Ungated practitioner resource

Responsible AI readiness checklist for CEQA and NEPA teams.

A responsible pilot starts with a defined task, approved sources, data boundaries, accountable reviewers, acceptance criteria, and documentation. This checklist helps environmental-review teams identify missing controls before choosing or deploying a tool.

Selections stay in this browser tab and are never submitted.

How to use this checklist

Record evidence and ownership—not a readiness score.

The three response choices are prompts for discussion. They do not produce a pass, grade, certification, or compliance result.

  1. Choose one proposed task or workflow rather than trying to assess an entire organization in one pass.

  2. For each question, select Yes, Not yet, or Not applicable and identify the evidence and owner behind that answer.

  3. Bring in the practitioner, project owner, information-technology, privacy, records, procurement, or counsel roles when their responsibilities are implicated.

  4. Move unresolved items into the action plan and apply the critical stop conditions before choosing a next path.

  5. Revisit the checklist when the task, sources, model, vendor terms, data sensitivity, procedure, template, or review responsibility changes.

Eight control domains

Work through one task with the people accountable for it.

Every answer should be supported by a source, observed condition, named owner, or documented gap. Responses are ephemeral and are not transmitted or retained by CEQA Labs.

Task and decision boundary

Define one use case, the intended output, non-delegable decisions, and the consequence of failure before discussing a model or tool.

Is the proposed task and intended output defined in specific, reviewable terms?
Is the reason for considering AI clearer than the reason for keeping the workflow conventional?
Are the decisions that must remain with an agency, counsel, qualified practitioner, or technical specialist explicitly identified?
Are prohibited uses, outputs, and decision roles documented?
Is the consequence of a material error, omission, disclosure, or delay understood?
Can an authorized owner pause, narrow, or stop the use without losing the conventional path?

Accountability and governance

Name the workflow owner, qualified reviewer, supporting governance roles, escalation path, and stop authority.

Is one accountable owner named for the workflow and its use in environmental review?
Is a qualified practitioner assigned to review AI-assisted material before it enters a client deliverable or administrative record?
Are information-technology, privacy, records, procurement, counsel, and technical-specialist roles assigned where applicable?
Do reviewers have enough time, source access, training, and authority to challenge or reject an output?
Are escalation and exception decisions assigned to people with the appropriate authority?
Is responsibility for approving, pausing, changing, and retiring the workflow documented?

Authoritative sources and traceability

Establish the approved source hierarchy, version dates, retrieval method, citation checks, and treatment of missing or conflicting material.

Are the controlling statutes, regulations, procedures, project facts, technical studies, and supplied sources identified?
Is someone responsible for confirming that the source set is current and appropriate to the jurisdiction and task?
Can every material statement and citation in an output be traced to an authoritative source?
Is model output treated as draft material rather than as an authority or source?
Will missing, conflicting, superseded, or low-quality material be identified and escalated?
If public precedent is used, is there a control preventing it from being treated as current authority or project-specific acceptance?

Data and confidentiality boundaries

Classify the information involved and decide which inputs, outputs, logs, and derived data are allowed before any material is transferred.

Are confidential, privileged, pre-decisional, personally identifiable, proprietary, security-sensitive, and sensitive-species or location data classified?
Is the approved input set documented for the specific task and environment?
Are prohibited data and information categories explicit regardless of the available tooling?
Can testing begin with public, synthetic, redacted, or otherwise approved material?
Are access, sharing, export, deletion, and downstream-use responsibilities assigned?
Is there a response path for an accidental disclosure or other data-handling incident?

Approved technology and vendor review

Verify the approved environment, access controls, external dependencies, material terms, version changes, and exit path without assuming any vendor is suitable.

Has the organization approved the system, account configuration, integrations, and access model for this task and data?
Have retention, deletion, training use, secondary use, ownership, logging, and subprocessor terms been reviewed by the responsible roles?
Are the model, service, retrieval sources, plug-ins, and other value-chain components inventoried?
Is someone responsible for monitoring material product, model, term, security, and availability changes?
Can the workflow be paused, exported, or moved if a component no longer meets approved requirements?
Are the changes that require re-review or reapproval defined?

Templates and quality criteria

Preserve supplied and approved templates and terminology, then test the actual task against explicit, observable acceptance criteria.

Are the supplied and approved templates, terminology, source conventions, and permitted changes documented?
Is there a representative test set with edge cases and known difficult conditions?
Is the conventional process or prior reviewed work available as a comparison baseline?
Are criteria defined for source fidelity, factual accuracy, completeness, citation integrity, template integrity, and usefulness?
Will testing examine unsupported content, confabulation, omission, inconsistent treatment, harmful bias, and overconfident language?
Are the errors that stop the pilot or require a different workflow explicit?

