# CISO AI Board Memo Checklist

Use this to brief leadership on AI security without turning the conversation into tool hype.

## Executive Summary

- What changed in AI risk this quarter?
- Which business units are using AI in production?
- Which AI systems can touch sensitive data, source code, cloud, or customer workflows?
- What is the current risk posture: green, yellow, or red?

## Control Status

- Approved AI tools are documented.
- Shadow AI usage is measured.
- AI agents have identities and owners.
- Model gateway logging is enabled where applicable.
- Sensitive data rules are enforced.
- Incident response covers agent misuse and prompt injection.

## Business Risk

- Top three AI-enabled attack paths.
- Top three productivity or defense wins.
- Open risks that need budget, policy, or executive decision.
- Metrics: adoption, blocked events, reviewed workflows, exposed secrets, incident readiness.

## Board Ask

- What decision is needed?
- What investment is needed?
- What risk acceptance is being requested?
- What will improve before the next board update?
