Would your AI estate survive an audit next quarter?
Six control areas drawn from NIST AI RMF, EU AI Act expectations and established model risk practice — scored, banded and turned into the first three fixes.
Score each dimension
Answer as your organisation operates today, not as it is described in a strategy deck. Scores update the result live.
Is there a complete, current inventory of AI systems including embedded vendor features?
1 = no inventory · 5 = live inventory with owners, risk tier and purpose
Are models validated independently before deployment, with documented limitations?
1 = the build team self-certifies · 5 = independent validation with documented limits and sign-off
Do you know what data trains and grounds each system, and is its use lawful and documented?
1 = provenance unclear · 5 = documented lineage, lawful basis and retention per system
Are AI vendors assessed for data use, subprocessors, model changes and exit?
1 = standard software due diligence only · 5 = AI-specific due diligence with change notification and exit plan
Are accuracy, bias and drift monitored in production against defined thresholds?
1 = no production monitoring · 5 = threshold-based monitoring with automatic alerting
Is there a tested playbook for AI failures, harmful output and rollback?
1 = no AI-specific playbook · 5 = tested playbook with rollback and regulator notification paths
Core controls operate. Close the gaps in vendor AI risk and incident rehearsal before scaling higher-risk use cases.
Weighted average 3.00 of 5. Scores stay in the page link and the PDF — nothing is stored and no email is required.
Your prioritised next 90 days
Generated from your three weakest weighted dimensions.
- 01AI inventory — scored 3/5
Stand up a single AI inventory covering in-house models, embedded vendor AI and shadow usage, with a named owner and risk tier per entry.
- 02Model risk & validation — scored 3/5
Introduce independent validation gates proportionate to risk tier, with documented intended use, limitations and rejection criteria.
- 03Data privacy & provenance — scored 3/5
Document training and retrieval data lineage per system, confirm lawful basis and retention, and block unapproved data from grounding pipelines.
Inventory, validation, monitoring and incident response carry higher weight because they are the controls examiners test first. Directional self-assessment only — not legal advice.
Common questions
- Which frameworks does this reflect?
- The dimensions map to NIST AI RMF functions and the documentation, monitoring and human-oversight expectations of the EU AI Act, plus the model risk practices regulated firms already run under SR 11-7.
- Is this a compliance certification?
- No. It is a directional self-assessment to help leaders find the weakest control before an auditor or regulator does. It does not constitute legal advice.
- Who typically runs it?
- Risk, compliance and security leaders together with the AI platform owner. Scoring separately and comparing answers usually surfaces the real gaps faster than a joint session.