A 40-point self-assessment for engineering organisations deploying AI tools. It is informed by NIST AI RMF 1.0, OWASP GenAI LLM Top 10 2026, ICO guidance, and practical controls across data, vendors, human oversight, AI literacy, and incident response. It supports structured review; it is not a certification or legal opinion.
Identifying and classifying every AI system in your organisation before broader governance can apply
Ensuring AI deployments comply with UK GDPR, US privacy laws, and data residency obligations
You can self-assess the first two categories natively. To reveal the full governance assessment, covering Security Controls, IP & Copyright, Human Oversight, AI Literacy, Vendor Risk, and Incident Response, plus the board-ready remediation brief, enter your institutional email below.
Defending against the specific attack vectors introduced by LLM and agentic AI systems
Managing the ownership and legal risk of AI-generated code and content in your codebase
Maintaining meaningful human control and audit trails across AI-assisted decision making and delivery
Ensuring your engineering organisation can use AI tools safely, effectively, and responsibly
Evaluating and managing the concentration risk and exit costs of your AI tool stack
Being operationally prepared to detect, contain, and communicate AI-specific security and quality incidents