AI Data Boundary Template
This template is used to define, approve, test, and evidence the data boundaries for an AI use case.
AI data control does not end at access.
AI systems may expose data through prompts, retrieved context, embeddings, outputs, logs, vendor processing, downstream workflows, retained history, and inference.
The purpose of this template is to define what data AI can access, process, retrieve, retain, expose, reuse, or send to vendors.
1. Data Boundary Information
AI Use Case Name
[Enter AI use case name]
Data Boundary ID
[Enter data boundary ID]
Date
[Enter date]
Prepared By
Name:
Function:
Email:
Business Owner
Name:
Function:
Email:
Technical Owner
Name:
Function:
Email:
Data Owner
Name:
Function:
Email:
Related AI Inventory Record
Related Risk Assessment
2. AI Use Case Summary
Short Description
[Describe the AI use case]
AI Pattern
Select all that apply:
[ ] Copilot
[ ] Internal LLM application
[ ] RAG system
[ ] AI-enabled SaaS
[ ] Embedded vendor AI
[ ] Agent
[ ] AI-enabled workflow automation
[ ] Customer-facing AI
[ ] Employee-facing AI
[ ] Developer AI tool
[ ] Security operations AI
[ ] Decision-supporting AI
[ ] Action-capable AI
[ ] Other
Assigned Risk Tier
Select one:
[ ] Tier 1: Low-risk productivity or public-data use
[ ] Tier 2: Internal productivity with enterprise data
[ ] Tier 3: Decision-supporting AI
[ ] Tier 4: Action-capable AI
[ ] Tier 5: High-impact autonomous or regulated AI
3. Data Boundary Statement
Approved Data Boundary
[Describe the approved data boundary for this AI use case]
Business Purpose for Data Use
[Explain why this AI use case needs access to the data]
Data Minimization Statement
[Describe how data access is limited to the minimum required for the approved use case]
Prohibited Data Use
[Describe data that must not be accessed, processed, retrieved, retained, exposed, or reused]
4. Data Source Mapping
Data Source Notes
[Describe source-specific restrictions, approvals, or concerns]
5. Data Classification
Data Classes In Scope
Select all that apply:
[ ] Public
[ ] Internal
[ ] Confidential
[ ] Restricted
[ ] Regulated
[ ] Personal data
[ ] Customer data
[ ] Employee data
[ ] Financial data
[ ] Legal or privileged data
[ ] Security-sensitive data
[ ] Source code
[ ] Secrets or credentials
[ ] Production data
[ ] Other sensitive data
Highest Data Classification
Select one:
[ ] Public
[ ] Internal
[ ] Confidential
[ ] Restricted
[ ] Regulated
[ ] Highly sensitive
[ ] Unknown
Classification Notes
[Describe classification rationale and handling expectations]
6. Allowed Data
Allowed Data Types
[List data types the AI is allowed to access, process, retrieve, or generate]
Allowed Repositories or Systems
[List approved repositories, systems, databases, SaaS platforms, or knowledge sources]
Allowed User Groups
[List users, roles, business units, or groups allowed to use this data through the AI system]
Allowed Use Cases
[List approved purposes for which this data may be used by AI]
7. Restricted or Prohibited Data
Restricted Data Types
[List data types that require special approval or additional controls]
Prohibited Data Types
[List data types that must not be used by this AI system]
Prohibited Sources
[List repositories, systems, or sources that AI must not access]
Secrets and Credentials
[Describe controls to prevent secrets, tokens, credentials, private keys, and production secrets from entering prompts, context, outputs, or logs]
8. Retrieval Boundary
Complete this section if the AI use case uses retrieval, search, RAG, enterprise knowledge, or document grounding.
Retrieval Used?
[ ] No
[ ] Yes
[ ] Unknown
Retrieval Boundary Description
[Describe what the AI can retrieve and what it cannot retrieve]
Retrieval Controls
Select all that apply:
[ ] User permission inheritance
[ ] Role-based retrieval
[ ] Attribute-based retrieval
[ ] Repository allowlist
[ ] Repository denylist
[ ] Document-level permissions
[ ] Metadata filtering
[ ] Classification filtering
[ ] Tenant filtering
[ ] Project or workspace filtering
[ ] Customer/account filtering
[ ] Geographic filtering
[ ] Sensitive source exclusion
[ ] Manual data owner approval
[ ] Other
Retrieval Boundary Table
Retrieval Testing Required?
