How this works
Answer 28 questions across eight areas — AI inventory, vendor and model supply chain, prompt injection and input handling, data protection, access control and agentic systems, monitoring and drift, incident readiness, and governance. Each takes 10–20 seconds.
Questions are weighted: the foundational disciplines count for more, because every other control depends on them. At the end you'll get a maturity score, a band, a breakdown by area, and a recommended set of priority actions. The questions reflect widely recognised AI security practice; which recommendations fit your organisation is your call.
Part 1 — AI Inventory & Shadow AI
Do you know what AI you actually have?
An inventory is the foundation: every other control scores against an unknown denominator without one. AI arrives through individual sign-ups and embedded features, not just procurement.
Shadow AI surfaces faster when disclosure is easy and unpunished. An email address and a 48-hour response commitment is enough to start.
The most common AI incident is sensitive data pasted into a tool nobody had catalogued, under terms nobody had read.
A list that was current last quarter but cannot be maintained is a snapshot, not an inventory.
Part 2 — Vendor & Model Supply Chain
What you buy is part of your attack surface.
The training-data clause is the most consequential line in an AI vendor's terms, and it changes without ceremony. Someone has to be reading it.
Standard vendor reviews miss the AI-specific risks: model provenance, tenant isolation, prompt-injection testing, retention of prompts and outputs.
A model update can change behaviour, safety posture, and output quality overnight. Notification terms make the change visible instead of mysterious.
Base models, weights, and datasets are dependencies like any package. Provenance and integrity checks apply to them too.
Part 3 — Prompt Injection & Input Handling
Any text a model reads can carry instructions.
Prompt injection rides on any text the model reads, not just the chat box. Defensive work fails most often because the map of entry points was wrong.
There is no privilege bit inside a prompt. Structured prompting and delimiters help; the architecture should survive the day they don't.
Output checks catch leaked system prompts and injected behaviour before the result lands somewhere consequential.
An hour of honest adversarial testing typically finds what a year of normal use will not.
Part 4 — Data Protection in AI Pipelines
What goes in, stays somewhere.
One page is enough: personal data, client content, credentials, confidential documents. The rule only works if people have read it.
Training data is a data asset like any other — classification, handling, and provenance discipline applies. What goes into the data becomes the model's behaviour.
Prompts and outputs are records containing whatever went into them. Retention you can state is retention you can defend.
Part 5 — Access Control & Agentic Systems
Who — and what — can act through your AI?
A departed freelancer with surviving access to a voice-cloning tool is an incident waiting for a motive. AI accounts deserve the same hygiene as email.
Most agentic deployments have over-broad tool grants because nobody scoped them at wiring time. Small grants make small blast radii.
Anything hard to reverse — payments, external messages, deletions — deserves a pause with a human in it, confirmed with full context.
Part 6 — Monitoring & Drift
Would you notice when behaviour changes?
Running a model without input/output logging is running a web server without access logs: incidents still happen, you just can't investigate them.
AI incidents often look like gradual degradation rather than an alert. Behaviour monitoring with thresholds turns "someone noticed something odd" into an alarm.
Monitoring nobody reads is storage. A named reviewer and an escalation threshold make it a control.
Part 7 — Incident Readiness
The first thirty minutes need a page to follow.
AI incidents differ enough — unusual evidence, unusual containment — that the general IT plan won't carry you. The first thirty minutes need a page, not improvisation.
Containment for AI looks different: rollback, capability disable, traffic re-route. Knowing the moves beforehand is most of the speed.
AI incidents increasingly carry notification clocks. A defined assessment step keeps a technical incident from quietly becoming a regulatory one. Confirm specifics with legal counsel.
A tabletop finds the gaps on a quiet Tuesday instead of mid-incident. Three people and one scenario is enough to start.
Part 8 — Governance & Reporting
Ownership is the control the others hang from.
Without a named owner, AI security is everyone's concern and nobody's job. At small scale this is a hat, not a hire.
The policy is the agreement between the organisation and its people about how AI gets used. Unread policies govern nothing.
What leadership never sees, leadership never funds. A short quarterly note beats a perfect annual deck.
Answer all 28 questions to see your report.
Your AI Security Maturity Results
Your Recommended Priority Actions
Ranked by weight: the gaps that the rest of your AI security practice depends on come first. Every action is a recommendation — which ones fit your organisation is your call.
The First 5 AI Security Fixes
A plain-English guide to the five fixes that close the riskiest gaps this assessment finds most often — the AI tool inventory, the training-data clause, the never-paste list, the access clean-up, and the kill switch. Enter your email and we'll send it over.
Optional, and separate from your assessment — your assessment answers are never sent, only the email address you choose to enter here. Unsubscribe anytime.
Where to go from here
The free assessment shows where you stand. The paid editions give you the working documents — registers, runbooks, questionnaires, and board packs — so you have the artefacts, not just the score. All paid editions are a one-time purchase with free updates while in our catalogue and a 30-day money-back guarantee.
For the one person who owns AI security alongside everything else. Inventory register, acceptable-use policy, shadow-AI discovery checklist, small-team vendor check.
See the Solo Edition →For the first AI security lead with a team around them. Full vendor due-diligence set, AI incident runbooks, asset register and model-risk classification, prompt-injection defence checklist.
See the Team Edition →For the programme that answers to a board. Ten-dimension maturity rubric, governance and board reporting pack, tabletop exercise kit, model-risk audit and regulatory readiness map.
See the Enterprise Edition →