Confirm systems and users in scope
List AI tools, Microsoft 365 workloads, connected agents, business systems, user groups, and departments included in the review.
This retained guide now supports public evidence collection, PSF scoring, and readiness readouts for AI systems and workflows.
The first step is to define what will be inspected, who can speak for it, and what evidence is needed. This is a facilitation resource, not a commercial assessment offer.
List AI tools, Microsoft 365 workloads, connected agents, business systems, user groups, and departments included in the review.
Name the business owner, technical owner, data owner, and person responsible for public disclosure or procurement answers.
Ask for exports, reports, policies, logs, screenshots, or reader access needed to support the review without changing production systems.
Ask which products, assistants, agents, automations, or external tools are active, and who depends on them.
Ask for data classes, sensitivity labels, customer data exposure, retention rules, and vendor processing records.
Ask who reviews outputs, what actions require approval, what logs exist, and how incidents are escalated.
Clarify business purpose, risk appetite, public claims, customer impact, and decisions that need evidence.
Validate deployment architecture, access, logging, data governance, security controls, and known gaps.
Map day-to-day process reality, exceptions, handoffs, manual reviews, and where AI could change accountability.
Check policy obligations, disclosure expectations, vendor risk, privacy constraints, and audit requirements.
Find shadow AI use, practical failure modes, confusing outputs, and training or escalation gaps.
Confirm how the organisation would answer a buyer, regulator, journalist, or customer asking how AI is used.
Use the Production Safety Framework as a scoring lens. A policy in draft, a planned control, or an informal habit should not be treated as deployed evidence.
Separate verified facts, partial evidence, open questions, and unsupported claims in the executive summary.
Every finding should identify the source, the PSF domain, the owner, the risk, and the evidence needed to close the gap.
Recommend the next documents, controls, reviews, disclosures, or deployment records needed before claims expand.
Use the guide to produce a record that can be checked, challenged, and linked to public disclosure, readiness, or deployment pages.