logo - Nomad
01

Answer six, see your gaps

The same opening conversation we have with every client, in the same order. Answers stay in your browser until you choose to send them.

/ 6
Score of 12

Scoring is deliberately blunt: two points where something is standing and owned, one where it exists but is informal, none where it does not exist yet.

01

Do you know everywhere AI is being used across the business?

No inventory
No inventory
Partial, by team
Partial, by team
Maintained centrally
Maintained centrally
02

Is one person accountable for AI risk decisions?

No one owns it
No one owns it
Shared across IT, legal, business
Shared across IT, legal, business
Named owner and forum
Named owner and forum
03

Are your AI and data policies written and approved?

Nothing written
Nothing written
Drafted, not approved
Drafted, not approved
Approved and in use
Approved and in use
04

Could you answer a client or auditor questionnaire this week?

No
No
Only by scrambling
Only by scrambling
Yes, from a standing record
Yes, from a standing record
05

Do you review AI vendors and third-party models before use?

No review
No review
Case by case
Case by case
Standard review every time
Standard review every time
06

Is anyone tracking which AI rules apply to you as they change?

No
No
Occasionally, internally
Occasionally, internally
Monitored continuously
Monitored continuously
Red · Exposed

There is no program to point to yet

A client questionnaire or an auditor would find nothing standing. Start at Crawl: scope, ownership, and a gap map before any spend.

Amber · Partial

Pieces exist, but the seams show

You could answer some questions and not others, which is where incidents live. Start at Walk: formalize policy and get evidence collecting itself.

Green · Defensible

You can show your work

The foundation holds. Start at Run: validate controls, close the remaining gaps, and keep pace as rules and models change.

What we would look at first
Build an AI inventory, including the tools teams adopted on their own.
Name a single accountable owner and a forum where AI decisions get made.
Draft and approve the policy set, then map controls to it.
Stand up evidence collection so answers come from a standing record, not a scramble.
Put a standard third-party AI review in front of procurement.
Assign regulatory monitoring so moved deadlines reach you before clients do.
Next step

Request an exposure review

An advisor reviews your cyber and AI governance posture against the obligations enforceable today and returns a red, yellow, green picture of what to address first.

No obligation, and you keep the findings either way. We reply within one business day.

Ryan Hughes · VP of Strategic Partnerships

This field is for validation purposes and should be left unchanged.