AI Audit Checklist: What to Prepare and What You Get

What to gather before an AI audit, in 4 groups that take about half a day to collect, what each pass of the audit actually examines, and a real redacted report from our free tool showing the readiness score, the first actions, how every finding is rated, and the section where the audit says what it could not determine.

Cover reading The AI audit checklist and a real report, beside a redacted audit panel scoring 75 out of 100 with findings for lead intake marked partial and appointment scheduling marked full, rated for complexity and confidence, ending with what the audit could not determine
On this page

An AI audit checklist is what you gather before the audit: a list of every task done more than 5 times a week with minutes and frequency against each, every tool the business pays for, your inbound volume and loaded hourly cost, and one person per process who actually does the work. About half a day to collect, and it decides the quality of everything that follows.

This also covers the half nobody publishes: what the resulting report actually looks like. There are 2 real ones further down, from DrioGrowth and Zapture Media, published with their permission, including the ratings and the section where the audit admits what it could not work out.

On this page

  1. What is an AI audit checklist?
  2. What should you prepare before an AI audit?
  3. What does the audit actually examine?
  4. What does the report look like?
  5. How are findings scored?
  6. What happens after the audit?
  7. How long, who is involved, what it costs
  8. How these figures were arrived at
  9. Frequently asked questions

What is an AI audit checklist?

It is the preparation list for an audit that finds where AI and automation should go in your business. Not the compliance kind. If you are looking for controls against ISO/IEC 42001, the NIST AI Risk Management Framework or the EU AI Act, that is a governance audit, which IBM describes as an examination of how AI systems are designed, trained and deployed, and it needs a different checklist entirely. Our guide to an AI audit for business covers the distinction.

This checklist is for the other kind: the one that looks at how your work runs and tells you which parts of it a machine could take over.

What should you prepare before an AI audit?

A 4 group preparation checklist for an AI audit covering your processes, your systems, your numbers and your people, with tick boxes, why each item matters and how long each group takes to collect
The checklist itself. Half a day to gather, and it decides the quality of everything after.

Group 3 is where most of the value sits and where most businesses arrive empty handed. An audit without your real numbers can tell you what is automatable. It cannot tell you what it is worth, and a finding without a number attached is very hard to get approved.

A free automated audit needs none of this, because it works from your public footprint and infers the rest. That is the trade: no preparation, lower certainty.

What does the audit actually examine?

Most pages on this topic list 6 bare labels and move on. Here is what each pass actually involves.

  • The customer journey, walked as a customer. How somebody finds you, whether they can book online or must call, what happens after a form submission, how long before a human appears. An automated audit does this literally, by navigating the site the way a buyer would.
  • The work behind each enquiry. Every step between a request arriving and the job being done, with particular attention to the handoffs where information gets retyped from one system into another.
  • Recurring internal work. Reporting, reconciliation, scheduling, chasing. The tasks that repeat on a cycle rather than in response to a customer.
  • Where unstructured input enters. Emails, phone calls, photographed documents, free text fields. These are the steps that used to block whole workflows and are now the ones a model can take.
  • What already exists. The tools, the integrations between them and the gaps those leave. Existing API access often moves a finding from high complexity to low.
  • Where attention goes. Which tasks consume the time of the people whose judgment the business depends on, which is usually different from which tasks take the most hours.

What does the report look like?

A real redacted Codeatic AI audit report showing a 75 out of 100 automation readiness score, 4 first actions, one finding in full with ratings for automatable, complexity, priority and confidence, and the sections listing what the audit assumed and what it could not determine
A real report with the business redacted. Nobody else in these results publishes their deliverable.

The structure is deliberate. A readiness score so you know where you stand. A short list of first actions so there is something to do on Monday. Then every finding with the same anatomy: what happens today, what could take it over, 4 ratings, and the evidence behind the claim.

