AI governance

Is your use of AI under control?

A 13-question self-assessment to measure your exposure to AI and how solid your framework is, then target your priority risks and the policy components that cover them.

About 5 minutes · 2 axes · 13 questions

This self-assessment is based on your answers. It helps you target what to look at first; it is not a compliance validation.

The calculation runs on your device and nothing is sent without your consent.

Part 1

Your company

To put your results in context.

Sector
Number of employees

Part 2

Your use of AI

How widely AI is used and how sensitive the data it touches is.

To what extent do your employees use AI tools (ChatGPT, Copilot, etc.)?
What data does AI touch in your organization?

Check all that apply.

Do you use AI for decisions about people (hiring, credit, access to a service)?
Where are the AI tools that process your company's data hosted?

Think of the tools used most: ChatGPT, Copilot, Gemini, AI features in your software.

On the business side:

Check what applies.

Part 3

Your framework

The rules, tools and habits already in place.

Do you have an inventory of the AI tools used in the organization?
Do you have a written policy or directive on the use of AI?
Do you control which tools are allowed, with company accounts rather than personal accounts?
Have your employees been trained in the responsible use of AI?
Do you have a designated person and a process for incidents involving AI or data?
Are AI outputs checked by a person before any significant use?
Before entrusting personal information to a tool hosted outside Quebec, do you assess the risks and the contractual protections?
Do you know whether your AI vendors use your data to train their models, and how long they keep it?

Answer every question to see your results.