Skip to content

Know if your AI workflow can survive production.

Answer 18 controls across 6 dimensions. The result is a self-assessment, not an audit or a certificate.

  • No login or card
  • Scored in your browser
  • Unknown is a valid answer

Deployment control room

Honest unknowns improve the result.

Choose the answer you can evidence today. A missing owner, policy, test, or incident path should appear in the plan, not disappear behind a generous score.

Diagnostic · model 2026-07-02

18 controls in. One verdict out.

Each control is a real deployment question: who owns the workflow, where the data lives, what the AI may do, what gets logged, what happens when it fails. Every answer is taken at face value. Nothing here opens your tenant, your code or your data, so the result is worth exactly what the answers are, and Unknown is a valid answer.

A readiness verdict

One of four bands, from "unsafe to deploy" to "production-ready for a bounded use case".

A risk register

Every risk signal your answers raise, ranked critical, high or medium, with the reason.

A 90-day action plan

A fixed 30/60/90 sequence with your first evidence gap and your first safe use case written into it.

A PDF brief

The verdict, both registers and the plan, in six sections you can forward internally.

Free · no login · scored in your browser

6 dimensions, 3 controls each

Use case

Workflow clarity, decision rights, value hypothesis

01

Data

Sources, permissions, sensitivity, retention

02

Governance

Owner, policy, oversight, assessment trigger

03

Security

Prompt, tool, supplier, and model risk controls

04

Architecture

Identity, integration, logging, environments

05

Operations

Evaluation, incidents, training, rollout ownership

06

The controls were written against public framework material: NIST AI Risk Management Framework, NIST AI 600-1 Generative AI Profile, ISO/IEC 42001:2023, EU AI Act overview, OWASP Top 10 for LLM Applications, Microsoft Cloud Adoption Framework for AI. No control cites a clause, so read that as the shelf the questions came from, not a mapping.

Control surface

6 dimensions. 3 controls in each.

The scan is organised around operating decisions: what the workflow may do, which data it can reach, who owns it, how it is tested, and what happens when it fails. Each dimension states what you tell it and what that telling does not prove.

01

Use case

Informed by Microsoft CAF AI strategy

What the workflow is for, who keeps the decision, and how value would be recognised.

A stated decision boundary is not evidence that the boundary is enforced anywhere.

02

Data

Informed by NIST Map and ISO 42001

Which sources the workflow reaches, how permissions carry, and what sensitivity applies.

Nothing here opens a tenant or a data store. The inventory is the one you describe.

03

Governance

Informed by EU AI Act and ISO 42001

Whether an owner, a written policy, an oversight step and an assessment trigger exist.

Saying a policy exists is not the policy. Neither the document nor its adoption is read.

04

Security

Informed by OWASP LLM Top 10

Which prompt, tool, supplier and model controls you believe are in place today.

No control is exercised. This is not a penetration test or a supplier assessment.

05

Architecture

Informed by Microsoft CAF and NIST Measure

How identity, integration, logging and environment separation are arranged.

No log or endpoint is read. A described architecture can differ from the deployed one.

06

Operations

Informed by NIST Manage and ISO 42001

Whether evaluation sets, incident paths, user training and rollout ownership exist.

An incident path nobody has ever run scores exactly like one that has been rehearsed.

Evidence model

Readiness, risk, and certainty stay separate.

A team can understand its gaps without being ready to deploy. It can also have a technically strong prototype with unacceptable use-case risk. The markers beside each step are the same key the other diagnostics use, so read what is missing from this one: no step is marked observed, because the scan reads your answers and never your systems.

This self-assessment is informed by public framework material and scores what you declare. It verifies nothing, and it is not a legal opinion, compliance audit, conformity assessment, certification, or substitute for testing the target environment.

Score the 18 declared controls

Each answer contributes to its dimension, to risk signals, to certainty, and to any hard blockers, which can hold the verdict at unsafe even when other controls score well. Every control is answered before a result renders.

Modelled

Keep every unknown unknown

Unknown is an option on all 18 controls, and it is an answer rather than a hole in the model. It scores zero, it counts as zero certainty, it carries that control's worst risk, and it lands in the evidence register instead of quietly taking a favourable default.

Not accessible

Build the risk and evidence registers

The result lists why each material risk was raised and which documents, tests, owners, or technical evidence you said were missing. The list is capped, and the result says so when it truncates.

