Most firms adopt AI in bids before writing a rule about it. This checklist gives you a one-page governance model you can adopt and enforce: approved tools, data zones, the human-verification requirement, roles, incident response and review. It is the practical companion to AI Proposal Governance.
A policy nobody can follow is worse than none. Name one approved tool, write down the rules, and make the right choice the easy one.
How to use this checklist
Work through it once to stand up the policy, then use the verification and data-handling items on every bid. The whole thing should fit on a page; if it grows longer, it will not be followed.
1. Name the approved tools
- [ ] One approved AI tool (or more, clearly listed) is named for proposal work.
- [ ] The approved tier is a business or enterprise tier with a no-training commitment.
- [ ] Consumer tiers are explicitly not approved for confidential or regulated data.
- [ ] The approved tool is as easy to use as any alternative.
2. Define the data zones
- [ ] Public – published content, public solicitation text, generic frameworks: usable within the approved tool.
- [ ] Internal – internal drafts, non-confidential context: approved tool only.
- [ ] Confidential – client names, pricing, technical detail, references: redact identifiers; approved tool only.
- [ ] Regulated – personal, financial, health or privileged data: prohibited without documented approval and controls.
3. Require human verification
- [ ] Every AI-assisted factual claim is traceable to a source.
- [ ] Drafting and checking are separated where stakes are high.
- [ ] Unverifiable claims are flagged, not softened.
- [ ] A named human approves the response before submission.
- [ ] A source log and sign-off are kept for high-stakes bids.
4. Set the rules for use
- [ ] Identifier handling is defined: what is redacted, and how.
- [ ] Client workspaces are separated, with no shared history between engagements.
- [ ] The retention window is understood, including abuse-monitoring logs.
- [ ] Staff know who to ask when unsure – one named owner.
5. Prepare the incident response
- [ ] Stop processing, preserve a record, and identify what was exposed.
- [ ] Follow the vendor’s deletion path.
- [ ] Notify the accountable owner and assess whether client notice is required.
- [ ] The checklist is written down and rehearsed once on a low-stakes document.
6. Assign roles and review
- [ ] A governance owner maintains the approved-tool list and the policy.
- [ ] A data owner decides tiers and identifier handling.
- [ ] A final approver is accountable per submission.
- [ ] The policy is reviewed at least twice a year, and after any incident.
Anchoring it to a framework
A recognized framework makes the policy defensible. The NIST AI Risk Management Framework provides a practical backbone:
| Function | What it covers in your policy |
|---|---|
| Govern | Policy, roles, accountability (this checklist) |
| Map | Which data and use cases are in scope |
| Measure | How you test and monitor quality and risk |
| Manage | How you respond when something goes wrong |
You do not need every subcategory. Using the four functions as headings makes the policy credible and easy to extend. For the source, see the NIST AI RMF (AI 100-1).
Frequently asked questions
What should an AI proposal governance policy cover?
Approved tools and tiers, data zones, how identifiers are handled, the human-verification requirement, who to ask, incident steps, and a review cadence. Half a page is enough for most firms.
Should we ban AI in proposals instead of governing it?
No. A ban moves use onto personal accounts where you have no visibility. A clear approved tool, simple data zones and verification get far higher compliance than a prohibition.
What framework should the policy follow?
The NIST AI Risk Management Framework – Govern, Map, Measure, Manage – is a practical backbone. Using the four functions as headings makes the policy credible and extensible.
Who owns AI governance for proposals?
A named governance owner who maintains the policy and the approved-tool list, supported by a data owner and a final approver. On a lean team one person may hold several roles, but the final approver stays distinct.
How often should the policy be reviewed?
At least twice a year, and after any incident or tool change. Tools, terms and regulations move faster than most documents.
Next step
Adopt the checklist as a one-page policy: name the tool, define the zones, require verification, prepare for incidents and assign owners. See AI Proposal Governance for the full method, AI and Confidential Client Data in Bids for the data-handling detail, and The Human-Verified Workflow for AI Proposals for how verification runs on a live bid.
References
- NIST, Artificial Intelligence Risk Management Framework (AI RMF 1.0) and AI RMF Playbook: Govern, Map, Measure, Manage.
- American Bar Association, Formal Opinion 512 (July 2024); ICMCI Code of Responsible Use of AI in Management Consulting (June 2026): confidentiality and conduct duties applied to AI use.
- Harmonic Security analysis (November 2025): sensitive data in 26.4% of file uploads to AI tools.
This checklist is not legal advice; confirm obligations with qualified counsel.