Know exactly what to send when your customer asks how you govern AI
Your customer expects you to hold 11 governance documents. This free check tells you which ones you already have, which are missing, and which 3 to write first.
Most companies stop at the question that asks them to attach a policy
That question arrives inside the security questionnaire every large company sends its suppliers before signing or renewing anything, and this year those questionnaires started carrying a section on AI.
This is the one that stops people
Nobody can produce that third one on the day it arrives. It asks for three documents, and all three had to be written before the form was ever sent.
You attach them, send the reply the same day, and the contract carries on.
Someone at that company records you as an open risk, and then has to explain you to their manager.
In 3 minutes you go from guessing to knowing
The way out is not to write all 11 documents tonight. It is to find out which ones you already hold, which are genuinely missing, and which 3 to start with. Nine questions is enough to work that out.
- ×No written list of the AI tools your staff actually use
- ×No rule telling them what they may put into those tools
- ×Nobody named as responsible when something goes wrong
- ×Nothing you could attach to the reply
- ✓All 11 documents named, and yours marked as in place, partly there or missing
- ✓The 3 to write first, ordered by what unblocks the most other work
- ✓What each document is for, in words you can repeat to your team
- ✓A page you can print and send to whoever asked
Here is that page, and you see it before you give us anything
It appears the moment you answer the last question, with no email and no account in between. This one belongs to a company that had made a start and still had work to do. Everything in it is the real report, not a sample cut short.
You have made a real start, with 6 documents still missing. Close them in the right order and the rest gets easier.
You do not have to take our word for any of this
Free usually means somebody is selling your details, and a compliance tool from a company you have never heard of deserves exactly that suspicion. So rather than ask you to trust us, here are four things about this one you can check for yourself.
Possible answers, every one tested
That is every possible route through the 9 questions. All of them were run and checked for a sensible result before the tool went live, so your report is not being worked out for the first time when you press the button.
It will not call you compliant
A test blocks the words "compliant", "certified" and "guarantee" from appearing anywhere in your report. A questionnaire cannot establish any of those, and anything telling you otherwise is selling you something.
Real documents, not an invented list
The list comes from ISO/IEC 42001, the international standard for managing AI, and that is the one your enterprise customers have started naming in their contracts.
Trackers, accounts and emails required
No cookies, no advertising trackers and no third-party analytics. If the report turns out to be useless to you, you close the tab and you have lost 3 minutes.
If you hold ISO 27001, you have already written most of this
ISO 42001 asks for the same kinds of documents, in the same order, as the security standard you already run. Your scope statement, your risk method, your treatment plan and your audit programme each get widened to cover AI rather than written again from an empty page.
So a list of 11 stops looking heavy once you find out how much of it you have already written. The check works that out from your answers and names the ones you can extend.
7 of the 11 documents extend something you already maintain
The remaining 4 are genuinely new, and the report names them, so you know precisely where the real work sits. Holders of ISO 9001 or SOC 2 get their own shorter version of the same shortcut.
All 11 in one line each, so nothing hides behind a long name
The official titles are the intimidating part. This is what each document actually has to say.
Three steps, and nothing is asked of you in between
Answer 9 questions
Every question is multiple choice and written in plain words, and "not sure" is always one of the options. Not knowing is itself a finding, so a guess would only spoil your own result.
Read it immediately
Your result appears the moment you answer the last question. You do not hand over an email first, and there is nothing to sign up for before you see what you came for.
Fix the 3 that matter
The report puts the 3 that unblock the most other work at the top. Close those first and everything after them turns out to be shorter than it looks today.
The five things people want to know before they start
Are you trying to sell me something?
There is nothing to buy on this site today. At the end you can leave an email address if you want to hear about a paid version that writes the missing documents for you, and that is optional. Skip it and you still keep the whole report.
We are just 11 people. Does any of this apply to us?
Size decides how much of it applies, not whether it applies. The check marks several documents as not yet needed at your stage, which is useful in itself, because it tells you what you can safely leave alone for now.
What if I do not know the answers?
"Not sure" is one of the options on every question, and choosing it is treated as a real answer rather than a blank. If nobody in the company knows whether a policy exists, then in practice it is not being followed, and the report says so.
Do you store my answers, and can anyone see them?
Your answers are worked out in your browser, so the result appears without anything being sent anywhere first. We store the answers and the score with no name attached, and we use no cookies and no third-party tracking. The privacy page explains all of it in full.
Will this make us compliant?
No, and it will never claim to. This compares your answers against a published checklist and shows you the gaps. It is not an audit, not a certification, and not legal advice. Whether a particular obligation applies to you depends on your jurisdiction and sector, and that question sits outside what this does.
We are checking whether this is worth building before we build it
The check is finished and it works. The part that does not exist yet is the one people keep asking for. It writes the missing documents for you, filled in for your own company rather than handed over as a blank template.
That is weeks of work, so we would rather find out whether anyone wants it before spending them. The check is free because it is how we find out.
If you want it, there is a line at the end of your report where you can say so. If you do not, take the report and go, and you have still had the useful part.
If you would rather read than answer questions
Three of these each take one of the 11 documents and cover it in full, with what goes into it and what to leave out. The fourth is for companies that already hold ISO 27001 and are wondering how much of this they have done already.
Find out tonight, rather than when the form arrives
The questionnaires are already going out. Knowing where you stand costs you 3 minutes and nothing else.