How ready is your AI governance?
About 3 minutes. Your answers never leave your browser.
The check is based on UACAF, our AI compliance framework.
This check scores your answers in your browser, so it needs JavaScript. You can also emailhello@secondkeysecurity.com and we will walk you through it.
About your AI use
How do you work with AI? Select all that apply.
Choose an answer.
Does any AI make or shape decisions about people's credit, employment, housing, insurance, healthcare or education?
Choose an answer.
Where do you operate or sell? Select all that apply.
Choose an answer.
Your controls
Answer for your company as it is today. A few more questions appear, depending on how you work with AI.
A named owner or council is accountable for AI decisions.
Choose an answer.
We have an approved AI acceptable-use policy, reviewed in the last 12 months.
Choose an answer.
We keep an inventory of all AI we use, including AI features inside SaaS tools and shadow AI.
Choose an answer.
Every AI system is risk-tiered, and prohibited uses are screened out.
Choose an answer.
Vendor contracts include AI terms (no training on our data, notice of model changes).
Choose an answer.
We do AI-specific due diligence before buying AI tools.
Choose an answer.
We have rules and technical controls on what data can go into AI tools.
Choose an answer.
We tell people when they interact with AI and label AI-generated content.
Choose an answer.
Humans review consequential AI outputs, and people can contest them.
Choose an answer.
We test AI for security issues like prompt injection.
Choose an answer.
AI agents have scoped permissions, human approval for consequential actions, and a kill switch.
Choose an answer.
We monitor AI systems and have an AI incident response process.
Choose an answer.
Staff are trained on safe and acceptable AI use.
Choose an answer.
We test AI that affects people for bias.
Choose an answer.
Our AI commitments to customers are documented.
Choose an answer.
Your results
%Level:
Starting is below 40%, Developing is 40% to 75%, and Established is above 75%. Snapshot taken .
Score by area
- Governance: %
- Inventory and risk: %
- Vendors and customers: %
- Data and transparency: %
- Oversight and fairness: %
- Security and agents: %
- Operations and training: %
Your top gaps
A named owner or council is accountable for AI decisions.
Set up a cross-functional AI governance group with an executive sponsor, a written charter, and clear decision rights.
UACAF control GOV-01
We have an approved AI acceptable-use policy, reviewed in the last 12 months.
Publish a leadership-approved AI policy that covers acceptable and prohibited uses, and review it at least once a year.
UACAF control GOV-02
We keep an inventory of all AI we use, including AI features inside SaaS tools and shadow AI.
Keep one inventory of every AI system, model, and agent, including AI features inside SaaS tools, with an owner and a risk tier for each.
UACAF control INV-01
Every AI system is risk-tiered, and prohibited uses are screened out.
Give every AI system a risk tier, record the reasons, and re-tier it when the system or its use changes.
UACAF control INV-03
Vendor contracts include AI terms (no training on our data, notice of model changes).
Add AI terms to vendor contracts: no training on your data without consent, and notice of incidents and model changes.
UACAF control TPR-02
We do AI-specific due diligence before buying AI tools.
Run the same AI due diligence on every vendor and AI feature before you buy: how your data is used, security, and incident history.
UACAF control TPR-01
We have rules and technical controls on what data can go into AI tools.
Apply your data classification rules to AI inputs and outputs, and keep confidential and regulated data in approved tools.
UACAF control DAT-05
We tell people when they interact with AI and label AI-generated content.
Tell people when they are dealing with an AI system, such as a chatbot or a voice agent, unless it is obvious.
UACAF control TRN-01
Humans review consequential AI outputs, and people can contest them.
Give people affected by an AI-driven outcome a way to contest it and get a human review, within a set time.
UACAF control HUM-04
We test AI for security issues like prompt injection.
Red-team your AI systems for prompt injection, data extraction, and tool misuse, and fix what you find before release.
UACAF control TEV-03
AI agents have scoped permissions, human approval for consequential actions, and a kill switch.
Set limits for each agent on the tools, data, systems, and actions it may use, deny everything else by default, and enforce the limits outside the model.
UACAF control AGT-01
We monitor AI systems and have an AI incident response process.
Add AI incidents to your incident response process, with severity levels, response playbooks, and root-cause analysis.
UACAF control MON-02
Staff are trained on safe and acceptable AI use.
Give AI training matched to each role: what AI can and cannot do, the risks, your policy, and when to escalate.
UACAF control LIT-01
We test AI that affects people for bias.
Test outcomes across groups before launch and on a set schedule, and record the results against thresholds.
UACAF control FAR-02
Our AI commitments to customers are documented.
Give customers AI-specific terms, an acceptable use policy, and clear commitments on how their data is used.
UACAF control PRD-02
You answered yes to every question, so this snapshot shows no gaps. A full assessment tests the evidence behind each answer.
Deadlines to watch
- EU AI Act high-risk (Annex III) obligations: December 2, 2027
- Colorado SB 26-189: January 1, 2027
- California ADMT rules: January 2027
As of September 2026. Confirm what applies to you with your counsel.
Next steps
Walk through your results with a partner.
Book a 30-minute review (opens in a new tab)A fixed-fee AI Governance Assessment against all 110 UACAF controls.
Ask about the full assessmentThe full UACAF framework: 110 controls, crosswalks and the assessment workbook. Free on request.
or email hello@secondkeysecurity.com
Want the full UACAF Assess tool?
Join early accessor email hello@secondkeysecurity.com
Get the full UACAF framework
UACAF, the Unified AI Compliance and Assurance Framework, is one set of 110 AI controls in 18 domains. Each control is mapped to NIST AI RMF, ISO/IEC 42001, the EU AI Act, the CSA AI Controls Matrix, the OWASP Top 10 lists for LLM and agentic applications, and US federal, state and sector rules.Read about the framework.
110 controls, crosswalks and the assessment workbook. Free on request.
or email hello@secondkeysecurity.com
A readiness snapshot based on UACAF v1.0, created by Dr. Abe Okomanyi, Second Key Security. Not legal advice or certification.