Practitioner review and documentation

Define the review trail so authorized people can understand the sources, method, revisions, decisions, exceptions, and remaining limits.

Does qualified practitioner review occur before AI-assisted material enters a client deliverable or administrative record?
Are statutory, regulatory, agency, and case citations checked against authoritative primary sources before use?
Are source versions, system versions, instructions, material inputs, outputs, and settings documented as appropriate to the engagement?
Are practitioner revisions, rejected output, assumptions, exceptions, and reviewer decisions documented as appropriate?
Can an authorized reviewer reconstruct the source and review trail without relying on memory or an unavailable system?
Have the responsible people decided what should not be retained because it creates privacy, security, privilege, or records risk?

Pilot, monitoring, and retirement

Bound initial use and define observation, incident, rollback, re-evaluation, and retirement actions before broader adoption.

Is the pilot bounded by task, users, data, duration, project stage, and review responsibility?
Are role-specific training and instructions available before use begins?
Is someone assigned to monitor output quality, user workarounds, unexpected use, incidents, and context changes?
Are incident reporting, containment, review, correction, and escalation paths documented?
Will evaluation repeat after material model, vendor, source, template, procedure, staffing, or task changes?
Are rollback and retirement triggers defined for the workflow, access, retained material, documentation, and downstream dependencies?

Critical stop conditions

Pause the proposed use when a foundational control is unresolved.

Turn gaps into an action plan

Assign the decision, evidence, owner, and due date.

Use the blank rows in a printed copy or recreate these columns in an approved internal system. Do not enter confidential, privileged, pre-decisional, or sensitive information on a shared or unapproved copy.

Responsible AI control-gap action-plan worksheet
GapOwnerDecision neededEvidenceDue date

What this checklist does not decide

A planning aid is not an approval or professional determination.

This ungated CEQA Labs resource is an independent planning aid informed by voluntary NIST publications. It is not a NIST product, checklist, certification, endorsement, conformance or compliance assessment, legal opinion, agency acceptance, security or privacy approval, procurement approval, or fitness determination for an organization or use. It does not replace current primary sources, project-specific CEQA or NEPA review, agency judgment, qualified practitioner review, counsel, technical specialists, records or privacy staff, or information-technology review. Do not enter project details or sensitive information into this checklist. NIST states that AI RMF 1.0 is being revised, so the source basis requires review when NIST publishes a material update.

Read the professional disclaimer

Sources and related research

Current official sources remain the authority for their own claims.

Source status was reviewed on July 9, 2026. NIST describes AI RMF 1.0 as voluntary and currently states that it is being revised. This independent checklist must be re-reviewed after material source changes.

NIST Artificial Intelligence Risk Management Framework (AI RMF 1.0)

NIST AI 100-1, published January 26, 2023, is described by NIST as voluntary, rights-preserving, non-sector-specific, and use-case agnostic.

Read AI RMF 1.0 on NIST.gov (opens in a new tab)https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-ai-rmf-10

NIST AI RMF Playbook

NIST describes this as a voluntary companion with suggested actions around Govern, Map, Measure, and Manage; organizations may use as many or as few suggestions as fit.

Read the AI RMF Playbook on NIST.gov (opens in a new tab)https://www.nist.gov/itl/ai-risk-management-framework/nist-ai-rmf-playbook

NIST AI RMF: Generative Artificial Intelligence Profile

NIST AI 600-1, published July 26, 2024, is a cross-sector companion resource for generative AI risks and proposed risk-management actions.

Read NIST AI 600-1 on NIST.gov (opens in a new tab)https://www.nist.gov/publications/artificial-intelligence-risk-management-framework-generative-artificial-intelligence

From Hype to Controls: Applying NIST AI 600-1 in CEQA and NEPA Workflows

A founder-led CEQA.ai research article with deeper sector-specific interpretation. It is related analysis, not the authority for NIST claims on this page.

Deeper research on CEQA.ai (opens in a new tab)https://ceqa.ai/posts/nist-ai-600-1-for-ceqa-nepa-teams/

Use it in context

Accountability changes with the organization using the workflow.

Choose the next path

Treat the outcome as a planning judgment—not a checklist result.

Keep the workflow conventional

Use the existing professional process when AI does not fit the task, approved environment, data sensitivity, or review standard—or when a stop condition remains unresolved.

See the six operating controls

Close control gaps first

Assign owners, resolve source and data decisions, define testing, and document the conditions that must be met before a pilot is reconsidered.

Responsible AI workflow design

Consider scoping a controlled pilot

Use this path only for an approved, narrow task with representative test material, named reviewers, stop conditions, documented evaluation, and a conventional rollback path.

Discuss a bounded pilot