20 Questions · Yes or No
How much of your AI footprint can you actually see?
Answer each question based on your organization's current practices. A “No” response may indicate an area that requires further review, clearer ownership, or stronger controls.
Governance and Accountability
Does your organization have a documented AI governance framework?
Has executive ownership for AI governance and risk been clearly assigned?
Does a cross-functional group oversee AI-related decisions, including representatives from IT, Security, Legal, Compliance, Risk, and business leadership?
Are AI-related risks incorporated into your existing enterprise risk management program?
Policies and Employee Use
Does your organization have a formal acceptable-use policy that specifically addresses AI tools?
Are employees given clear guidance about what company, customer, or regulated data may be submitted to AI platforms?
Are employees required to use approved business accounts rather than personal accounts when accessing AI tools for work?
Does your organization provide ongoing employee training on safe and responsible AI use?
Visibility and Application Inventory
Does your organization maintain an inventory of approved AI applications, features, vendors, and integrations?
Can your organization identify unapproved or unauthorized AI tools being used by employees?
Are AI capabilities added to existing software platforms reviewed before they are enabled or adopted?
Can leadership receive meaningful reporting on how AI is being used across the organization?
Identity, Access, and Infrastructure
Are AI integrations reviewed using the principle of least privilege before access is granted?
Are permissions, access scopes, authentication tokens, and connected accounts for AI applications reviewed periodically?
Can your organization identify which email systems, file repositories, collaboration platforms, and business applications are accessible to AI tools?
Are technical controls in place to reduce the risk of sensitive information being submitted to unauthorized AI services?
Vendor, Privacy, and Compliance Risk
Do AI vendors complete security, privacy, legal, and compliance assessments before they are approved?
Does your vendor review process evaluate how AI providers store, process, retain, and use company data?
Monitoring and Response
Does your incident response plan include scenarios involving AI applications, vendors, data exposure, or compromised integrations?
Are AI adoption, governance maturity, vendor risk, security findings, and mitigation activities regularly reported to executive leadership or the Board?
Answer the remaining 20 questions to see where your organization stands.