Your audit committee wants to know which AI tools staff are using. The answer is in the logs your network already writes. One export produces a complete inventory with risk flags, training verdicts and a PDF evidence pack that drops straight into the workpaper file.
Whether you work to IIA standards, SOC 2 trust criteria or your own risk universe, unapproved AI tools now sit across every category: data handling, change management, vendor risk and access control. The finding is the same everywhere: staff are using tools nobody approved.
Marketing pastes customer lists into an AI writing tool. Finance uploads a spreadsheet to a forecasting model. Legal runs contracts through a summariser. Every paste is a potential data breach that auditors are expected to flag.
GDPR Article 30 requires a record of processing activities. The EU AI Act mandates an inventory of AI systems. HIPAA demands access logs. If a tool is invisible, none of these obligations can be met.
SEC, FINRA, the OCC and the FCA all expect firms to know what AI they use. The question is no longer "do you have a policy?" but "show me the inventory." A finding without evidence is an observation. A finding with a full tool list and risk flags is defensible.
Most organisations discover 3 to 5 times more AI tools than they expected. The gap between "what we approved" and "what the network sees" is where audit findings live. See the latest shadow AI statistics.
Upload a DNS, proxy or firewall export. Minutes later you have a complete AI tool inventory, risk-scored, with evidence ready for the file.
Every AI tool your network reached: name, category, type, vendor, risk rating. Matched against our register of 20,399+ AI-tool domains.
13 risk factors per tool: data sovereignty, training-on-user-data default, opt-out availability, abusive-purpose flags, enterprise tier, API access. Red, amber, green at a glance.
Which users, devices or IPs reached each tool, and which tools each user reached. Cross-reference with your HR system for department-level findings.
A formatted PDF you can attach directly to the workpaper file. Plus a CSV export for your own analysis, pivot tables or GRC import.
The same AI tool inventory addresses controls across multiple frameworks. One audit, multiple findings.
| Framework / Standard | Relevant Control | Shadow AI Finding | Evidence From Report |
|---|---|---|---|
| IIA IPPF | Standard 2120 - Risk Management | Unapproved AI tools create unmanaged information risk | Tool inventory with risk flags and hit counts |
| SOC 2 (TSC) | CC6.1 - Logical access controls | AI SaaS tools accessed without provisioning | Per-user tool access list, sanctioned vs unsanctioned |
| ISO 27001:2022 | A.5.9 - Inventory of information assets | AI tools not in asset register | Complete tool list with categories and risk ratings |
| GDPR | Art. 30 - Records of processing | AI tools processing personal data not in ROPA | Tools with data-sovereignty and training flags |
| EU AI Act | Art. 4 - AI literacy / Art. 6 - Risk classification | AI systems used without classification or training | Full inventory with vendor details and risk factors |
| NIST CSF 2.0 | GV.OC - Organisational context | AI tools outside governance scope | Department-level tool usage with user mapping |
| COSO ERM | Principle 10 - Information & technology | Shadow AI as unidentified emerging risk | Tool count, category breakdown, trend data |
| HIPAA | ยง164.312(b) - Audit controls | PHI potentially processed by unapproved AI | Healthcare-flagged tools with user access list |
Need the ISO 27001 evidence pack specifically? See our ISO 27001 shadow AI evidence guide. For GDPR-focused findings, see GDPR and shadow AI.
A 2,200-employee manufacturer includes AI governance in the ITGC scope for the first time. The audit committee asked a single question: "What AI tools are our people using?"
IT exported 14 days of DNS query logs from their Cisco Umbrella instance. The file was 1.2 million lines covering all internal users. Export took five minutes from the Umbrella console.
The auditor uploaded the export to the Shadow AI Audit tool. Processing took three minutes. No software to install, no agents, no network changes.
The report identified 47 distinct AI tools. 39 were not on the approved software list. 11 had default training-on-user-data enabled. 4 were flagged for data sovereignty (servers outside permitted jurisdictions).
The auditor attached the PDF evidence pack to the workpaper and wrote a single finding: "AI tool inventory incomplete. 39 unapproved tools identified through network analysis." Rating: Medium. Management accepted and committed to a 90-day remediation plan.
| Tool | Category | Risk | Hits |
|---|---|---|---|
| ChatGPT | LLM Chat | High | |
| Grammarly | Writing | Med | |
| Midjourney | Image Gen | High | |
| Claude | LLM Chat | Med | |
| Notion AI | Productivity | Med | |
| Otter.ai | Transcription | High | |
| Perplexity | Search | Low | |
| Runway | Video Gen | High |
Want to see the full output? View the sample report or run a free preview on your own logs.
Shadow AI is not a one-time project. Build it into the annual audit plan and it becomes a repeatable test with declining effort and increasing value.
Run the first audit to establish the AI tool inventory. Document the total count, unsanctioned percentage and highest-risk tools. This becomes the benchmark for all future audits.
After management deploys an AI acceptable-use policy, run the second audit. Compare against Q1: did the number of unsanctioned tools decrease? Are the high-risk tools still active?
If the organisation deployed blocking rules, test effectiveness. Upload a fresh export and confirm that blocked tools no longer appear. Any residual traffic becomes an exception finding.
