Free AI Governance Risk Check:
Find the Shadow AI Use Putting Your Business at Risk
- 9 quick questions
- Takes about 2 minutes
- No sign-up to see your result
Your top next moves
Use the interactive AI governance risk check below to see where your business actually stands.
Answer 8 quick questions, scored against the same four functions, Govern, Map, Measure, and Manage, that the NIST AI Risk Management Framework uses, and get your result in about 2 minutes: your risk level, the specific gaps to close, and a printable checklist you can hand to your team or IT provider.
No sign-up to see your result.
What the NIST AI Risk Management Framework Actually Covers (the short version)
The NIST AI Risk Management Framework (AI RMF 1.0) is a voluntary framework, published by the National Institute of Standards and Technology on January 26, 2023, for managing risk across the AI lifecycle. It isn’t a law and it isn’t a certification you can buy or hold.
It’s organized around four functions:
- Govern
Put accountability, policy, and culture in place first
- Map
Understand what AI is actually in use and the context it’s used in
- Measure
Assess and track the risks you’ve mapped
- Manage
Act on what you’ve measured, prioritize, and respond
In July 2024, NIST published a companion, the Generative AI Profile (NIST AI 600-1), which applies those same four functions specifically to tools like ChatGPT, Copilot, and Gemini, the category most small businesses actually encounter.
The checklist below is organized around those four functions.
The Full AI Governance Checklist
(NIST AI Risk Management Framework)
Work through each area below. Anything you can’t confirm is a gap. If you can’t prove it, a client, insurer, or regulator asking the same question can’t either.
- 1. Govern: Policy and Accountability
✓ A written AI use policy that employees have actually seen, not just a rule that exists somewhere in a handbook nobody reads. See our AI policy guide and free template for what to include.
✓ The policy names which tools are approved and, specifically, what information (client data, financials, patient or student records, source code, anything covered by a confidentiality agreement) can never be typed into a public AI tool.
✓ One named person, existing staff is fine, accountable for AI use and risk, the way most businesses already name a privacy or security lead. - 2. Map: Knowing What AI is Actually in Use
✓ An honest inventory of every AI tool employees are using, including tools staff picked on their own (a personal ChatGPT account, a browser extension, an AI feature inside a phone app), not only tools IT issued. This is what “shadow AI” means: AI use the business hasn’t reviewed because nobody knew to look for it.
✓ A review of AI features already built into software you already pay for, Microsoft 365 Copilot, your CRM, your accounting or practice-management platform, so you know which are switched on.
✓ Clarity on what kind of data each in-use AI tool can actually reach. - 3. Measure: Assessing the Risk You’ve Mapped
✓ A technical control, not only a written rule, that blocks or flags sensitive data before it reaches a public AI tool. This usually rides on the same data-loss-prevention tooling many businesses already have in Microsoft 365 or Google Workspace. See Microsoft 365 data-loss prevention vs. backup for how that overlaps with, and differs from, your backup strategy.
✓ A tool-by-tool answer to whether an AI product retains or trains on the data you enter, versus a contractual no-training guarantee (usually a business-tier setting, not the free-tier default).
✓ Awareness of where AI output itself introduces risk, a chatbot confidently stating something false (NIST’s Generative AI Profile calls this “confabulation”) is a different failure mode than a data leak, and both are worth watching for. - 4. Manage: Acting on What You’ve Found
✓ Written confirmation, a contract clause, a data processing agreement, or a vendor questionnaire answer, of how every vendor that’s added AI to a product you already use actually handles your data. See our guide to assessing third-party vendor security for how to run that review.
✓ A short incident plan specific to AI-related exposure: who’s told, how it’s contained, and what changes afterward, if an employee’s AI use exposes sensitive data.
✓ A recurring check-in, quarterly is reasonable, since the tools, the vendors, and the built-in AI features in your existing software change faster than most other IT risk categories.
How to read your gaps?
Most of the technical items above (MFA, encryption, audit logging, tested backups) live in your IT setup, not a policy binder, which is the half of HIPAA a managed IT partner operates for you.
- 0 – 2 Gaps
Strong Shape
- 3 – 6 Gaps
Real, findable gaps, most organizations have some at this stage of AI adoption
- 7+ Gaps or 2+ Critical Gaps
AI is likely in active, ungoverned use in your business right now.
AI Governance Checklist FAQ
It’s a voluntary framework published by NIST in January 2023 to help organizations manage risk across the AI lifecycle. No federal law requires private businesses to follow it. It matters anyway because it’s becoming the reference point clients, insurers, and some state laws point to when they ask how a business governs its AI use.
They’re the framework’s core structure. Govern comes first: putting policy and accountability in place before anything else. Map means knowing what AI is actually in use and its context. Measure means assessing the risks you’ve identified. Manage means acting on what you’ve measured, prioritizing fixes and responding when something goes wrong. This tool scores your answers against those same four functions.
Shadow AI is AI tool use inside your business that nobody has reviewed or approved, an employee using a personal ChatGPT account for work, a browser extension that summarizes documents, an AI feature quietly switched on inside software you already pay for. It matters because you can’t secure or govern a tool you don’t know exists, and it’s often the single biggest gap this check surfaces.
It’s a companion document NIST published in July 2024 that applies the AI RMF’s four functions specifically to generative AI, the ChatGPT-and-Copilot category most small businesses actually encounter, rather than AI broadly. It names specific risk areas this category raises, including data privacy, information security, intellectual property exposure, and a model confidently stating something false.
It depends on your state, and this is moving quickly. As one example, Texas’s Responsible AI Governance Act (TRAIGA), effective January 1, 2026, gives businesses an affirmative defense against certain enforcement actions if they can show substantial compliance with the NIST AI RMF, including the Generative AI Profile. Other states are still working out their own approach, and this isn’t legal advice, confirm your specific exposure with counsel. What’s consistent across states is that documented governance, a policy, an inventory, and evidence of review, is what “substantial compliance” actually looks like in practice, which is exactly what this check is scoring.
Yes. The framework, and the pain point it addresses, isn’t about building AI, it’s about using it. If any employee uses ChatGPT, Copilot, or a similar tool for work, or if any software you already pay for has AI features turned on, that’s AI use the business needs a policy for.
It overlaps heavily, the access control, encryption, and vendor-vetting habits a decent security program already has cover a lot of this ground, but AI governance adds two things most existing programs don’t: an inventory of AI tools specifically (including ones staff picked themselves) and a policy naming what can and can’t be typed into them. If you already have strong cybersecurity fundamentals, closing the AI-specific gaps is usually fast.
For most businesses, it’s the written policy, question 1 in the tool above. It’s the fastest legitimate gap to close and it’s what turns every other item on this list from ad-hoc to governed.
Ready to close your gaps?
If your result flagged gaps in your tool inventory, data controls, or vendor reviews, most of that is technical and process work an IT partner handles day to day.
LeadingIT helps Chicagoland businesses across industries build the AI use policy, tool inventory, data controls, and vendor review process the NIST AI RMF expects, and keep it current as the tools change. We deliver this FOR clients; there’s no NIST AI RMF “certification” an organization or an IT company can hold, and we don’t claim one, the framework itself is voluntary guidance, not a certifiable standard.
Email yourself the full result from the tool above, book a free 30-minute gap review, or contact us and see how we deliver this as a managed service.