A checklist for organizations using AI to help produce reports – to draft narrative, summarize data or assemble sections – covering the controls that keep AI-assisted reporting accurate, confidential and defensible. It is the practical companion to Report Governance for AI: A Policy You Can Adopt.
The position this checklist takes is simple: AI may assist report production, but a named human is accountable for every figure, every claim and every decision the report supports.
If no one can name the person accountable for the AI-assisted content, the control does not exist.
The checklist
Accountability
- Is there a named human accountable for each AI-assisted report?
- Is the approval gate human, with the approver recorded?
- Is the responsibility for figures and claims explicitly assigned?
- Is AI assistance disclosed where the audience or a rule requires it?
Verification
- Is every figure verified against source, not against the model’s output?
- Are every factual claim and quotation verified?
- Are references and citations checked for existence and accuracy?
- Is there a second-person review before issue?
Inputs and confidentiality
- Is there a policy on what data may be entered into an AI tool?
- Is confidential or personal data excluded from prompts where required?
- Are permitted tools specified, rather than left to individual choice?
- Is training and retention behavior of the chosen tools understood and accepted?
Accuracy and hallucination
- Are outputs treated as drafts, never as verified content?
- Are numbers ever generated by the model rather than retrieved?
- Are summaries checked against the source they summarize?
- Are unsupported assertions removed, not softened?
Records
- Is the AI tool and version recorded for each assisted report?
- Is the prompt or method recorded where it affects reproducibility?
- Is the human review recorded, with the reviewer’s name and date?
- Is the retention of AI-assisted drafts aligned to policy?
Why the verification gates exist
The evidence behind these controls is the error rate. Reported hallucination rates in large language models vary widely – roughly 22% to 94% depending on the task and the measurement method, with one benchmark finding 13.6% of responses grounded (Stanford HAI, AI Index 2026, with Vectara’s leaderboard and OpenAI model documentation). The honest reading is that no model output can be treated as verified without a human check.
Confidentiality is the second risk. A 2025 Harmonic Security study found 26.4% of employees have pasted confidential company data into a generative AI tool. For reporting, that means a report produced with AI may carry sensitive figures into a third-party service unless the inputs are governed.
The external reference points for a policy are the NIST AI Risk Management Framework, ABA Formal Opinion 512 on lawyers’ use of generative AI, and the ICMCI Code of Ethical Conduct for consultants. See Confidential Data in Report Production and Hallucination Risk in Reports.
How to adopt it
- Start with accountability. One named human per report, an approval gate, and disclosure where required.
- Make verification a step, not an intention – with a second person where the stakes are high.
- Set an input policy before broadening access to tools.
- Record tool, version and method, so an assisted report is reproducible.
- Review the controls quarterly, and after any incident.
This is a short policy. Its value comes from being applied, which is why it should be readable in one sitting.
Frequently asked questions
Can AI be used to write reports?
Yes, for drafting narrative and assembling structure – provided every figure and claim is verified by a named human and the approval gate is human. AI-assisted output is a draft, never a verified report.
Should AI use be disclosed?
Where the audience or an applicable rule requires it, yes. In regulated or professional contexts, confirm the disclosure expectations before adopting AI in the workflow.
What data should never be entered into an AI tool?
Anything the applicable policy, regulation or contract treats as confidential or personal, unless the tool and the configuration have been approved for that data.
How do you verify AI-assisted content?
Check every figure against source, every claim and quotation against evidence, and every reference for existence and accuracy, then have a second person review before issue.
How accurate is AI at producing report content?
Reported hallucination rates vary widely – roughly 22% to 94% depending on task and measurement – so accuracy cannot be assumed and verification cannot be optional.
Who owns the AI governance policy?
The reporting owner or a designated governance lead, with the approval of the accountable executive. It should be reviewed at least quarterly.
Next step
Adopt the checklist, name the accountable human for each AI-assisted report, and make verification a step in the workflow rather than a hope. See The Human-Verified Reporting Workflow, or book a pilot call to build the workflow with you.
Sources
- Stanford HAI, AI Index 2026, with Vectara’s hallucination leaderboard and OpenAI model documentation (2025-2026): hallucination rates reported between roughly 22% and 94%, with one benchmark at 13.6% grounded responses.
- Harmonic Security (2025): 26.4% of employees have pasted confidential data into a generative AI tool.
- NIST AI Risk Management Framework; ABA Formal Opinion 512; ICMCI Code of Ethical Conduct – reference frameworks for AI governance.
Figures are cited from their sources and dated. This asset is general information, not legal advice; confirm obligations in your sector with qualified advisors.