# AI agent audit software procurement checklist

Version 1.0

Published and reviewed: 28 July 2026

Companion guide: https://kla.digital/blog/ai-agent-audit-software-requirements-vendor-categories

Use this workpaper to compare the purchased edition and deployment of each candidate. Record an
observable verdict and evidence for every line. A roadmap statement is an open item.

## Procurement record

- Organization:
- Review owner:
- Audit or assurance objective:
- In-scope agent population:
- Environments and tenants:
- Review period:
- Applicable criteria:
- Candidate vendor and product:
- Edition, region, deployment, and quoted integrations:
- Vendor representative:
- Proof-of-concept start:
- Proof-of-concept end:
- Final reviewer:
- Final decision:
- Decision date:
- Next review date:

Use these verdicts:

- **Pass:** the buyer ran the test and retained sufficient evidence.
- **Partial:** the capability worked for part of the boundary or required an unplanned dependency.
- **Fail:** the test produced the wrong result or no usable evidence.
- **Unverified:** the vendor described the capability and the buyer did not run the test.
- **Out of scope:** the requirement is excluded with an approved rationale and owner.

## 1. Inventory

- [ ] Import one vendor-platform agent export and one custom-agent source.
- [ ] Record stable agent, release, owner, purpose, environment, model, tool, and lifecycle fields.
- [ ] Detect a duplicate record and preserve the reconciliation decision.
- [ ] Preserve a missing owner as an open gap.
- [ ] Retain proposed, active, suspended, and retired records for the stated review period.
- Verdict:
- Evidence:
- Limitation, owner, and due date:

## 2. Identity

- [ ] Trace one action to the agent, workload, service, delegated human, owner, and reviewer identities.
- [ ] Record issuer, subject, audience, credential or token reference, status, and lifecycle event.
- [ ] Disable the agent or workload identity and prove later calls fail.
- [ ] Detect an expired credential and an unexpected audience.
- Verdict:
- Evidence:
- Limitation, owner, and due date:

## 3. Permissions

- [ ] Export assigned tools, resources, data, actions, purpose, amount, environment, and time limits.
- [ ] Compare assigned authority with authority observed during the review period.
- [ ] Deny one forbidden resource, one forbidden field, one excessive amount, and one expired grant.
- [ ] Preserve exception owner, rationale, approval, expiry, and review history.
- Verdict:
- Evidence:
- Limitation, owner, and due date:

## 4. Policy

- [ ] Record policy ID, version, inputs, matched rules, reasons, precedence, outcome, and owner.
- [ ] Exercise `allow`, `warn`, `require_approval`, and `block`.
- [ ] Replay one request under two policy versions.
- [ ] Force the policy dependency to fail and confirm the configured failure outcome.
- Verdict:
- Evidence:
- Limitation, owner, and due date:

## 5. Approval

- [ ] Hold the exact request and record its digest before review.
- [ ] Record reviewer identity, current authority, evidence presented, rationale, and decision.
- [ ] Deny self-approval and an ineligible reviewer.
- [ ] Deny an expired approval and a request changed after approval.
- [ ] Join the approved request to one execution receipt.
- Verdict:
- Evidence:
- Limitation, owner, and due date:

## 6. Tool calls

- [ ] Record ordered tool requests, bounded parameters, callers, targets, timestamps, responses, and errors.
- [ ] Reconstruct one retry and one partial failure.
- [ ] Join nested or asynchronous work with stable correlation identifiers.
- [ ] Preserve the policy and approval state applied to each consequential call.
- Verdict:
- Evidence:
- Limitation, owner, and due date:

## 7. Outcomes

- [ ] Reconcile one successful call to the source system's before and after state.
- [ ] Record a business outcome, receipt, exception, rollback, and reconciliation state.
- [ ] Detect one delayed downstream side effect.
- [ ] Preserve unresolved outcome gaps in the audit population.
- Verdict:
- Evidence:
- Limitation, owner, and due date:

