Free tool

Where your AI program really stands.

Eighteen plain questions about how your organization handles AI, grouped the way the US government's AI risk framework (the NIST AI RMF) groups them and mapped to the international standard ISO 42001. No email wall, nothing hidden. Rate each one honestly; your maturity level updates live and your weakest area is called out, so you know what to fix first. About five minutes.

Rating scale

0 None · 1 Ad hoc, case by case · 2 Defined, written down · 3 Managed, measured · 4 Optimized, improving on its own

Govern

who is in charge, and the rules they set
There is a written, leadership-approved AI policy that says what is and is not allowed, and people follow it.
Specific people are named as responsible for AI risk, and everyone knows who owns what.
Leadership reviews how AI is going on a regular schedule, not just when something breaks.
There are clear rules for which AI uses are allowed, which are limited, and which are off-limits.
Staff are trained to use AI well and responsibly, suited to their role.

Map

knowing what AI you have, and how risky it is
You keep an up-to-date list of the AI you use and the places it matters most.
Each AI use is rated for how risky it is, based on its impact, how much it acts on its own, and how sensitive its data is.
For each AI system you have written down what it is for and what could go wrong.
You account for AI from outside vendors too, including AI baked into the software you already buy.

Measure

testing it, and watching how it performs
AI is tested for accuracy, fairness, and safety before it goes live.
You have set targets for what counts as good enough on quality and risk, and you measure against them.
Once live, AI is watched for slipping accuracy, misuse, and problems.
You keep records and proof, so you can answer an auditor or regulator later.

Manage

staying in control once it is live
Each AI risk you find has a written plan to deal with it and a person responsible.
You have a plan for when AI goes wrong, and you have practiced it.
A person reviews the AI on decisions that carry real consequences.
AI is managed from launch to retirement, with control over changes and a clean way to shut it down.
What you learn feeds back in, so your rules and controls keep improving.
Your result
Level 1
Initial
0.0 / 4.0 average · 0 of 18 answered
By function

An honest self-assessment, not an audit. The gap is what a governance program closes.

The AI readiness assessment a consulting firm bills $5,000–$15,000 for — yours, free.

Market rate across 2026 pricing guides.

Scored yourself? The Expert Readiness Assessment validates these results against evidence and turns them into a roadmap you can defend.

Book a conversation →