Modelled

Choose a bounded first use case

The recommended starting shape reduces decision authority, data exposure, and integration scope. It remains a planning recommendation until something verifies it.

Modelled

FAQ

What the verdict can and cannot prove

How many questions is it?

18 controls across 6 dimensions, 3 in each. Every control offers Unknown, which scores zero and becomes an evidence gap instead of a favourable default.

Does the scan inspect anything itself?

No. Every input is an answer you select. Nothing connects to your tenant, repository, code, logs, or data, and no answer is verified. That is why the output is a self-assessment and why the result is worth exactly what your answers are worth.

What is included in the result?

A readiness verdict, readiness and risk scores, self-reported certainty, a six-axis view, a risk register, an evidence-gap list, a first safe use case, a 30/60/90-day plan, and a PDF brief in six sections.

Is this a compliance audit or certification?

No. It is a structured self-assessment informed by public frameworks. It does not establish legal compliance, certify an AI management system, or replace a technical and legal review.

What happens to my answers?

Scoring runs in your browser. A result is submitted only when you intentionally provide a work email for follow-up or report delivery.

ITSailor field library

Turn the gaps into working material.

Use the free packs for agent guardrails, governance decisions, operational evidence, and workflow engineering. Every available free resource remains browsable below.

25 free resources in the verified catalog. Reviewed 2026-07-18.

Browse the complete free library (25)

Resource packs

Downloadable pack

Azure Landing Zone Readiness Pack

Discovery, architecture, security baseline, policy and operating-review templates for Azure platform planning.

6 planning templates · policy intent · operating review

Downloadable pack

Azure Virtual Desktop Readiness Pack

Assess AVD requirements, architecture, FSLogix recovery, security, cost and regional outage readiness.

6 planning templates · recovery · cost and outage review

Downloadable pack

Backup & Restore Drill Pack

Plan, run and evidence recovery drills without inventing the process during an incident.

6 working templates · drill evidence · recovery validation

Downloadable pack

Cloud Cost Audit Workbook

The six-tab Excel model ITSailor uses to surface cloud + SaaS waste and rank the savings backlog. Real formulas, not a static sheet.

6-tab Excel model · formulas · prioritised savings backlog

Downloadable pack

Cloud Licence & Renewal Pack

Track renewals, audit licence use, assess new vendors and prepare evidence before commitment windows close.

6 working templates · renewal calendar · audit and reclaim procedures

Downloadable pack

Cloud Migration Cutover Pack

Structure discovery, pilot waves, cutover, rollback and hypercare for cloud and Microsoft 365 migrations.

7 working templates · cutover gates · rollback procedure

Downloadable pack

GCP Landing Zone Readiness Pack

Discovery, architecture, organisation policy and operating-review templates for a governed Google Cloud foundation.

6 planning templates · policy set · operating review

Downloadable pack

Microsoft 365 Evidence Snapshot

Read-only PowerShell and KQL examples for Secure Score, inactive licensed users and failed sign-in bursts.

2 read-only Graph scripts · 1 KQL query · permissions guide

Downloadable pack

Microsoft 365 Security Review Workpapers

Versioned workpapers for reviewing Microsoft 365 controls, evidence, permissions and remediation priorities.

38 source-linked checks · permission audit · gap analysis

Downloadable pack

Microsoft Defender Incident Response Pack

Operational templates for triage, device isolation, email purge, identity compromise and detection review.

7 working templates · 4 response procedures · review records

Downloadable pack

Microsoft Sentinel Detection Starter

Three KQL detections plus the catalogue, tuning, hunting and review records needed to operate them.

3 KQL samples · 2 runbooks · monthly operating review

Downloadable pack

Resilience Repo Starter Pack

AWS Terraform scaffolding, a BCDR SOP and an infrastructure decision matrix.

AWS Terraform baseline · BCDR SOP · decision matrix

Downloadable pack

Sovereign Exit Kit Starter

Record ownership, architecture, handover evidence and supplier-exit questions before a dependency becomes lock-in.

4 neutral templates · ownership map · handover and supplier-exit checks

Downloadable pack

Workflow Engineering Starter Flow Pack

Two sanitised n8n workflow exports, a broken-flow triage runbook and the operating notes needed to adapt them safely.

2 sanitised n8n exports · triage runbook · operating notes