// Free quiz

AI Governance readiness quiz

Rolling out ChatGPT, Copilot or other AI tools? Answer twelve high-level questions about the policy, data handling, oversight and vendor checks that keep AI use safe, and get a readiness score with the gaps to close. It will not certify you, but it will show where to start.

The 12 checks in this quiz

Answer each one No, In progress, or Yes. Anything not fully in place comes with a concrete next step.

Policy & ownership

  1. Do you have a written, approved AI use policy that staff have read and acknowledged?

    Put an AI acceptable-use policy in writing, get leadership sign-off, and have staff acknowledge it. It is the foundation every AI framework starts from.

  2. Is someone clearly accountable for approving AI tools and handling AI issues?

    Name an owner (or a small committee) responsible for approving AI tools and dealing with problems, so decisions are not ad hoc.

Data & privacy

  1. Have you defined what company or customer data can and cannot be put into AI tools?

    Spell out what data is allowed in AI tools and what is off-limits (personal, confidential, regulated), and make it clear to staff.

  2. Have you checked whether your AI vendors train on or retain the data you put in?

    Review each AI vendor data-use terms; prefer business tiers that do not train on your inputs, and record the decision.

  3. For AI that touches personal information, have you considered privacy obligations (PIPEDA / Law 25)?

    Assess privacy impact before using AI on personal data; PIPEDA and Quebec Law 25 can apply. Try the privacy readiness quiz.

Risk & oversight

  1. Do you keep a human in the loop to review important or customer-facing AI output?

    Require human review before AI output is used in decisions, code, or anything customer-facing. Treat AI as a draft, not a decision.

  2. Do you have a way to catch AI errors, bias or made-up answers before they cause harm?

    Add verification steps for high-stakes AI use and tell staff to fact-check output before relying on it.

  3. Is AI covered in your risk assessment and incident response (a bad output or a data leak)?

    Add AI scenarios (data leakage, wrong output, vendor outage) to your risk register and incident plan. See the incident response quiz.

People & use

  1. Have staff had basic training on using AI safely and what not to share?

    Run short AI-awareness training: which tools are approved, what data is off-limits, and how to sanity-check output.

  2. Do you know which AI tools staff are actually using, including unapproved ones?

    Inventory the AI tools in use, including unsanctioned shadow AI, so you can govern what is really happening.

Vendors & tools

  1. Do you vet an AI vendor security and compliance before adopting it?

    Check each AI vendor security posture and certifications (such as SOC 2) before rollout, like any other supplier.

  2. Do your AI contracts make clear who owns the inputs and the outputs?

    Confirm in writing that you keep rights to your inputs and outputs and that the vendor liability terms are acceptable.

About this quiz. About this quiz. AI governance is tied to your privacy, security and contractual obligations, so this short quiz is a readiness indicator, NOT an audit, certification or legal advice. It covers the practical building blocks (policy, data, risk, oversight, vendors) that frameworks like the NIST AI RMF and ISO 42001 expect. Everything runs in your browser and is not saved.
// What this means for your business

Adopt AI without the governance gaps

Most businesses are already using AI before anyone writes the rules. We help Canadian teams put the policy, data guardrails and oversight in place so you get the productivity without the privacy, security or compliance surprises, then keep it current as the tools and rules change.