Privacy Act that affect how AI tools may be used. Accounting and bookkeeping practices should check whether AI tool use is consistent with Tax Practitioners Board guidelines and professional indemnity insurance requirements. Legal practices must consider legal professional privilege and Law Society guidance, which in several states is now specific about AI use with client files. Healthcare and allied health providers are subject to the Australian Privacy Act's health information provisions, which are stricter than general personal information rules.

Financial services businesses regulated by ASIC and APRA face additional governance requirements. If you are in any of these industries, add a column to your shadow AI register for industry-specific obligations and check each approved tool against them before communicating decisions to staff.

Methodology (Real-World, Verified)

This guide is researched against primary regulatory sources and official regulator guidance, verified as of the date shown, and written for a business with no dedicated compliance function.

Related reading: our can staff upload customer data to AI tools and our AI and the Privacy Act guide.

Related reading: our Claude AI review for Australian business.

Try our free AI Tool Pricing Tracker to check current AUD pricing across the major AI platforms.

Try our free AI Privacy Risk Scorer to score your current AI tool setup against Privacy Act requirements.

Try our free AI Compliance Checker to check whether your AI tools meet your compliance obligations.

Related reading: our free AI acceptable use policy template and our AI governance by region.

What is shadow AI and does my small business actually need to worry about it?

Shadow AI is any AI tool your staff use for work that your business has not reviewed or approved. Yes, it matters for small businesses: the risk is not the tool itself, it is the data that passes through it. If a staff member pastes client information into a free ChatGPT account, that data is likely sent to US servers and may be used for model training under the free-tier terms. For businesses subject to the Privacy Act 1988, that is a potential breach of the Australian Privacy Principles regardless of business size.

How long does a shadow AI audit take for a small business?

For a business of 5 to 20 people, allow two to four hours for the initial audit: around 30 to 60 minutes to gather your software list and complete staff interviews, and another 60 to 90 minutes to build and assess the register. Quarterly reviews after the first audit typically take 30 to 60 minutes. The steps above are written to be completed by a business owner or office manager without specialist IT support.

Can staff keep using tools like ChatGPT or Grammarly after the audit?

Possibly, but the answer depends on what data they are entering and what account type is in use. Free-tier ChatGPT accounts have terms that allow OpenAI to use conversations for model training by default. If staff are entering client information, that is a Privacy Act risk. A ChatGPT Team or Enterprise account includes a data processing agreement and opts out of training data use. Grammarly's business plans also include stronger data terms than the free version. The audit helps you make this distinction per tool and per use case, rather than a blanket ban or blanket approval.

What should go into an AI policy after the audit is done?

At minimum, your AI policy should list approved tools, any conditions on their use (such as no client data to be entered without a business account), and a process for staff to request approval of new tools. It should also name who is responsible for maintaining the register and when it will be reviewed. The free AI staff policy template for Australia gives you a ready-to-use starting structure, and the AI policy checklist covers everything a complete policy should include.

Does the Privacy Act apply to my business if I have fewer than 3 million dollars in revenue?

The general threshold for the Privacy Act 1988 is annual turnover above $3 million, but there are exceptions that bring smaller businesses within its scope. If your business handles health information, provides services to the Commonwealth, or is in an industry with specific obligations, you may be covered regardless of revenue. Even if your business is technically exempt, following the Australian Privacy Principles is the practical standard that most professional indemnity insurers and larger clients now expect. The OAIC website has a tool to check whether your business is covered.

What is the difference between a shadow AI audit and an AI policy?

The audit is the discovery process: finding what tools are in use, assessing the risks, and deciding what to do about each one. The policy is what comes out of those decisions: the rules your staff need to follow going forward. You need the audit first, because a policy written without knowing what tools are in use will miss the actual risk. Once the audit is done, the register and decisions form the basis of your policy. Think of them as the same process in two stages: find out what is happening, then formalise what should happen.

Find official guidance for your region

Requirements vary by jurisdiction. This article provides general information only. Consult your regional authority or a qualified professional for advice specific to your situation.

The information in this article is general in nature. It reflects a summary of publicly available guidance and does not constitute legal, privacy, or professional advice. Your obligations will depend on your specific situation, jurisdiction, and business circumstances. Do not rely on this article as a substitute for qualified legal or professional advice.

Once your shadow AI register is complete, the next step is formalising your decisions into a policy your staff can follow. Download the free AI staff policy template for Australian businesses to get a ready-to-customise starting point.

Get the Free AI Policy Template