Then the 2 sections most reports leave out: what the audit assumed, and what it could not determine. Those are not weaknesses. They are the precise list of questions a 30 minute conversation should answer, which turns a free report into a short specific call rather than a generic one.

How are findings scored?

4 dimensions, read together rather than one at a time.

  • Automatable: partial or full. Partial means part of the task can run by itself and part needs a person. It is the honest answer far more often than full.
  • Complexity: low, medium or high. Mostly a function of how many systems are involved and whether they have usable APIs, not how clever the automation is.
  • Priority: how much it matters to this business. Not how impressive the automation would be.
  • Confidence: how sure the audit is. An audit working from public information cannot be certain about internal processes, and saying so per finding is what separates a report from a pitch.

The combination to build first is high priority, low complexity, high confidence. Across the DrioGrowth and Zapture Media reports, 7 of 14 findings landed in that shape, which is a typical hit rate and more than enough for a first project.

From our work. We tallied 2 recent free audit reports for this post, from 2 paid media agencies, DrioGrowth and Zapture Media, both of whom agreed to be named. 13 of the 14 findings were marked partial rather than fully automatable, and only 1 was full. 4 of 14 carried low confidence. That distribution is the thing worth noticing: an honest reading of a business from the outside produces a lot of partials and some open questions, because most work has a judgment step somewhere inside it.

Where the paid version goes further is the numbers. At Ziltrix, a security workforce platform, the audit identified roughly 40% to 50% of the operation as automatable, and the first build took shift confirmation calls from 8 staff to 1, recovered $42,000 a year in salary and went live in 4 weeks. At Ph3onix, a full working day every week spent counting shelf stock became minutes, worth about $68,000 a year. Neither of those figures could have come from a website, which is the whole argument for doing the preparation in the checklist above.

What happens after the audit?

  1. Sort by the 3 way combination, not by excitement. High priority, low complexity, high confidence goes first.
  2. Take the low confidence findings to a conversation. The could not determine section is your agenda.
  3. Record the before number for whatever you build. If you skipped group 3 of the checklist, do it now.
  4. Build the narrowest version. One slice of one finding, not the whole thing.
  5. Run it beside the manual process for 2 weeks before you remove the manual process.
  6. Only then look at the second finding. Most failed programmes started 3 things at once.

The evidence for working this narrowly is not subtle. MIT's Project NANDA reported in July 2025 that 95% of enterprise generative AI pilots delivered no measurable impact on profit and loss, and Gartner predicted in June 2025 that more than 40% of agentic AI projects will be canceled by the end of 2027, citing unclear business value. A narrow first build with a recorded before number is the direct answer to both.

How long, who is involved, what it costs

The free automated audit takes a couple of minutes, needs nothing from you but a business name and location, and reads your public footprint. Use it to decide whether a paid audit is justified.

The paid audit starts with a free 30 minute discovery call with the owner, runs 7 to 10 days, and is a fixed $3,000. It needs the checklist above plus roughly an hour each from the people who actually do the processes in scope.

Builds that follow run 4 to 8 weeks for a narrowly scoped first project, and you own 100% of the code. Comparisons of readiness tooling make the same point we would: some produce a maturity score, some a benchmark, and the best produce a prioritized action plan. A score with no action list is half a deliverable.

Where Codeatic fits in

Start with the free AI audit. It costs nothing, needs no preparation, and the report is the one shown above. If it raises questions, get in touch and we will work through the could not determine section with you. When you want the numbers, the AI Opportunity Audit is where the checklist earns its keep.

For more context, what a free AI audit can and cannot tell you covers how to read the output and what 4 real audits found covers the outcomes.

When not to bother with any of this

When you already know the exact task you want automated and why, in which case you need a build estimate rather than an audit. When the business is small enough that you can list every recurring task from memory in 10 minutes, since you have just done the audit yourself. And when nothing on your list runs more than a few times a month, because the payback will not arrive.

