AI Governance Gap Check

Know exactly what to send when your customer asks how you govern AI

Your customer expects you to hold 11 governance documents. This free check tells you which ones you already have, which are missing, and which 3 to write first.

Free
No email, no account, and nothing to cancel afterwards.
3 min
You answer from what you already know about your own company. Nothing to look up, no file to find.
2,867,202
Every possible set of answers was tested before this went live. Nobody reads your report except you.
Exhibit 01 The moment this matters

Most companies stop at the question that asks them to attach a policy

That question arrives inside the security questionnaire every large company sends its suppliers before signing or renewing anything, and this year those questionnaires started carrying a section on AI.

Supplier assurance · section 7 of 9
From: Vendor Risk, at a customer you cannot afford to lose
Artificial intelligence and automated decision making
1Do you use artificial intelligence in the delivery of services to us?
2List every AI system in scope, including tools embedded in third-party software.
3Attach your AI policy, your risk assessment, and the name of the individual accountable for AI risk.
This is the one that stops people
4Describe the human oversight applied to AI output before it reaches us.

Nobody can produce that third one on the day it arrives. It asks for three documents, and all three had to be written before the form was ever sent.

If you have them

You attach them, send the reply the same day, and the contract carries on.

If you leave it blank

Someone at that company records you as an open risk, and then has to explain you to their manager.

Exhibit 02 What changes

In 3 minutes you go from guessing to knowing

The way out is not to write all 11 documents tonight. It is to find out which ones you already hold, which are genuinely missing, and which 3 to start with. Nine questions is enough to work that out.

Right now
  • ×No written list of the AI tools your staff actually use
  • ×No rule telling them what they may put into those tools
  • ×Nobody named as responsible when something goes wrong
  • ×Nothing you could attach to the reply
3 minutes later
  • ✓All 11 documents named, and yours marked as in place, partly there or missing
  • ✓The 3 to write first, ordered by what unblocks the most other work
  • ✓What each document is for, in words you can repeat to your team
  • ✓A page you can print and send to whoever asked
Exhibit 03 What you get back

Here is that page, and you see it before you give us anything

It appears the moment you answer the last question, with no email and no account in between. This one belongs to a company that had made a start and still had work to do. Everything in it is the real report, not a sample cut short.

39 out of 100 Early stage

You have made a real start, with 6 documents still missing. Close them in the right order and the rest gets easier.

AI system inventoryPartly
AI policyPartly
Roles and responsibilitiesMissing
Operational proceduresMissing
AI impact assessment processMissing
Statement of ApplicabilityNot yet needed
Show the remaining 5 documents and a full explanation
AIMS scope statementMissing
AI objectivesMissing
AI risk assessment methodologyPartly
AI risk treatment planMissing
Internal audit programmeNot yet needed
AI policy, marked Partly. The document exists but staff have not been told about it. If an incident happened tomorrow the policy would not have changed anyone's behaviour, and that is the first thing an assessor probes.
Do these 3 first. The AI system inventory, because every other document describes systems you have not yet listed. Then the AI policy, because it is the most requested and the cheapest to produce. Then roles and responsibilities, because without an owner every document you write goes stale.
Exhibit 04 Why you can trust it

You do not have to take our word for any of this

Free usually means somebody is selling your details, and a compliance tool from a company you have never heard of deserves exactly that suspicion. So rather than ask you to trust us, here are four things about this one you can check for yourself.

2,867,202

Possible answers, every one tested

That is every possible route through the 9 questions. All of them were run and checked for a sensible result before the tool went live, so your report is not being worked out for the first time when you press the button.

Never

It will not call you compliant

A test blocks the words "compliant", "certified" and "guarantee" from appearing anywhere in your report. A questionnaire cannot establish any of those, and anything telling you otherwise is selling you something.

11

Real documents, not an invented list

The list comes from ISO/IEC 42001, the international standard for managing AI, and that is the one your enterprise customers have started naming in their contracts.

0

Trackers, accounts and emails required

No cookies, no advertising trackers and no third-party analytics. If the report turns out to be useless to you, you close the tab and you have lost 3 minutes.

Exhibit 05 The shortcut

If you hold ISO 27001, you have already written most of this

ISO 42001 asks for the same kinds of documents, in the same order, as the security standard you already run. Your scope statement, your risk method, your treatment plan and your audit programme each get widened to cover AI rather than written again from an empty page.

So a list of 11 stops looking heavy once you find out how much of it you have already written. The check works that out from your answers and names the ones you can extend.

7 of the 11 documents extend something you already maintain

The remaining 4 are genuinely new, and the report names them, so you know precisely where the real work sits. Holders of ISO 9001 or SOC 2 get their own shorter version of the same shortcut.

Exhibit 06 Everything covered

All 11 in one line each, so nothing hides behind a long name

The official titles are the intimidating part. This is what each document actually has to say.

01Every AI tool in use, and who uses it
02Which parts of the business are covered
03What staff may and may not put into AI
04What you are trying to achieve
05Who answers when something goes wrong
06How you decide what could go wrong
07What you are doing about each risk
08The effect on the people it touches
09How a person catches a wrong output
10Which controls apply, and why the rest do not
11How you check your own governance
Exhibit 07 How it works

Three steps, and nothing is asked of you in between

1

Answer 9 questions

Every question is multiple choice and written in plain words, and "not sure" is always one of the options. Not knowing is itself a finding, so a guess would only spoil your own result.

2

Read it immediately

Your result appears the moment you answer the last question. You do not hand over an email first, and there is nothing to sign up for before you see what you came for.

3

Fix the 3 that matter

The report puts the 3 that unblock the most other work at the top. Close those first and everything after them turns out to be shorter than it looks today.

Exhibit 08 Before you start

The five things people want to know before they start

Are you trying to sell me something?

There is nothing to buy on this site today. At the end you can leave an email address if you want to hear about a paid version that writes the missing documents for you, and that is optional. Skip it and you still keep the whole report.

We are just 11 people. Does any of this apply to us?

Size decides how much of it applies, not whether it applies. The check marks several documents as not yet needed at your stage, which is useful in itself, because it tells you what you can safely leave alone for now.

What if I do not know the answers?

"Not sure" is one of the options on every question, and choosing it is treated as a real answer rather than a blank. If nobody in the company knows whether a policy exists, then in practice it is not being followed, and the report says so.

Do you store my answers, and can anyone see them?

Your answers are worked out in your browser, so the result appears without anything being sent anywhere first. We store the answers and the score with no name attached, and we use no cookies and no third-party tracking. The privacy page explains all of it in full.

Will this make us compliant?

No, and it will never claim to. This compares your answers against a published checklist and shows you the gaps. It is not an audit, not a certification, and not legal advice. Whether a particular obligation applies to you depends on your jurisdiction and sector, and that question sits outside what this does.

Exhibit 09 Why this costs nothing

We are checking whether this is worth building before we build it

The check is finished and it works. The part that does not exist yet is the one people keep asking for. It writes the missing documents for you, filled in for your own company rather than handed over as a blank template.

That is weeks of work, so we would rather find out whether anyone wants it before spending them. The check is free because it is how we find out.

100 people asking for it is the number we set before we started. Reach it and we build the full version.

If you want it, there is a line at the end of your report where you can say so. If you do not, take the report and go, and you have still had the useful part.

If you would rather read than answer questions

Three of these each take one of the 11 documents and cover it in full, with what goes into it and what to leave out. The fourth is for companies that already hold ISO 27001 and are wondering how much of this they have done already.

Find out tonight, rather than when the form arrives

The questionnaires are already going out. Knowing where you stand costs you 3 minutes and nothing else.