[ ] No
[ ] Yes
[ ] Unknown
Retrieval Test Notes
[Describe tests required to verify retrieval boundaries]
9. Prompt and Input Data Boundary
Prompt/Input Data Allowed
[Describe what users or systems may submit into the AI system]
Prompt/Input Data Prohibited
[Describe what users or systems must not submit]
Sensitive Data Detection
Select all that apply:
[ ] Not required
[ ] User guidance only
[ ] Warning
[ ] Redaction
[ ] Masking
[ ] Blocking
[ ] DLP integration
[ ] Manual approval
[ ] Escalation
[ ] Unknown
Prompt/Input Logging Approach
Select one:
[ ] No prompt content logging
[ ] Metadata-only logging
[ ] Redacted prompt logging
[ ] Full prompt logging
[ ] Reference or hash only
[ ] Violation-only logging
[ ] Unknown
Prompt/Input Notes
[Describe prompt data risks, restrictions, and logging approach]
10. Context Assembly Boundary
Context Sources
Select all that apply:
[ ] User prompt
[ ] System prompt
[ ] Retrieved documents
[ ] Conversation history
[ ] Memory
[ ] Tool responses
[ ] Workflow state
[ ] User metadata
[ ] Application metadata
[ ] External content
[ ] Other
Context Isolation Required?
[ ] No
[ ] Yes
[ ] Unknown
Context Isolation Boundaries
Select all that apply:
[ ] User
[ ] Session
[ ] Tenant
[ ] Business unit
[ ] Project
[ ] Repository
[ ] Customer account
[ ] Data classification
[ ] Trust level
[ ] Internal vs external
[ ] Production vs non-production
[ ] Other
Context Assembly Controls
[Describe how context is selected, minimized, labeled, isolated, and protected]
11. Model, Vendor, and Processing Boundary
AI Processing Model
Select one:
[ ] Internal model
[ ] Hosted model API
[ ] Cloud AI service
[ ] SaaS AI feature
[ ] Embedded vendor AI
[ ] Open-source model hosted internally
[ ] Open-source model hosted externally
[ ] Unknown
[ ] Other
Vendor or Platform
Vendor/platform:
Model/service:
Processing location:
Does Data Leave the Enterprise Boundary?
[ ] No
[ ] Yes
[ ] Unknown
Cross-Boundary Movement
Select all that apply:
[ ] No cross-boundary movement
[ ] Vendor boundary
[ ] Cloud boundary
[ ] Geographic boundary
[ ] Jurisdictional boundary
[ ] Tenant boundary
[ ] Business unit boundary
[ ] Production/non-production boundary
[ ] Internal/external boundary
[ ] Unknown
Vendor Processing Notes
[Describe vendor processing, location, subprocessors, contractual restrictions, and shared responsibility]
12. Retention and Reuse
Data Retained
Select all that apply:
[ ] Prompts
[ ] Uploaded files
[ ] Retrieved context
[ ] Embeddings
[ ] Model inputs
[ ] Model outputs
[ ] Conversation history
[ ] Memory
[ ] Tool call logs
[ ] Approval logs
[ ] Generated records
[ ] Audit evidence
[ ] Vendor telemetry
[ ] Training datasets
[ ] Fine-tuning datasets
[ ] None
[ ] Unknown
Retention Period
[Describe retention period by data type]
Deletion Process
[Describe how data is deleted and who owns deletion]
Training Allowed?
[ ] No
[ ] Yes
[ ] Only with approval
[ ] Unknown
Product Improvement or Analytics Allowed?
[ ] No
[ ] Yes
[ ] Only with approval
[ ] Unknown
Fine-Tuning Allowed?
