Responsible AI readiness checklist for CEQA and NEPA teams.
A responsible pilot starts with a defined task, approved sources, data boundaries, accountable reviewers, acceptance criteria, and documentation. This checklist helps environmental-review teams identify missing controls before choosing or deploying a tool.
Selections stay in this browser tab and are never submitted.
How to use this checklist
Record evidence and ownership—not a readiness score.
The three response choices are prompts for discussion. They do not produce a pass, grade, certification, or compliance result.
01
Choose one proposed task or workflow rather than trying to assess an entire organization in one pass.
02
For each question, select Yes, Not yet, or Not applicable and identify the evidence and owner behind that answer.
03
Bring in the practitioner, project owner, information-technology, privacy, records, procurement, or counsel roles when their responsibilities are implicated.
04
Move unresolved items into the action plan and apply the critical stop conditions before choosing a next path.
05
Revisit the checklist when the task, sources, model, vendor terms, data sensitivity, procedure, template, or review responsibility changes.
Eight control domains
Work through one task with the people accountable for it.
Every answer should be supported by a source, observed condition, named owner, or documented gap. Responses are ephemeral and are not transmitted or retained by CEQA Labs.
Domain 01
Task and decision boundary
Define one use case, the intended output, non-delegable decisions, and the consequence of failure before discussing a model or tool.
Domain 02
Accountability and governance
Name the workflow owner, qualified reviewer, supporting governance roles, escalation path, and stop authority.
Domain 03
Authoritative sources and traceability
Establish the approved source hierarchy, version dates, retrieval method, citation checks, and treatment of missing or conflicting material.
Domain 04
Data and confidentiality boundaries
Classify the information involved and decide which inputs, outputs, logs, and derived data are allowed before any material is transferred.
Domain 05
Approved technology and vendor review
Verify the approved environment, access controls, external dependencies, material terms, version changes, and exit path without assuming any vendor is suitable.
Domain 06
Templates and quality criteria
Preserve supplied and approved templates and terminology, then test the actual task against explicit, observable acceptance criteria.
Domain 07
Practitioner review and documentation
Define the review trail so authorized people can understand the sources, method, revisions, decisions, exceptions, and remaining limits.
Domain 08
Pilot, monitoring, and retirement
Bound initial use and define observation, incident, rollback, re-evaluation, and retirement actions before broader adoption.
Critical stop conditions
Pause the proposed use when a foundational control is unresolved.
No accountable owner or qualified reviewer has authority and time to review the proposed use.
The workflow would assign an agency determination, legal opinion, technical-specialist conclusion, or final professional judgment to the AI system.
The authoritative source set is unavailable, materially outdated, or cannot be traced through the output.
Prohibited or sensitive information cannot remain within an approved handling environment.
Material vendor terms, training use, retention, access, deletion, ownership, or subprocessor conditions remain unresolved.
The team cannot test the workflow against representative examples, known failure modes, and explicit review criteria.
Required review history or source traceability cannot be produced without creating an unresolved privacy, privilege, security, or records conflict.
A material accuracy, bias, safety, privacy, security, or information-integrity issue remains unresolved.
An authorized client, agency, counsel, information-technology, privacy, records, procurement, or other decision-maker has prohibited the use.
Turn gaps into an action plan
Assign the decision, evidence, owner, and due date.
Use the blank rows in a printed copy or recreate these columns in an approved internal system. Do not enter confidential, privileged, pre-decisional, or sensitive information on a shared or unapproved copy.
Responsible AI control-gap action-plan worksheet
Gap
Owner
Decision needed
Evidence
Due date
What this checklist does not decide
A planning aid is not an approval or professional determination.
This ungated CEQA Labs resource is an independent planning aid informed by voluntary NIST publications. It is not a NIST product, checklist, certification, endorsement, conformance or compliance assessment, legal opinion, agency acceptance, security or privacy approval, procurement approval, or fitness determination for an organization or use. It does not replace current primary sources, project-specific CEQA or NEPA review, agency judgment, qualified practitioner review, counsel, technical specialists, records or privacy staff, or information-technology review. Do not enter project details or sensitive information into this checklist. NIST states that AI RMF 1.0 is being revised, so the source basis requires review when NIST publishes a material update.
Current official sources remain the authority for their own claims.
Source status was reviewed on July 9, 2026. NIST describes AI RMF 1.0 as voluntary and currently states that it is being revised. This independent checklist must be re-reviewed after material source changes.
NIST describes this as a voluntary companion with suggested actions around Govern, Map, Measure, and Manage; organizations may use as many or as few suggestions as fit.
From Hype to Controls: Applying NIST AI 600-1 in CEQA and NEPA Workflows
A founder-led CEQA.ai research article with deeper sector-specific interpretation. It is related analysis, not the authority for NIST claims on this page.
Treat the outcome as a planning judgment—not a checklist result.
01
Keep the workflow conventional
Use the existing professional process when AI does not fit the task, approved environment, data sensitivity, or review standard—or when a stop condition remains unresolved.
Use this path only for an approved, narrow task with representative test material, named reviewers, stop conditions, documented evaluation, and a conventional rollback path.