RICS AI standard compliance checklist: 12 things to have in place
A practical 12-point checklist for complying with the RICS AI standard — knowledge, registers, policies, due diligence, client notices, output reviews and the records behind each.
How do you comply with the RICS AI standard? In practice, by being able to show twelve things — each traceable to a requirement in Responsible use of artificial intelligence in surveying practice (effective 9 March 2026). Use this as a gap analysis: tick what you can produce today, and diarise the rest.
Knowledge and scope
- Baseline AI knowledge for anyone using AI on services — a basic understanding of how the systems work, their limitations and failure modes, error and bias risks, and data risks (section 2). A short internal session or CPD course, with attendance recorded, covers this.
- A tool inventory — you know every AI system in use, including embedded and free tools. Most firms discover more than they expect; see where AI hides in QS workflows.
Practice management (section 3)
- A written appropriateness assessment — why AI is the right tool for each use, considering alternatives, data risks, error and bias, environmental and stakeholder impacts (3.2). A periodically reviewed written policy or standing statement is acceptable.
- An AI systems register — system, purpose, date first used, next review date, for every materially-used system (3.2). Free template on that page.
- A responsible-use policy — covering third-party and internally developed AI, informed by the risk register (3.2).
- Data governance rules — what may be put into which tools, and how outputs are handled (3.1).
- An AI risk register — RAG-rated risks with mitigation plans, reviewed at least quarterly by the people responsible for AI decisions (3.3).
Using AI on instructions (section 4)
- Written supplier due diligence before relying on a materially-impacting system — written information requests, recorded answers, recorded fitness-for-purpose testing; gaps logged as risks (4.1).
- Recorded materiality determinations — the decision and the reasoning, per use (1.2).
- Written reliability decisions on outputs — by or under a named, appropriately qualified surveyor; dip sampling for automated or high-volume use (4.2).
- Client notices and updated terms of engagement — in writing, in advance, where use is material; six specific items in engagement documents (4.3).
- Explainability information ready on request — the system used, how it works and its limits, the due diligence done, how risks are managed, and the reliability decisions made (4.4).
Scoring yourself
Most practices we speak to can produce two or three of the twelve on a good day — usually the policy, some training and good intentions. The pattern to aim for: every item exists in writing, has an owner, and has a review date. If an item exists only in someone's head or inbox, it fails the “could you hand it over tomorrow?” test.
Do I need all twelve if we barely use AI?
The obligations attach to AI use with a material impact on service delivery. If genuinely nothing you use is material, the heavy items (register entries, notices, output reviews) may be empty — but you still need the assessment, policy and knowledge base that let you say so credibly, and a register/risk process ready for when a material tool arrives.
How long does this take a small firm?
With templates: the register in an hour, a first policy in an afternoon, due-diligence letters as tools come up for review. The recurring cost is the quarterly risk review and per-project decisions — which is exactly the part worth systematising.
ComplyQS is this checklist as a workspace: the registers, decisions, notices and audit trail, generated from what you record as you work — with the quarterly reviews nudged automatically.
Work through it free for 180 daysThis checklist is general information, not legal or professional advice, and summarises requirements — always check the published standard. ComplyQS is not affiliated with or endorsed by RICS.