AGAI Governance Starter Kit Runs privately in your browser
Free assessment for SMEs & nonprofits

Turn responsible AI
from intention into action.

Answer 12 practical questions. Get a readiness score and a prioritized 90-day governance plan—without sending your answers anywhere.

NIST AI RMFOWASP GenAIPrivacy-first~5 minutes
Govern01

A named person or group owns AI governance.

Accountability should be clear even in a small organization.

Govern02

We have an approved policy for acceptable AI use.

The policy covers permitted tools, prohibited data and employee responsibilities.

Map03

We maintain an inventory of AI tools and use cases.

Include free tools, embedded features, pilots and vendor-supplied AI.

Map04

Each AI use case has a documented purpose, owner and affected users.

This helps expose unclear ownership and unintended impacts.

Protect05

Employees know what data must never be entered into public AI tools.

Examples include personal, confidential, regulated and commercially sensitive data.

Protect06

Our AI rules align with our data-classification scheme.

AI guidance should translate labels into simple handling rules.

Measure07

We assess AI vendors for privacy, security and data retention.

Review training use, subprocessors, access controls, deletion and incident terms.

Measure08

Higher-risk AI use cases receive a documented impact assessment.

Prioritize decisions affecting people, money, access, safety or legal rights.

Manage09

Important AI outputs require human review before action.

The reviewer should have authority and enough knowledge to challenge the output.

Manage10

Employees receive practical AI literacy and safety training.

Training includes verification, privacy, bias, copyright and incident reporting.

Manage11

Staff know how to report an AI-related error or security incident.

Use an existing incident channel where possible.

Manage12

AI tools and controls are reviewed at least annually or after major change.

Review sooner after a serious incident, new regulation or material model update.

01

Find the gaps

See where informal AI use is creating avoidable governance, privacy and security risks.

02

Prioritize action

Focus on the five improvements that matter most instead of starting with a large framework.

03

Start the conversation

Use the downloadable plan with leadership, IT, security, HR, legal and operational teams.