Free tool · ~10 minutes

AI Risk Readiness Check

Twelve questions, three per NIST function. Answer honestly — the point is finding the gap, not passing the quiz. Nothing is sent anywhere until you choose to email yourself the results.

0 of 12 answered

GOVERN

1. Is there a named individual or committee accountable for approving new AI systems before deployment?

GOVERN

2. Does the board or senior leadership receive regular reporting on AI risk?

GOVERN

3. Is there a written AI governance policy in active use — not just on file?

MAP

4. Do you maintain a current inventory of every AI system in production, including vendor-embedded tools?

MAP

5. For each AI system, is its purpose and the population it affects documented?

MAP

6. Have you classified your AI systems by risk tier (e.g., under the EU AI Act or an internal equivalent)?

MEASURE

7. Are AI systems that affect credit or lending decisions tested for disparate impact on a regular schedule?

MEASURE

8. Is model performance (accuracy, drift) monitored on an ongoing basis, not just at launch?

MEASURE

9. Are security and robustness considerations tested before an AI system goes live?

MANAGE

10. Is there a documented incident-response process specific to AI system failures or vendor model updates?

MANAGE

11. Is there a defined process for retiring or rolling back an AI system?

MANAGE

12. Are AI-related risks reviewed and updated at least annually?

Your results

GOVERN
0
out of 6
MAP
0
out of 6
MEASURE
0
out of 6
MANAGE
0
out of 6

This is a directional self-check, not an audit. If your lowest score is where you'd expect an examiner to ask the hardest question, that's the honest starting point for a conversation.

Discuss my results — book a 20-minute call