[ ] No
[ ] Yes
[ ] Only with approval
[ ] Unknown
Retention and Reuse Notes
[Describe restrictions on retention, training, fine-tuning, analytics, telemetry, or product improvement]
13. Output Data Boundary
Output Types
Select all that apply:
[ ] Informational answer
[ ] Summary
[ ] Draft
[ ] Classification
[ ] Recommendation
[ ] Score
[ ] Extracted data
[ ] Generated code
[ ] Customer response
[ ] Internal communication
[ ] Decision support
[ ] Workflow instruction
[ ] Action request
[ ] Generated record
[ ] Other
Output Sensitivity Rule
[Describe whether output inherits classification from source data and how sensitivity is preserved]
Output Sharing Restrictions
[Describe who can receive or use AI outputs]
Output Logging Approach
Select one:
[ ] No output content logging
[ ] Metadata-only logging
[ ] Redacted output logging
[ ] Full output logging
[ ] Reference or hash only
[ ] Violation-only logging
[ ] Unknown
Output Boundary Notes
[Describe output sensitivity, sharing, downstream use, generated records, and correction requirements]
14. Downstream Use Boundary
Downstream Use Allowed?
[ ] No
[ ] Yes
[ ] Conditional
[ ] Unknown
Downstream Systems or Workflows
Downstream Use Restrictions
[Describe restrictions before AI output can be used by downstream systems, workflows, records, or decisions]
Decision or Action Impact
[Describe whether output influences decisions, records, workflows, or actions]
15. Logging and Evidence Boundary
Required Evidence
Select all that apply:
[ ] Data source map
[ ] Data owner approval
[ ] Data classification
[ ] Retrieval configuration
[ ] Retrieval logs
[ ] Data access logs
[ ] Prompt/input logs or metadata
[ ] Output logs or metadata
[ ] Training/reuse restriction
[ ] Retention rule
[ ] Vendor processing record
[ ] Cross-boundary transfer record
[ ] Leakage test result
[ ] Exception record
Evidence Location
[Describe where evidence is stored]
Evidence Access Restrictions
[Describe who can access evidence and how evidence is protected]
Evidence Retention
[Describe how long evidence is retained]
16. Data Boundary Testing
Tests Required
Select all that apply:
[ ] Data source approval check
[ ] Data classification check
[ ] Retrieval boundary test
[ ] Cross-user retrieval test
[ ] Cross-tenant retrieval test
[ ] Sensitive data prompt test
[ ] Sensitive data output leakage test
[ ] Prompt injection through retrieved content test
[ ] Vendor retention setting review
[ ] Training/reuse setting review
[ ] Output sensitivity review
[ ] Log sensitivity review
[ ] Cross-boundary transfer review
Test Results
Open Findings
17. Exceptions
Exceptions Required?
[ ] No
[ ] Yes
[ ] Unknown
Exception Summary
18. Approval
Data Owner Approval
Name:
Decision:
Date:
Notes:
Business Owner Approval
Name:
Decision:
Date:
Notes:
Privacy / Legal Approval, If Required
Name or forum:
Decision:
Date:
Notes:
Not applicable reason, if any:
Security / Architecture Approval
Name or forum:
Decision:
Date:
Notes:
Final Data Boundary Decision
Select one:
[ ] Approved
[ ] Approved with conditions
[ ] Approved for pilot only
[ ] Requires remediation
[ ] Requires exception approval
[ ] Requires additional review
[ ] Rejected
[ ] Deferred
Approval Conditions
[List conditions required before approval, production use, or scaling]
19. Review Triggers
Review this data boundary if any of the following occur:
[ ] Data source changes
[ ] Data classification changes
[ ] Vendor processing changes
[ ] Retention setting changes
[ ] Training/reuse setting changes
[ ] Retrieval logic changes
[ ] User population changes
[ ] Output use changes
[ ] Downstream workflow changes
[ ] Risk tier changes
[ ] Incident occurs
[ ] Assurance finding occurs
[ ] Regulatory or legal requirement changes
Next Review Date
[Enter date]
20. Summary
Use case:
Risk tier:
Data sources:
Highest data classification:
Retrieval boundary:
Vendor processing:
Retention:
Training/reuse:
Output sensitivity:
Required evidence:
Required testing:
Exceptions:
Approval status:
Next review date: