Skip to content
ERICK TRUONG

Governance self-check

How good are your AI guardrails, really?

Twelve questions across the six areas a board, an auditor or a regulator will ask about. You'll get a score, the area to fix first, and the move I'd make this week.

About 4 minutes12 questionsNo account requiredYour answers never leave this browser

0 of 12 answered

Yes, partly, or no. Answer as things actually are, not as they are written down.

  1. 01 · Ownership

    One named executive is accountable for AI risk, not a committee.
    Every AI system we use has a named owner inside the business.
  2. 02 · Acceptable use and data

    Staff have a written policy on allowed, restricted and prohibited AI uses, and they have acknowledged it.
    People can name what data must never go into an AI tool.
  3. 03 · Visibility

    We keep an up-to-date register of AI systems in use, including tools teams adopted on their own.
    We would know within a week if a team started using a new AI tool on company data.
  4. 04 · Vendors

    AI vendors are assessed on security, data handling, training use and subprocessors before signature.
    Our contracts require notice before a vendor changes the model or how our data is used.
  5. 05 · Human review

    There is an agreed rule for what a human must review before output reaches a customer, a contract or a regulator.
    Reviewers know they are accountable, and have time allowed for the review.
  6. 06 · Monitoring and incidents

    Live AI systems are monitored after launch, with a review cadence and someone who reads the results.
    We could pause an AI system today, and we know who would be told.

12 questions left.

Want the detail behind these questions? The eight controls, and what the frameworks ask of you.