Free tool · AI Governance

How exposed is your AI estate?

15 questions. 5 governance domains. Instant results — including a domain radar chart, your risk band, and the top gaps in your current controls.

No account required. Results are calculated in your browser and not stored.

1 Model Accuracy & Reliability

Q1Are your AI model outputs validated against a known-good evaluation set before deployment?

Q2Do you monitor for output quality degradation or distributional drift in production?

Q3Is hallucination risk explicitly assessed and documented for each AI deployment?

2 Security & Adversarial Robustness

Q4Has your AI system been tested against adversarial prompt injection attacks?

Q5Is there a defined process for reporting and responding to AI security incidents?

Q6Are multi-turn attack patterns (not just single-turn) part of your red-team protocol?

3 Agentic AI & Autonomy

Q7Do your AI agents have explicitly bounded action scopes (least-privilege tool access)?

Q8Is there mandatory human review at defined checkpoints in agentic workflows?

Q9Are tool call logs and agent action traces reviewed for anomalous behaviour?

4 Governance & Accountability

Q10Does each AI deployment have a named risk owner accountable for that system?

Q11Is AI risk reviewed at board or executive committee level at least annually?

Q12Do you have a documented AI risk register linked to specific controls and evidence?

5 Regulatory & Compliance

Q13Are your AI systems explicitly mapped to applicable regulations (RBI/SEBI/EU AI Act/DPDP/DORA)?

Q14Is there a documented control effectiveness testing cadence for AI-related controls?

Q15Can you produce a full evidence trail for a regulator audit request within 48 hours?

Domain scores

Top 3 control gaps

Results are not stored. This assessment does not create an account or send your data anywhere. For a full assessment with evidence mapping and regulatory exposure, contact Zytra.