Skip to content
Academy
Marketing Academy · Field Work●Marketing Tools
MiniAudit· 25 minutes

The Governance Gap: Auditing a Team's AI Usage

Lenskart

Objective: Given a log of 8 recent AI tool interactions from a marketing team, apply the lesson's Common Mistakes framework to flag which ones violate data-privacy or human-review practices before they become a security incident.

You're auditing AI tool usage for Lenskart's regional marketing team after a data-privacy review was flagged company-wide. You have a log of the last 8 times someone on the team used an AI tool.

Score all 8 logged interactions against the lesson's two governance-related Common Mistakes (data residency/PII exposure, skipping human review) and recommend a fix for each violation.

Before you start

What you'll need

Free path (everything below is enough to finish)

FreeBuild and score the governance audit log

Free, and the audit trail is easy to share with a compliance stakeholder

The process

2 steps

Step 01 of 02

Data residency and PII exposure in consumer AI accounts

The lesson names pasting customer lists into a consumer ChatGPT account as the #1 reason 40% of marketers cite data privacy as their top AI adoption blocker. Enterprise tiers with zero-retention agreements are the fix.

Of the 8 logged interactions, 2 involve pasting a customer email list into a free-tier consumer chatbot account to draft a segmented campaign. What makes this specifically a governance violation rather than just a workflow shortcut?

Google Sheets— List all 8 interactions with the tool used, account tier (free/enterprise), and whether customer data was involved.

Procedure

  1. List each interaction with tool name, account tier, and data type used
  2. Flag any interaction that pastes customer PII into a free consumer-tier account
  3. Note which of those flagged items used an account with no zero-retention agreement
Sample output
Interaction                          Account tier    PII involved?   Flag
Segment email list via ChatGPT free   Free consumer    Yes             VIOLATION
Draft ad headline via Claude free     Free consumer    No              OK
Summarize interview via NotebookLM    Team workspace    Yes (names)     Needs review

Healthy

Every interaction touching customer PII runs through an enterprise or team-tier account with a zero-retention agreement on file.

Unhealthy

A customer email list gets pasted into a free consumer chatbot account with no data agreement, exactly the pattern the lesson flags as the top-cited adoption blocker.

What this means

The violation isn't using AI to segment a list, it's doing it on the wrong account tier with no data agreement covering what happens to that list afterward.

So what do I do about it?

SymptomActionEffort
Any interaction pastes customer PII into a free-tier consumer AI accountMove that workflow to an enterprise/team-tier account with a signed zero-retention agreement before it repeats30 min
YouYou can do this yourself, no engineering access required.

Step 02 of 02

Skipping the human review layer before publishing AI output

The lesson treats AI as a first-draft engine, not a publisher, citing Sports Illustrated's 2023 fake-author scandal as the cautionary tale for unedited AI output going live.

Of the 8 interactions, 1 shows an AI-drafted blog post published the same day it was generated, with no edit timestamp between draft and publish. Why does that specific pattern matter more than just 'was it edited'?

Google Sheets— Add a 'draft timestamp' and 'publish timestamp' column to the same log.

Procedure

  1. Compare draft generation time against publish time for each content-producing interaction
  2. Flag any same-day, near-zero-gap publish as a likely skipped-review case
  3. Note whether a named human reviewer is logged for that item
Sample output
Interaction                    Draft time   Publish time   Gap        Flag
Blog post via Jasper            9:02 AM      9:14 AM        12 min     VIOLATION, no reviewer logged
Ad variant via ChatGPT          10:00 AM     Next day 2 PM  ~28 hrs    OK, reviewer logged

Healthy

Every published piece shows a meaningful time gap between AI draft and publish, with a named human reviewer logged in between.

Unhealthy

A blog post goes live 12 minutes after being drafted, with no reviewer name attached, the same failure pattern that caused a real, public retraction elsewhere.

What this means

A near-zero time gap between draft and publish is a reliable proxy for skipped review, even without knowing exactly what was or wasn't checked.

So what do I do about it?

SymptomActionEffort
A published item shows less than a few hours between AI draft and publish with no reviewer loggedAdd a mandatory named-reviewer field to the publishing checklist before content can go live30 min
YouYou can do this yourself, no engineering access required.

Final deliverable

An 8-row governance audit log flagging every PII-exposure and skipped-review violation, each with a specific one-line fix.

See a reference example
Sample output
Warby Parker regional team, AI usage audit (excerpt)

Interaction                     Flag         Fix
Customer list segmentation      PII exposure  Move to enterprise-tier account with zero-retention agreement
Same-day blog publish            No review     Require a named reviewer before publish, minimum 2-hour gap

Success criteria

You're done when you can:

  • Correctly identifies both PII-exposure interactions using account tier as the deciding factor, not just tool name
  • Correctly flags the same-day publish gap as a review-skip risk using timestamp evidence