## 8. Evidence integrity

- [ ] Export canonical records plus a manifest and stable schema.
- [ ] Record hash, signature or equivalent integrity proof, custody, and verification result.
- [ ] Alter one record and detect the change.
- [ ] Remove one record and detect the omission.
- [ ] Add one record and detect the addition.
- [ ] Substitute one valid record from another tenant or period and detect the mismatch.
- Verdict:
- Evidence:
- Limitation, owner, and due date:

## 9. Retention

- [ ] Map each record class to retention, deletion, residency, backup, and access rules.
- [ ] Apply two retention classes to the fixture.
- [ ] Place one case on legal hold and preserve the decision history.
- [ ] Delete one expired record through the supported process.
- [ ] Record signing-key, encryption-key, and backup lifecycle dependencies.
- Verdict:
- Evidence:
- Limitation, owner, and due date:

## 10. Export

- [ ] Export the complete sampled period in a documented machine-readable format.
- [ ] Include stable IDs, schema versions, attachments, manifests, and source links.
- [ ] Verify and query the export with ordinary tools after vendor access is removed.
- [ ] Record fields, relationships, or attachments omitted from the export.
- [ ] Measure export completion time and operational dependencies.
- Verdict:
- Evidence:
- Limitation, owner, and due date:

## 11. Tenant scope

- [ ] Record tenant, legal entity, account, region, and environment on every relevant object.
- [ ] Attempt cross-tenant reads, writes, searches, and exports.
- [ ] Test background jobs, caches, logs, support access, and administrator paths.
- [ ] Attempt to substitute evidence from a different tenant or environment.
- Verdict:
- Evidence:
- Limitation, owner, and due date:

## 12. Audit workflow

- [ ] Define the population, period, criteria, control owner, and reviewer.
- [ ] Select a reproducible sample and record the selection logic.
- [ ] Issue an evidence request and preserve owner, due date, response, and reviewer disposition.
- [ ] Record test steps, exceptions, findings, remediation, sign-off, and conclusion boundary.
- [ ] Export the complete workpaper and its source links.
- Verdict:
- Evidence:
- Limitation, owner, and due date:

## Failure and recovery cases

- [ ] Identity unavailable or stale.
- [ ] Policy service unavailable.
- [ ] Approval service unavailable or decision expired.
- [ ] Telemetry delayed, duplicated, reordered, or missing.
- [ ] Evidence storage unavailable.
- [ ] Signing or integrity service unavailable.
- [ ] Export interrupted and resumed.
- [ ] Source-system outcome conflicts with the agent or trace record.
- [ ] Emergency revocation during an active workflow.
- [ ] Retention deletion conflicts with a legal hold.

## Commercial and operating boundary

- [ ] Purchased capabilities, edition, region, and deployment match the proof of concept.
- [ ] Required connectors, customer code, professional services, and manual attestations are listed.
- [ ] Data categories, residency, subprocessors, support access, and deletion terms are reviewed.
- [ ] Availability, recovery, incident, change, and deprecation terms are reviewed.
- [ ] Usage, storage, export, API, connector, and professional-service costs are modeled.
- [ ] Source-code escrow, export, transition, and service-exit needs are recorded where relevant.
- [ ] Product claims are linked to official sources and carry a review date.

## Final requirement matrix

| Requirement | Verdict | Evidence reference | Material limitation | Owner | Due date |
|---|---|---|---|---|---|
| Inventory |  |  |  |  |  |
| Identity |  |  |  |  |  |
| Permissions |  |  |  |  |  |
| Policy |  |  |  |  |  |
| Approval |  |  |  |  |  |
| Tool calls |  |  |  |  |  |
| Outcomes |  |  |  |  |  |
| Evidence integrity |  |  |  |  |  |
| Retention |  |  |  |  |  |
| Export |  |  |  |  |  |
| Tenant scope |  |  |  |  |  |
| Audit workflow |  |  |  |  |  |

## Decision record

- Selected category or stack:
- Selected vendor and edition:
- Requirements passed:
- Requirements partial:
- Requirements failed:
- Requirements unverified:
- Accepted limitations:
- Rejected limitations:
- Required remediation before purchase:
- Contract conditions:
- Evidence retained:
- Decision rationale:
- Approver:
- Renewal test date:

This checklist supports procurement and assurance work. It does not provide certification, legal
advice, or a conclusion about any vendor or deployment.
