HOW THE CHECK WORKS
Clear questions.
Transparent results.
The AI Exposure Check helps you understand your reported AI practices and the things you still need to find out. It is a starting point for a review.
Questionnaire v1 · Rules v1 · Published September 16, 2026
What it does and does not do
Ten questions cover tools, data, access, ownership, and oversight. Each answer maps to a written explanation and a practical next step. The check uses local rules. No AI model generates your results.
This check uses your answers. It does not inspect your systems or verify your security or compliance. It does not discover tools, access accounts, verify vendor settings, or provide legal advice, certification, or independent assurance.
How we describe your answers
| Your answer | Result label | What it means |
|---|---|---|
| Yes | Reported in place | You say this practice exists. Keep supporting information current. |
| Partly | Incomplete | Some work is in place. Finish the missing parts. |
| No | Reported gap | You report a missing practice or review. This does not imply a breach or unlawful conduct. |
| Not sure | Unknown | Confirm what is in place with the people responsible. |
| Not applicable | Not applicable | Only available for Q9. You report no AI-assisted decisions about customers or employees. Q9 is excluded from applicable counts. |
Unknown use should be answered “Not sure,” not “Not applicable.” All ten questions must have an explicit answer before results are generated.
How we choose starting actions
We suggest up to three actions from answers marked Partly, No, or Not sure. This is a review order, not measured risk severity.
- Data handling and access reviews come first: Q3 through Q6.
- Tool inventory and existing software features come next: Q1 and Q2.
- Ownership and oversight follow: Q7 through Q10.
Within each group, “No” comes first, then “Not sure,” then “Partly.” Question order breaks ties. All findings remain available below the starting actions.
If every applicable answer is Yes, we suggest keeping records current. If every applicable answer is Not sure, we recommend establishing an inventory and involving the people responsible for systems and data. No outcome means your business has been verified as safe or compliant.
The questions
- Q1 · Tools
Do you have a current list of AI tools used for company work, including tools people adopted themselves?
- Q2 · Tools
Have you checked the AI features included in the software your company already pays for?
- Q3 · Data
Have you documented which kinds of company or customer information people enter into AI tools?
- Q4 · Data
Have you reviewed how your AI providers handle stored information and model training for the plans you use?
- Q5 · Access
Have you reviewed the files, email, or other systems that connected AI tools can access?
- Q6 · Access
Have you set and communicated rules for using personal AI accounts for company work?
- Q7 · Ownership
Is someone clearly responsible for approving new AI tools and uses?
- Q8 · Ownership
Does your team have written, practical guidance on acceptable AI use?
- Q9 · Oversight
Where AI influences decisions about customers or employees, is a person responsible for reviewing its output?
- Q10 · Oversight
Does your team know who to contact if AI exposes information, gives a harmful answer, or takes an unexpected action?
Sources and scope
The NIST AI Risk Management Framework 1.0 is a useful broader reference: Govern 1.6 addresses AI system inventories, Govern 2.1 addresses responsibilities, and Map 1.1 addresses the context of use. It is a voluntary framework.
Syndesi wrote this questionnaire and its review order. The questions are not a NIST assessment, a complete framework mapping, or a measure of conformity. Referencing NIST does not imply endorsement. For a practical next step, read our AI inventory guide.
Who is behind it
AI Audit is built and published by Syndesi. It is not an independent assessor or certification body. The free check can lead to an optional AI Risk and Readiness Review with Syndesi, where the scope and price are agreed separately.
A paid review gathers evidence beyond these answers and should distinguish verified findings, reported information, and remaining unknowns. Formal legal or independent assurance work belongs with the appropriate professionals. Read our ownership and publishing information.
