Kilwhiss AI Assurance · free five-minute check

Move from AI experimentation to governed deployment.

Start with the free AI Exposure Check. Identify gaps in oversight of AI tools, agents and shadow AI, then see which controls need attention before deployment and throughout the AI lifecycle.

No sensitive details requestedImmediate indicative resultThree priority actions

Your assessment

Four clear sections. One immediate result.

Answer what you know. “Not sure” is useful, it identifies where visibility or evidence may be missing.

20 core questions · agent questions appear only when relevant
01

About your organisation Not scored

Basic context used to frame your result.

Has a customer, tender team, insurer, auditor or board member asked about your AI controls?

Does any AI system use tools, access connected services, retain working memory or perform actions?

02

Visibility and shadow AI

Where AI is being used and whether leadership can see it.

Do staff use ChatGPT, Copilot, Gemini, Claude, meeting assistants or other AI-enabled tools for work?

Could staff be using personal or free AI accounts for business activity?

Does the organisation maintain a current list of approved AI systems, embedded features and use cases?

Has the organisation actively checked for unapproved or previously unknown AI use?

Is there a simple route for staff to request, disclose or report a new AI tool or use case?

03

Data, people and decisions

What enters AI systems and how outputs affect people.

Could confidential, commercially sensitive, personal or special-category information enter an AI system?

Is AI used to score, recommend, prioritise or influence decisions affecting people?

Are material outputs checked by a trained person before being relied upon or communicated externally?

Have supplier data use, retention, model-training, hosting and subprocessor terms been reviewed?

Are access, identity, leaver and least-privilege controls applied to approved AI services?

04

Governance and lifecycle monitoring

How AI is approved, monitored, changed and retired.

Does every approved AI system or agent have a named business owner?

Are systems and agents tested against documented acceptance criteria before live use?

Are errors, harmful outputs, unexpected actions, incidents, complaints and human overrides recorded?

Are performance and control effectiveness reviewed against defined thresholds?

Does a material change to a model, prompt, knowledge source, integration, permission or supplier term trigger reassessment?

Does each system have a scheduled review date and a route to restrict, suspend or retire it?

Is AI included in acceptable-use, incident-response and business-continuity arrangements?

Have staff received role-appropriate AI literacy and safe-use training?

Could the organisation provide current evidence supporting its answers today?

Does leadership periodically review AI risks, incidents, exceptions and overdue actions?

No tool names, prompts, credentials or customer data are requested.