Compile the four quarters into a trend report for the audit committee. Show the starting count, the effect of policy and controls, and any persistent gaps. Recommend the same cycle for next year.
Running quarterly audits? The 5-report pack at $299 covers a full year of quarterly audits plus a spare. See pricing.
A complete AI controls workpaper needs more than just the tool list. Here is everything the report provides and what to add from your own records.
Based on our data across hundreds of audits, these are the findings that recur in nearly every engagement.
The most common finding. The organisation has no record of which AI tools staff use. The report produces the first complete inventory. This is a control gap under ISO 27001 A.5.9, SOC 2 CC6.1 and IIA Standard 2120.
Multiple tools used by staff train on input data by default. Staff are unknowingly contributing company data to model training. Vendor terms confirm it. The report flags which tools and which tier (free vs enterprise) avoids it.
Each AI tool is a vendor relationship. If 40 tools are found and 35 are not in the vendor register, that is 35 unmanaged vendor relationships. Procurement and legal have no visibility into the terms governing data use.
The organisation either has no AI policy or the policy exists but lacks enforcement. The audit report quantifies the gap: 47 tools found, zero blocked. Policy without enforcement is a control deficiency.
Tools headquartered or hosted outside permitted jurisdictions process company data. The data sovereignty flags in the report identify exactly which tools and which jurisdictions are involved.
A small number of users account for the majority of AI tool usage. These power users may be handling sensitive data. The per-user breakdown identifies who they are and what they are using.
The audit finding is step one. Remediation means policy, enforcement and ongoing monitoring. We provide defaults for all three.
We have prepared default allow/block rules across 20,399+ AI tools. Instead of writing a policy from scratch, start with optimised defaults and adjust for your risk appetite. Set allow, block and monitor rules in minutes.
Build the shadow AI audit into the quarterly ITGC cycle. Each re-test takes minutes and produces comparable evidence. Track the sanctioned percentage over time and report progress to the audit committee.
After IT implements blocking rules, run the audit again to verify effectiveness. Any tool that was blocked but still appears in the logs indicates a control failure. The before/after comparison is the evidence.
Each audit produces comparable data. Over four quarters, you can show the audit committee whether the AI risk posture is improving, stable or deteriorating. This is the evidence that controls are working.
For a full remediation playbook, see Shadow AI Remediation Playbook. For policy enforcement options, see AI Policy Enforcement.
You do not need a new tool. The logs your organisation already writes contain the evidence. Here is what to request from IT and how to frame the ask.
Cisco Umbrella, Cloudflare Gateway, NextDNS, Pi-hole, DNSFilter. Every domain query your network made. The richest source for AI tool detection.
Zscaler, Squid, Blue Coat. Full URL-level visibility including HTTPS domains. Export the access log for the audit period.
Palo Alto, Fortinet, SonicWall. Application-aware firewalls log resolved domains per session. Export the traffic log for the audit window.
Sample request email for IT: "Please export DNS query logs for all internal users for the past 14 days in CSV format. We need the timestamp, source IP or username, and queried domain columns. This is for the Q3 ITGC audit scope."
One full shadow AI audit report: every tool, per-user breakdown, risk flags, training verdicts, PDF evidence pack and CSV export.
$99
Five reports for quarterly audits plus a spare. Credits never expire. Covers a full annual audit cycle with one purchase.
$299 ($60/report)
For audit teams running audits across multiple entities or clients. Plans from $99/mo include audit allowances and priority processing.
From $99/mo
Not sure yet? Run a free preview first. The preview shows totals by category and a sample of the tools found. No credit card needed.
Step-by-step guide to building a complete AI tool inventory from the logs your network already writes.
How to assemble the evidence auditors and regulators expect for AI governance.
Shadow AI from the compliance perspective: GDPR, EU AI Act, ISO 27001 and more.
How to set up a recurring audit cadence that tracks AI risk posture over time.
No. You need a DNS, proxy or firewall log export in CSV or similar format. No agents, no software, no network changes. IT exports the file and you upload it to the audit tool.
The scan runs in minutes. A 1-million-line export typically processes in under three minutes. The longest part is usually waiting for IT to provide the export.
No. The log export is read once during processing and discarded. Only the resulting report is stored in your account. Reports are kept for 90 days and can be downloaded as PDF or CSV at any time.
Yes. The PDF evidence pack is designed to be shared. Attach it to the workpaper, include it in the management letter or send it directly to the audit committee. The CSV is useful for management's own analysis.
Our register covers 20,399+ AI-tool domains across all categories: LLMs, code assistants, image generators, transcription, translation, writing tools and more. The register is updated continuously.
Run a separate audit for each provider's export, or combine the exports into a single file before uploading. Each audit accepts up to 2,000,000 lines and 25 MB.
Yes. Every account gets a free preview: totals by category and a sample of the tools found. The preview is limited but gives you confidence the tool works with your export format.
Yes. The report maps directly to SOC 2 trust criteria CC6.1 (logical access) and CC7.1 (monitoring). The per-user breakdown and risk flags are the evidence the auditor needs. See our SOC 2 AI inventory guide.
One log export. One scan. A complete AI tool inventory with risk flags, training verdicts and a PDF evidence pack ready for the workpaper file.