Start with what you know about actual use
AI governance answers can become aspirational quickly. A colleague may know the approved tool list, while another team uses an untracked service. A written policy may exist, but nobody may know whether staff have read it. An honest assessment should preserve those differences.
RiskSensai’s self-reported assessment includes an AI-governance domain. Its current questions cover subjects such as knowledge of AI use, written rules, controls on sensitive information and human review of consequential outputs. The workflow collects answers; it does not automatically inspect every employee’s tools or approve every AI use.1
Prepare the answers with the responsible people before selecting a favorable response. The aim is to understand current practice, not to make the organization’s result look complete.
Distinguish a remembered list from a maintained inventory
One existing question asks whether you know where AI is used in internal tools and the product. The available answers distinguish no tracking, knowledge from memory, a written list and a maintained inventory with data context and scheduled review.
That distinction is useful. Being able to name two large tools is not the same as having a current list of product features, employee tools and the information they handle. Do not select a maintained-inventory answer because you intend to create one next month.
Prepare a small manual worksheet outside the questionnaire if needed:
| Item | Information to confirm |
|---|---|
| Tool or product feature | What is actually used? |
| Purpose | Which task or business process uses it? |
| Data context | What categories of information can reach it? |
| Owner | Who can explain and review the use? |
| Current approval | What decision or rule permits it, if established? |
| Uncertainty | What remains unknown? |
This is a preparation aid, not a claim that RiskSensai automatically created an inventory record or discovered the tools.
Confirm the status of written rules
The questionnaire distinguishes informal guidance from written acceptable-use rules and stronger acknowledgement practices. Locate the actual policy or instruction before answering. Ask who approved it, who received it and whether it has been revisited as tools changed.
A chat message reminding staff to be careful is not necessarily a complete written policy. A policy draft is not an approved standard. A published policy does not prove that every employee acknowledged it. Choose the answer that accurately represents the stage you can establish.
If the status is unclear, record the question for the owner. The assessment can reveal that uncertainty without requiring you to invent an acknowledgement process or describe a draft as operational.
Review data controls separately from intentions
Another existing question concerns keeping customer or confidential data out of unapproved AI tools. The options distinguish no controls, general requests, clear rules with approved business accounts and more technical controls.
Check what each claim depends on. A verbal request not to paste sensitive data does not establish blocking or monitoring. A business account does not automatically settle every data-handling question; the actual settings, terms, access and use still need review.
Do not upload a confidential sample to demonstrate the control while preparing the answer. Ask for the relevant policy, configuration record or responsible person’s explanation through an appropriate process. The AI assistant’s own transparency information also emphasizes human judgment and informational limits.2
Examine human oversight where it matters
The fuller questionnaire asks about human review when AI output influences consequential decisions. Consider whether there is a real reviewer with time, authority and enough information to challenge the output. A person who always accepts a generated answer is not the same as a meaningful review process.
Use a concrete example from an authorized, appropriately minimized discussion. For instance, if an AI output helps prioritize a business decision, who checks it before it takes effect? What facts do they inspect? Can they reject it? Where are unresolved assumptions handled?
NIST’s AI RMF provides context for considering AI risk in its use setting.3 That background does not mean this assessment classifies your system under a particular law or satisfies all requirements of a governance framework.
Worked example: a partial picture
Suppose your organization has an approved writing assistant and a documented rule against supplying customer data. You can confirm those facts. However, you do not know whether every team uses company-managed accounts, and you have no current list of AI features added by vendors.
A useful preparation note would separate the facts:
| Established | Not yet established |
|---|---|
| One approved assistant and a written data rule | All AI use across teams |
| A named person responsible for that tool | Current coverage of vendor-added AI features |
| A process for reviewing certain outputs | Whether every relevant account is company-managed |
Answer accordingly and identify who can resolve the gaps. Do not combine one strong practice with several unknowns into a blanket claim that AI governance is complete.
Keep framework references in perspective
Question context may refer to frameworks or controls. A reference explains why a subject matters; it is not a formal legal classification, a certification result or an independent examination of the response.
If a question raises a legal or regulatory issue, take the factual preparation to an appropriately qualified person. Do not ask an AI-generated explanation to replace the jurisdiction-specific analysis or professional judgment your organization needs.
Likewise, a suggested priority is not an approved policy, a purchased tool or an automatically created task. Decide what work is appropriate, identify an owner and use the relevant supported workflow separately.
Enter and review the answers in the right context
Follow the existing assessment entry, sign in when prompted and explicitly select the organization. Use the available mode and answer the actual questions displayed. Guide context does not turn the questionnaire into a different legal assessment.
After saving, review the result as an informational picture of the answers. Choose a few follow-ups that reduce important uncertainty: confirming account ownership, completing the tool list or clarifying who reviews consequential outputs.
The useful outcome is a more accurate conversation about AI use. You should be able to explain which practices exist, what evidence supports them and what remains unknown—without claiming automatic discovery, legal clearance or assurance that the questionnaire did not provide.
Sources and references
-
RiskSensai. Free Digital Trust Assessment. Explains self-reported scope and authenticated assessment entry. ↩
-
RiskSensai. AI Transparency. Explains human judgment and AI-service boundaries. ↩
-
NIST. Artificial Intelligence Risk Management Framework (AI RMF 1.0) (2023-01). Supports context-sensitive AI-risk discussion. ↩

