# Enterprise AI Risk Assessment

Measure how much risk your AI use creates, how well your controls cover it, and what to fix first. 13 questions, about 5 minutes, no sign-up. Answers stay in your browser unless you share a link.

[Take the assessment](https://www.openlayer.com/enterprise-ai-risk-assessment) · [How scoring works](https://www.openlayer.com/enterprise-ai-risk-assessment/methodology)

## What you get

- **Residual risk score.** Your inherent AI risk weighed against your control readiness, banded Low (0–24), Moderate (25–49), High (50–74), or Critical (75–100).
- **Seven control areas.** Discovery, Registration, Testing, Observability, Security & Guardrails, Cost Controls, and Compliance, each scored 0–100 and weighted by how relevant it is to your environment.
- **What to fix first.** The gaps driving your score, worst first. Each names the next step, never a control you already have, and says whether a control is missing, whether you have the right controls but a low score, whether coverage is uneven, or whether visibility is the gap. An illustrative what-if shows how residual risk moves if you close a gap.
- **A shareable report.** Copy a read-only link or a text summary, or save the report as a PDF.

Scores appear only after all 13 questions are answered, so a half-finished assessment never shows a misleading verdict.

## Talk it through

After the report, book a 30-minute walkthrough with an Openlayer expert. The areas to cover are preselected from your gaps, and the booking can attach your scores and a link to your report. Or [request a general demo](https://www.openlayer.com/request-a-demo).

> Before Openlayer, we had limited visibility into where AI risk was actually showing up across the organization. Within weeks, we were able to identify our biggest gaps, put controls around them, and materially reduce our exposure without slowing teams down.

## The questions

### AI risk surface: Map your AI risk surface

Where AI runs, what it can access, what it can do, and what happens if it fails.

1. **Where is AI being used in your organization?** (Select all that apply.)
   - Employee AI tools
   - Internal copilots and enterprise search
   - Customer-facing applications
   - AI embedded in products
   - Automated workflows and agents
   - Predictive models and traditional ML
   - Third-party products with embedded AI
   - Still exploring
   - I’m not sure

2. **Approximately how many AI systems are in use or development across your organization?** (Select one.)
   - 1–5
   - 6–20
   - 21–50
   - 51–100
   - 100+
   - We don’t know

3. **What information can these systems access or process?** (Select all that apply.)
   - Public information
   - Internal company information
   - Source code or intellectual property
   - Personal information
   - Financial or payment information
   - Protected health information
   - Authentication credentials or secrets
   - Data used for regulated decisions
   - I’m not sure

4. **What can your most capable AI systems do?** (Select all that apply.)
   - Generate content or answers
   - Recommend decisions to people
   - Retrieve information from internal systems
   - Create or modify records
   - Communicate with customers or third parties
   - Execute transactions
   - Take actions that are difficult or impossible to reverse
   - Change production systems or workflows
   - Act without human approval
   - I’m not sure

5. **If one of these AI systems failed or behaved incorrectly, what could reasonably happen?** (Select all that apply.)
   - Minor productivity or workflow disruption
   - Incorrect information reaches employees
   - Incorrect information reaches customers
   - Sensitive information is exposed
   - A financial loss or unauthorized transaction occurs
   - A regulated or consequential decision is affected
   - A production or business-critical system is disrupted
   - Physical health or safety could be affected
   - Significant legal or regulatory exposure
   - Significant reputational or customer-trust impact
   - I’m not sure

### Discovery: Know what AI you have

How completely you can see AI use across teams, vendors, and products.

6. **How completely can you discover AI use across your organization?** (Select all that apply.)
   - Identify AI applications built by internal teams
   - Identify AI used directly by employees
   - Identify AI embedded in third-party products
   - Identify the models and vendors being used
   - Identify which systems access sensitive data
   - See how many systems were added or changed recently
   - Maintain a continuously updated view
   - Discovery varies by team
   - None of these consistently
   - I’m not sure

### Registration: Catalog and assess risk

What is consistently recorded about each AI system.

7. **What information is consistently registered for each AI system?** (Select all that apply.)
   - Business purpose and intended use
   - System owner
   - Models, vendors, tools, and datasets
   - Users and affected populations
   - Sensitive-data classification
   - Risk tier
   - Approval status
   - Deployment and change history
   - Applicable policies and regulations
   - Registration varies by team
   - None of these consistently
   - I’m not sure

### Testing: Catch problems before they ship

How systems are validated before deployment or major changes.

8. **How are AI systems tested before deployment or major changes?** (Select all that apply.)
   - Functional and task-completion evaluations
   - Accuracy, hallucination, and grounding tests
   - Bias and fairness tests
   - Safety and harmful-content tests
   - Prompt injection and adversarial tests
   - Sensitive-data leakage tests
   - Agent tool and permission tests
   - Tests using production examples
   - Automated release thresholds
   - Human review without standardized tests
   - Testing varies by team
   - No formal testing
   - I’m not sure

### Observability: See what your AI does in production

What you can monitor once systems are live.

9. **What can you monitor across AI systems in production?** (Select all that apply.)
   - Requests, responses, and traces
   - Agent steps and tool calls
   - Latency and availability
   - Task completion and business outcomes
   - Quality and hallucination metrics
   - Safety and policy violations
   - Model, prompt, and application changes
   - User feedback
   - AI incidents
   - We have logs, but no unified view
   - Monitoring varies by team
   - None of these consistently
   - I’m not sure

### Security & Guardrails: Protect AI in real time

Which protections are enforced while systems run.

10. **Which protections are consistently enforced at runtime?** (Select all that apply.)
   - Identity and role-based access
   - Least-privilege access for agents
   - Sensitive-data detection or redaction
   - Prompt injection defenses
   - Input and output policies
   - Tool and action authorization
   - Human approval for high-impact actions
   - Runtime blocking or fallback
   - Rate limits
   - Kill switch
   - Complete audit trail
   - Controls vary by application
   - None of these consistently
   - I’m not sure

### Cost Controls: Know and control spend

How well you can attribute and limit AI consumption.

11. **How well can you understand and control AI spending?** (Select all that apply.)
   - Know total AI spend
   - Know total token consumption
   - Attribute usage and cost to applications
   - Attribute usage and cost to teams
   - Compare cost across models and vendors
   - Identify unexpected usage spikes
   - Set budgets or usage limits
   - Alert teams before budgets are exceeded
   - Automatically block or reroute excessive usage
   - We only see provider invoices
   - None of these consistently
   - I’m not sure

### Compliance: Prove it

The requirements you face and how ready your evidence is.

12. **Which requirements shape your AI program?** (Select all that apply.)
   - EU AI Act
   - NIST AI Risk Management Framework
   - ISO/IEC 42001
   - HIPAA
   - GDPR or other privacy requirements
   - Financial-services model risk requirements
   - SOC 2, ISO 27001, or security requirements
   - Industry-specific requirements
   - Internal responsible-AI policies
   - Customer contractual requirements
   - Another known requirement not listed here
   - None. This use is low-risk enough that no specific requirements apply
   - I’m not sure

13. **How prepared are you to produce AI compliance evidence?** (Select one.)
   - Controls and evidence are continuously tracked
   - Evidence is automatically mapped to requirements
   - We can produce evidence with some manual work
   - Evidence is distributed across teams and tools
   - We would need a significant collection effort
   - We do not maintain AI-specific evidence
   - I’m not sure
