RAG Source Audit Template
Use this before uploading documents into a personal, team, or customer-facing RAG system.
| Source | Owner | Audience | Data sensitivity | Version / retrieval date | Authority | Approved tool/account? | Include? | Notes |
|---|---|---|---|---|---|---|---|---|
example-policy.pdf | Operations | Internal | Confidential | 2026-08-04 | Official | Yes | Yes | Record the next owner review. |
Sensitivity
- Public: safe for public use.
- Internal: company-only, no personal data.
- Confidential: customer, contract, financial, HR, product, or strategy data.
- Regulated: legal, medical, payment, government, or special-category personal data.
Include Only If
- The tool and account are approved for the source sensitivity.
- The document is current enough for the use case.
- The document is authoritative or clearly marked as opinion/background.
- The target audience is allowed to see the source.
- The RAG instructions tell the model to say when the source set does not answer a question.
- A known-answer and known-absence test has checked citation accuracy, coverage and unsupported claims for the intended language and feature.
- The source version or retrieval date and the product feature used are recorded so a later result can be reproduced.
Review Trigger
- The source owner sets a review date from the source’s change rate, consequences of staleness and any contractual or regulatory requirement; this template does not prescribe a universal monthly, quarterly or twice-yearly cadence.
- Re-check after a known source, permission, product, model, retrieval, citation or account-policy change.