home / guides / How to Build an Approved AI Tools List (With Evaluation Checklist)

Guide

How to Build an Approved AI Tools List (With Evaluation Checklist)

A short, honest set of vendor questions — data retention, training, SSO, and admin controls — for deciding what makes the list.

Updated 2026-09-27 · 9 min read · yforest AI Labs

Key takeaways

  • An approved AI tools list only works if it's specific, current, and easy for employees to find.
  • Evaluate every tool on the same four questions: data retention, training on your data, SSO, and admin controls.
  • Start with two or three tools that cover the most common needs — a longer list is harder to maintain and adds little value.
  • Free tiers deserve more scrutiny than paid plans, not less, since they're more likely to train on your input by default.
  • Review the list quarterly — a vendor's data practices can change without much notice.

"Ask before you use a new AI tool" only means something if there's an actual list to check against. Without one, every request turns into a judgment call made from scratch, and most small businesses default to saying yes to whatever seems useful, without a consistent way to evaluate it. An approved AI tools list fixes that — not by naming favorites, but by giving every tool the same short, honest evaluation before it earns a spot.

Why a list, not case-by-case decisions

Case-by-case AI approvals feel more flexible, but in practice they produce inconsistent answers — the same type of tool gets approved for one team and denied for another, based on who happened to ask and how the conversation went. A written list, evaluated against the same criteria every time, removes that inconsistency and gives employees something concrete to check before they start using a new tool.

It also solves the problem at the root of shadow AI. Employees don't go looking for unapproved tools out of defiance — they go looking because there's no fast, clear way to get a tool approved. A short list with a known evaluation process closes that gap.

The four-question evaluation checklist

Keep the checklist short enough that you'll actually use it every time a new tool comes up. These four questions cover the risk that matters most for a small business — what happens to your data once it enters the tool.

QuestionWhy it matters
Data retention — how long is our data kept, and can we delete it?Determines how long an exposure lasts if something goes wrong.
Training — does the vendor train its models on our input?If yes, information you enter can influence outputs shown to other users elsewhere.
SSO — does it support single sign-on through our existing system?Lets you control access centrally and remove it instantly when someone leaves.
Admin controls — can an administrator see usage and manage settings?Without this, you have no visibility into how the tool is actually being used day to day.
Where to find the answers

Most reputable vendors publish this information in a security or trust page, a data processing addendum, or an enterprise/business-tier FAQ. If you can't find it in ten minutes of searching, ask the vendor directly in writing — a clear written answer is itself a good sign.

Copy-ready vendor evaluation form

Use this for every tool before it's added to the list, whether it's a request from an employee or something you're considering proactively.

AI vendor evaluation — starter form
Tool name: ___________________________ Requested by: ___________________________ Intended use: ___________________________ 1. Data retention — How long does the vendor keep our data? Can we request deletion? Answer: ___________________________ 2. Training on our data — Does the vendor use our input to train its models? Is there an opt-out? Answer: ___________________________ 3. Single sign-on — Does the tool support SSO through our existing identity provider? Answer: ___________________________ 4. Admin controls — Can an administrator view usage and manage user access centrally? Answer: ___________________________ Decision: ☐ Approved ☐ Approved with limits: ___________ ☐ Declined Reviewed by: ___________________________ Date: __________

Note what this form deliberately leaves out: price, brand reputation, and marketing claims. Those factors matter for choosing between two similarly safe tools, but they're not a substitute for the four questions above — a well-known brand name isn't itself a data-handling guarantee.

What the list should not do

Because this guide is meant to help you evaluate tools generally, it deliberately avoids naming specific vendors, quoting prices, or making claims about any particular product's guarantees. Your own evaluation form, run against the four questions above, will tell you far more than any general recommendation could — data practices, pricing, and feature sets change often enough that a specific endorsement here would likely be outdated within months.

Keeping the list current

An approved list that never changes eventually stops matching reality — new needs come up, vendors change their terms, and tools get replaced. Review it on the same cadence as the rest of your AI governance: quarterly is a reasonable default for most small teams. When a vendor changes its data or training policy, treat that as a trigger for an off-cycle review rather than waiting for the next scheduled one.

Watch for policy changes

AI vendors update their terms of service more frequently than most software categories. A tool approved a year ago under one set of data rules may operate under different ones today — worth a quick check at each review.

Not every tool needs the full evaluation

The four-question checklist is thorough by design, but running it in full for every tool someone mentions in passing will slow the process down enough that people stop using it. Sort requests by what the tool would actually touch before deciding how much scrutiny it needs.

Tool touches...Evaluation depth
Nothing but the employee's own drafting, no company or customer dataLight check — confirm it's not obviously unsafe, approve quickly
Internal company information, no customer or financial dataFull four-question checklist
Customer data, financial records, or system integrations (SSO, CRM, email)Full checklist plus a written data processing agreement or terms review, ideally with legal input

This tiered approach keeps the approval process fast for low-risk requests — which are also the most common ones — while reserving real scrutiny for the tools that could actually cause a problem if something went wrong.

Don't forget AI features already inside your software

The most overlooked category of "AI tool" isn't a new chatbot someone signed up for — it's an AI feature quietly switched on inside software you already pay for. CRM platforms, email tools, scheduling software, and accounting systems increasingly ship with AI features enabled by default, sometimes without an obvious announcement. These deserve the same evaluation as a standalone tool, because the data question is identical: what happens to the information that flows through that feature, and who can see it.

Check your existing software

Before building your approved list from scratch, do a quick pass through the settings of software you already use. You may find AI features already turned on that were never formally approved — and now have an easy path onto (or off of) your list.

Making sure people actually use it

A carefully built list that lives in a document nobody opens does no better than having no list at all. Treat "where do employees find this" as seriously as the evaluation itself.

  • Put it somewhere people already look. Link it from the handbook, an onboarding checklist, or wherever your team already checks for company information — not a folder three levels deep in a shared drive.
  • Reference it by name in the policy. Your written AI acceptable use policy should point directly to where the current list lives, rather than trying to reproduce it inline and risking it going out of sync.
  • Announce updates. When a new tool gets approved, say so — a one-line message to the team keeps the list feeling current instead of static.

The list only does its job if checking it is easier than not checking it. If an employee has to ask around to find the current version, they'll skip the step entirely and make the call themselves — which is exactly the shadow AI problem this list exists to prevent.

A brief mention in a team meeting when the list is first published, followed by a short note any time it changes, is usually enough. The goal isn't constant reminders — it's making sure that the one time someone actually needs to check it, they know exactly where to look.

Common mistakes

  • Approving a tool because it's popular. Popularity says nothing about data retention or training practices — check the actual answers.
  • Making the list too long. More tools means more surface area to review and more confusion about which one to use for what.
  • Skipping the free tools. Free tiers often have looser data practices than paid ones and deserve at least as much scrutiny.
  • Never revisiting approved tools. A tool's data practices when you approved it may not match its current ones.
  • Treating the list as private. If employees don't know it exists or where to find it, it won't prevent shadow AI.

Once your list is built, connect it to your written AI acceptable use policy so employees see one consistent set of rules, and to your vendor security checklist for tools that go beyond general AI assistants into more specialized systems.

◆ Small Business AI Kickstart

Get AI ready today.
Before it's too late.

yforest AI Labs comes to your company, trains your team, and ships your first tools.

FAQ

How many tools should be on an approved list to start?

Two or three is enough for most small businesses at the start — one general-purpose assistant, and one or two tools for specific needs like transcription or customer support. A longer list is harder to maintain and doesn't add much value early on.

Should we name specific vendors in a public-facing guide or handbook?

Internally, yes — your team needs to know exactly which tools are approved. Just evaluate each one on the same checklist rather than picking based on reputation or marketing claims alone.

What if a tool we already use doesn't answer our vendor questions clearly?

Treat a vague or evasive answer as a red flag. A vendor that can't clearly explain its data retention or training practices in writing is a reason to look for an alternative or restrict the tool to low-risk uses only.

Do free AI tools need the same evaluation as paid ones?

Free tools need more scrutiny, not less. Free consumer tiers are more likely to use your input to train their models by default, so check the data-training question especially carefully before approving one for anything beyond casual, non-sensitive use.

How often should the approved list be reviewed?

Quarterly works well for most small businesses — often enough to catch a vendor's policy change, infrequent enough to stay low-effort.

Sources

  1. UpGuard shadow AI research, reported by Cybersecurity Dive (Nov 2025)

This guide is general information, not legal advice. Have a qualified attorney review any policy before you adopt it.