Free assessment / 5–7 minutes
AI Tool Risk Assessment
Review data use, autonomy, human oversight and security safeguards.
How the scoring works
Method v1.0.0 is a custom, deterministic screening model. It has not been independently validated and is not an official ISO or NIST scoring scheme.
- Control gaps: implemented = 0, partial = 0.5, no or not sure = 1. Risk questions use the exposure values shown in your answer record. Weights are 1–3.
- Vendor and AI risk: 40% weighted exposure + 60% weighted control gaps. Scores are rounded to 0–100. Below 35 = low, 35–64 = moderate, 65–100 = high. Exposure remains even when controls are strong.
- Critical conditions trigger review or restrictions regardless of score. AI assessments also require review for any unknown answer or a score of 35 or above. Lower-risk use is not organizational approval.
- ISO QuickScan: equal-weight average implementation across 30 questions. Implemented with evidence = 100%, partial = 50%, no or not sure = 0%. Below 50 = early, 50–79 = developing, 80–100 = established foundation. These labels do not indicate conformity or certification readiness.
- Actions: a fully missing or unknown weight-3 control is high priority; other gaps of at least 75% are medium; remaining gaps are low. Mandatory review conditions always take precedence. There is no N/A option: evaluate controls proportionately for your stated scope.
These tools support initial planning, not legal advice, a formal audit or approval. QuickScan covers selected management and operational topics, not every ISO requirement or Annex A control.
Background: ISO/IEC 27001 and NIST AI Risk Management Framework. Questions and scoring are independently authored.