01 AI tools currently usedHow clearly do you know which AI tools your team is using?
Approved tools and owners are clear. Some tools are known, but use is partly informal. We are not sure which tools, plugins, or agents are in use.
02 Business data pasted into AI toolsWhat business data is being pasted or uploaded?
Only public or low-risk information. Some team notes, drafts, or process documents. Sensitive business data may be used without clear rules.
03 Customer or client data exposureCould customer or client information enter an AI tool?
No customer or client data is used. Only limited or anonymized examples are used. Identifiable customer or client details may be exposed.
04 AI use in public-facing contentHow is AI used before content is published or sent outward?
AI drafts are reviewed before anything is published or sent. Review usually happens, but standards are inconsistent. AI-assisted content can go out with little review.
05 Financial, legal, HR, health, or regulated decisionsDoes AI touch sensitive decisions or recommendations?
No. AI is not used for these decisions. AI may support research, but a person owns the decision. AI may influence advice, screening, eligibility, or outcomes.
06 Human review before publishing, sending, or actingWhat human review happens before AI output is used?
A named person reviews before publishing, sending, or acting. Review happens, but ownership is not always clear. AI output can move forward without accountable review.
07 AI tools or agents changing thingsWhat can your AI tools or agents do beyond drafting?
They can only read, draft, or summarize. They can trigger low-risk actions with limits. They can send, delete, deploy, bill, or change records.
08 Approval rules for high-risk actionsAre high-risk AI-assisted actions gated by approval rules?
Yes. Approval rules are written and understood. Some rules exist, but they are mostly informal. No clear approval rules exist yet.
09 Documentation and evidence of AI-assisted workflowsCan you reconstruct how AI was used in a workflow?
Yes. Tools, inputs, reviewers, and decisions are documented. Partly. Some notes exist, but evidence is inconsistent. Not reliably. There is little or no usable record.
10 Fallback when AI output is wrongWhat happens when AI output is wrong, risky, or incomplete?
There is a known correction or escalation procedure. People usually handle it, but the process is informal. There is no clear fallback procedure.