GOVERNANCE / SECURITY / INTERNAL AUDIT

Set the context. Focus the plan.

From a question to a researched briefing, practical controls,
and the evidence your team needs.

Free to use. No account required.
01

Your AI context

Optional manual screening. Research can suggest a starting context for you.

What does the system involve?
Use more than one jurisdiction? Run a separate screen for each.
YOUR IMPLEMENTATION OUTLINE

Your next 90 days,
mapped out.

5 actions to prioritize in your first 30 days.

09suggested actions
  1. 01 / DAYS 1–30Scope & ownership
  2. 02 / DAYS 31–60Controls & evidence
  3. 03 / DAYS 61–90Test & validate
05Sources
matched
01Priority
reviews
00Tasks with
evidence
02

Start with these decisions

01

Add a legal review of the jurisdictions your use case affects.

Screening prompts, not legal classifications. Confirm the facts with your legal and risk teams.

SOURCE LINKED GUIDANCE

The references behind your plan

FrameworkNIST

NIST AI Risk Management Framework

A voluntary structure for governing, mapping, measuring and managing AI risk across the lifecycle.

Voluntary global baseline
FrameworkNIST

Generative AI Profile

A companion to the AI RMF addressing risks specific to generative AI, including unreliable outputs and information integrity.

Generative AI systems
StandardISO

ISO IEC 42001

An AI management system standard for organizations that provide or use AI. A certificate concerns its defined scope, not every legal obligation.

Voluntary unless contractually required
Security guidanceOWASP

Top 10 for LLM Applications

A security reference for applications using large language models, including prompt injection, sensitive information exposure and excessive agency.

LLM applications