The short version

The AI audit checklist is 4 groups: your processes with minutes and frequency, your systems and who holds the logins, your numbers including loaded hourly cost and inbound volume, and one person per process plus a decision maker. Half a day to gather. The report you get back scores readiness, lists first actions, and rates every finding on automatable, complexity, priority and confidence, with the evidence and an explicit list of what it could not determine. Build the high priority, low complexity, high confidence finding first, and record the before number so you can prove it worked.

How these figures were arrived at

The checklist describes what we ask for in a Codeatic AI Opportunity Audit and is not a published standard. The reports in the second figure are genuine output from our free AI audit tool, published with written permission from DrioGrowth and Zapture Media; both audits were run from public information only, with no data supplied by either company, which is why the confidence ratings and the could not determine sections exist. The distribution across those 2 reports, 13 of 14 findings partial and 4 of 14 at low confidence, is a tally of exactly 14 findings and is a small sample rather than a benchmark. Client outcomes are published on our case study page and measured against the manual process each client recorded before the build. External statistics are attributed inline with the publishing organization and date.

Reviewed 5 October 2026 by Usama Tariq, Co-Founder and CTO. If you find an error in this post, email info@codeatic.com and we will publish a correction on the page rather than editing it quietly.

Frequently asked questions

What is on an AI audit checklist?

4 groups. Your processes, meaning every task done more than 5 times a week with minutes and frequency against each. Your systems, including every paid tool, which ones talk to each other and who holds the admin logins. Your numbers, meaning inbound volume, loaded hourly cost and average job value. And your people, meaning one person per process who actually does it plus somebody who can approve a build.

How long does an AI audit take?

A free automated audit takes a couple of minutes. A paid audit runs 7 to 10 days after a 30 minute discovery call. Gathering the checklist takes about half a day of your side's time.

Who needs to be involved from my team?

One person per process in scope, for roughly an hour each, and they should be the person who does the work rather than the person who manages it. Managers describe the intended process; the people doing it describe the real one. You also need somebody who can approve a build, or the audit ends as a document.

Does an AI audit need access to our data or systems?

A free audit needs nothing, since it works from public information. A paid audit needs people to talk to and your numbers, not usually live system access. If a provider asks for admin credentials early, ask exactly what for.

What if the audit finds nothing worth doing?

That is a legitimate outcome and a cheap one. If your recurring tasks run a few times a month, or every step needs judgment, the honest finding is to automate nothing. A provider who never reaches that conclusion is not auditing.

What does an AI audit report contain?

A readiness score, a short list of first actions, then each finding with what happens today, what could take it over, ratings for automatable, complexity, priority and confidence, and the evidence behind the claim. Good reports close with what the audit assumed and what it could not determine.

What does automatable partial mean?

That part of the task can run by itself and part needs a person. It is the honest answer most of the time: across the DrioGrowth and Zapture Media reports, 13 of 14 findings were partial and only 1 was fully automatable. Assembling a report can be automated; deciding what to do about it usually should not be.

How much does an AI audit cost?

Automated audits are free. Our paid AI Opportunity Audit is a fixed $3,000 over 7 to 10 days. Builds that follow typically run 4 to 8 weeks and you own 100% of the code.


Abdul Wahab, Co-Founder and CEO, Codeatic

Abdul has spent 5 years building software, across web stacks and mobile in React Native, Flutter and native Android, before moving into product, architecture and AI work. He holds an MS in Computer Science from PUCIT and leads Codeatic, an AI automation agency working with SMBs and startups across the US, Canada and the UK. Connect on LinkedIn.

Technically reviewed by Usama Tariq, Co-Founder and CTO, Codeatic. Usama is an AI and computer vision engineer who builds production systems from unstructured video, image and speech data. He built the REVOX engine at Veedback, developed LLM and computer vision systems at Coeus Solutions GmbH, and led AI model development at OMNO AI. He is an OpenCV OAK-D finalist and a contributor to Workhub, and holds a BS in Computer Science from COMSATS University Islamabad. Connect on LinkedIn.