Question 1
Do you have a current inventory of every AI system in production in your organization? Including third-party tools that use AI under the hood.
Yes — written down, kept current, owner per system Partial — we have a list, but it's probably out of date Informal — we mostly know what's running but it's not documented No
Question 2
For each AI system, can you point to where the claimed capabilities are documented? Product pages, model cards, contracts, internal specs.
Yes — each system has documented capability claims Some do, some don't The claims exist (marketing, sales decks) but aren't cross-referenced No
Question 3
Is there evidence that the AI has been tested against those claims? Yes — written test results we could hand to a regulator Tested internally, but the results aren't formally documented Vendor-provided test data only No formal testing
Question 4
Is the AI's behavior monitored once it's in production? Outputs sampled, drift watched, escalation paths defined.
Yes — with alerts and a named owner Logged but not actively reviewed Only if someone complains No
Question 5
Do you know where the AI fails? Documented edge cases, known failure modes, scenarios where it shouldn't be used.
Yes — documented and communicated to users We have some idea but it's not written down We find out when it fails No
Question 6
Does your organization have a written AI policy? Acceptable use, restricted use cases, approval gates, vendor requirements.
Yes — written, approved, and enforced Written but not consistently followed In draft No
Question 7
When AI vendors require new contract language (DPAs, AI addenda, audit rights), are you ready? Yes — we have standard positions and fallback positions We handle them case by case They cause delay and uncertainty every time We haven't encountered these yet
Question 8
How prepared are you for AI-specific regulatory disclosure? EU AI Act, state-level US disclosure laws, sector regulators.
Tracked, with a written response plan We know it's coming, working on it Vaguely aware, no concrete plan Not on our radar
Question 9
If your board asked tomorrow "what is our AI risk exposure", how long would it take to answer? We have a current written answer ready Days — we could pull it together Weeks — significant work needed We wouldn't know how to start
Question 10
Who currently provides independent assurance that your AI is doing what you say it does? Independent reviewer / external audit Internal audit / compliance team The team that built it Nobody