Skip to content

Know if your AI workflow can survive production.

Answer 18 controls across 6 dimensions. The result is a self-assessment, not an audit or a certificate.

  • No login or card
  • Scored in your browser
  • Unknown is a valid answer

Deployment control room

Honest unknowns improve the result.

Choose the answer you can evidence today. A missing owner, policy, test, or incident path should appear in the plan, not disappear behind a generous score.

Diagnostic · model 2026-07-02

18 controls in. One verdict out.

Each control is a real deployment question: who owns the workflow, where the data lives, what the AI may do, what gets logged, what happens when it fails. Every answer is taken at face value. Nothing here opens your tenant, your code or your data, so the result is worth exactly what the answers are, and Unknown is a valid answer.

A readiness verdict

One of four bands, from "unsafe to deploy" to "production-ready for a bounded use case".

A risk register

Every risk signal your answers raise, ranked critical, high or medium, with the reason.

A 90-day action plan

A fixed 30/60/90 sequence with your first evidence gap and your first safe use case written into it.

A PDF brief

The verdict, both registers and the plan, in six sections you can forward internally.

Free · no login · scored in your browser

6 dimensions, 3 controls each

Use case

Workflow clarity, decision rights, value hypothesis

01

Data

Sources, permissions, sensitivity, retention

02

Governance

Owner, policy, oversight, assessment trigger

03

Security

Prompt, tool, supplier, and model risk controls

04

Architecture

Identity, integration, logging, environments

05

Operations

Evaluation, incidents, training, rollout ownership

06

The controls were written against public framework material: NIST AI Risk Management Framework, NIST AI 600-1 Generative AI Profile, ISO/IEC 42001:2023, EU AI Act overview, OWASP Top 10 for LLM Applications, Microsoft Cloud Adoption Framework for AI. No control cites a clause, so read that as the shelf the questions came from, not a mapping.

Control surface

6 dimensions. 3 controls in each.

The scan is organised around operating decisions: what the workflow may do, which data it can reach, who owns it, how it is tested, and what happens when it fails. Each dimension states what you tell it and what that telling does not prove.

01

Use case

Informed by Microsoft CAF AI strategy

What the workflow is for, who keeps the decision, and how value would be recognised.

A stated decision boundary is not evidence that the boundary is enforced anywhere.

02

Data

Informed by NIST Map and ISO 42001

Which sources the workflow reaches, how permissions carry, and what sensitivity applies.

Nothing here opens a tenant or a data store. The inventory is the one you describe.

03

Governance

Informed by EU AI Act and ISO 42001

Whether an owner, a written policy, an oversight step and an assessment trigger exist.

Saying a policy exists is not the policy. Neither the document nor its adoption is read.

04

Security

Informed by OWASP LLM Top 10

Which prompt, tool, supplier and model controls you believe are in place today.

No control is exercised. This is not a penetration test or a supplier assessment.

05

Architecture

Informed by Microsoft CAF and NIST Measure

How identity, integration, logging and environment separation are arranged.

No log or endpoint is read. A described architecture can differ from the deployed one.

06

Operations

Informed by NIST Manage and ISO 42001

Whether evaluation sets, incident paths, user training and rollout ownership exist.

An incident path nobody has ever run scores exactly like one that has been rehearsed.

Evidence model

Readiness, risk, and certainty stay separate.

A team can understand its gaps without being ready to deploy. It can also have a technically strong prototype with unacceptable use-case risk. The markers beside each step are the same key the other diagnostics use, so read what is missing from this one: no step is marked observed, because the scan reads your answers and never your systems.

This self-assessment is informed by public framework material and scores what you declare. It verifies nothing, and it is not a legal opinion, compliance audit, conformity assessment, certification, or substitute for testing the target environment.

Score the 18 declared controls

Each answer contributes to its dimension, to risk signals, to certainty, and to any hard blockers, which can hold the verdict at unsafe even when other controls score well. Every control is answered before a result renders.

Modelled

Keep every unknown unknown

Unknown is an option on all 18 controls, and it is an answer rather than a hole in the model. It scores zero, it counts as zero certainty, it carries that control's worst risk, and it lands in the evidence register instead of quietly taking a favourable default.

Not accessible

Build the risk and evidence registers

The result lists why each material risk was raised and which documents, tests, owners, or technical evidence you said were missing. The list is capped, and the result says so when it truncates.

Modelled

Choose a bounded first use case

The recommended starting shape reduces decision authority, data exposure, and integration scope. It remains a planning recommendation until something verifies it.

Modelled

FAQ

What the verdict can and cannot prove

How many questions is it?

18 controls across 6 dimensions, 3 in each. Every control offers Unknown, which scores zero and becomes an evidence gap instead of a favourable default.

Does the scan inspect anything itself?

No. Every input is an answer you select. Nothing connects to your tenant, repository, code, logs, or data, and no answer is verified. That is why the output is a self-assessment and why the result is worth exactly what your answers are worth.

What is included in the result?

A readiness verdict, readiness and risk scores, self-reported certainty, a six-axis view, a risk register, an evidence-gap list, a first safe use case, a 30/60/90-day plan, and a PDF brief in six sections.

Is this a compliance audit or certification?

No. It is a structured self-assessment informed by public frameworks. It does not establish legal compliance, certify an AI management system, or replace a technical and legal review.

What happens to my answers?

Scoring runs in your browser. A result is submitted only when you intentionally provide a work email for follow-up or report delivery.

ITSailor field library

Turn the gaps into working material.

Use the free packs for agent guardrails, governance decisions, operational evidence, and workflow engineering. Every available free resource remains browsable below.

26 free resources in the verified catalog. Reviewed 2026-07-18.

Browse the complete free library (26)

Resource packs

Downloadable pack

Azure Landing Zone Readiness Pack

Discovery, architecture, security baseline, policy and operating-review templates for Azure platform planning.

6 planning templates · policy intent · operating review

Downloadable pack

Azure Virtual Desktop Readiness Pack

Assess AVD requirements, architecture, FSLogix recovery, security, cost and regional outage readiness.

6 planning templates · recovery · cost and outage review

Downloadable pack

Backup & Restore Drill Pack

Plan, run and evidence recovery drills without inventing the process during an incident.

6 working templates · drill evidence · recovery validation

Downloadable pack

Cloud Cost Audit Workbook

The six-tab Excel model ITSailor uses to surface cloud + SaaS waste and rank the savings backlog. Real formulas, not a static sheet.

6-tab Excel model · formulas · prioritised savings backlog

Downloadable pack

Cloud Licence & Renewal Pack

Track renewals, audit licence use, assess new vendors and prepare evidence before commitment windows close.

6 working templates · renewal calendar · audit and reclaim procedures

Downloadable pack

Cloud Migration Cutover Pack

Structure discovery, pilot waves, cutover, rollback and hypercare for cloud and Microsoft 365 migrations.

7 working templates · cutover gates · rollback procedure

Downloadable pack

Microsoft 365 Evidence Snapshot

Read-only PowerShell and KQL examples for Secure Score, inactive licensed users and failed sign-in bursts.

2 read-only Graph scripts · 1 KQL query · permissions guide

Downloadable pack

Microsoft 365 Security Review Workpapers

Versioned workpapers for reviewing Microsoft 365 controls, evidence, permissions and remediation priorities.

38 source-linked checks · permission audit · gap analysis

Downloadable pack

Microsoft Defender Incident Response Pack

Operational templates for triage, device isolation, email purge, identity compromise and detection review.

7 working templates · 4 response procedures · review records

Downloadable pack

Microsoft Sentinel Detection Starter

Three KQL detections plus the catalogue, tuning, hunting and review records needed to operate them.

3 KQL samples · 2 runbooks · monthly operating review

Downloadable pack

Resilience Repo Starter Pack

AWS Terraform scaffolding, a BCDR SOP and an infrastructure decision matrix.

AWS Terraform baseline · BCDR SOP · decision matrix

Downloadable pack

Sovereign Exit Kit Starter

Record ownership, architecture, handover evidence and supplier-exit questions before a dependency becomes lock-in.

4 neutral templates · ownership map · handover and supplier-exit checks

Downloadable pack

Workflow Engineering Starter Flow Pack

Two sanitised n8n workflow exports, a broken-flow triage runbook and the operating notes needed to adapt them safely.

2 sanitised n8n exports · triage runbook · operating notes

Diagnostics

Interactive tool

AI Readiness Scan

Get an AI deployment verdict, risk register, and 90-day plan from what you declare.

18 declared controls · risk register · unknowns stay unknown

Interactive tool

Automation ROI Scenario Builder

Model one workflow from your own operating numbers and see the range it produces.

Your own baseline · three scenarios · 7 scored questions of 10

Interactive tool

Azure Cost Review

Read your own Azure cost export without it leaving your browser.

FREE · NOTHING UPLOADED

Interactive tool

DevEx Maturity Scan

Inspect one GitHub repository across five evidence families.

5 evidence families · unreadable controls stay unknown · token not stored

Interactive tool

Email Deliverability Scanner

Ensure your emails hit the inbox, not the spam folder.

Live DNS checks · 29 DKIM selectors

Interactive tool

Microsoft 365 Licence Overlap Check

Check whether the add-on you are about to buy is already in the plan you hold.

15 add-ons · every verdict sourced to Microsoft · unsettled pairs stay unsettled

Interactive tool

Microsoft 365 Security Scorecard

Review your Microsoft 365 security posture across 38 risk-weighted controls.

38 checks · 6 categories · source-linked assessment

Interactive tool

Offboarding Risk Profiler

Identify access leaks and data risks for departing users.

Risk profile · gap matrix · remediation timeline

Interactive tool

SaaS Auditor - License, Spend & Shadow IT

Find every SaaS you run - and pay for - across users, spend, and SSO.

Three scan paths · browser-local CSV processing