Free AI self-assessments
Know where you stand before an auditor, a customer or a regulator asks. 30 short questionnaires covering the EU AI Act, ISO/IEC 42001, the NIST AI RMF, US state AI laws, AI security and AI governance. Answer one in about six minutes to see a score for each domain; ask for the PDF report by email. No account needed.
They run on Certifyi, a related product. A score is a self-check, not an audit, a certification or legal advice.
-
RegulationEU
EU AI Act Readiness Assessment
Whether you could evidence what the EU AI Act sets out for your role as provider or deployer: roles, prohibited practices, high-risk requirements, conformity, deployer duties, transparency and general-purpose AI.
28 questions · about 7 min · 7 domainsStart
-
RegulationEU
AI System Risk Classification Assessment
Which EU AI Act tier each AI system sits in, and whether you could defend the call: inventory, prohibited-practice screening, the high-risk routes, transparency-only systems and how decisions are revisited.
21 questions · about 6 min · 6 domainsStart
-
RegulationEU
Fundamental Rights Impact Assessment (FRIA)
For deployers of high-risk AI covered by the EU AI Act's fundamental rights impact assessment: applicability, the assessment itself, affected groups, human oversight, notification and keeping it current.
21 questions · about 6 min · 6 domainsStart
-
Governance and riskEU
AI Literacy Readiness Assessment
How you support AI literacy among the people who build, run and use AI, as the EU AI Act asks of providers and deployers: scope, role-based training, content, delivery, records and behaviour change.
21 questions · about 6 min · 6 domainsStart
-
Privacy and fairnessEU
AI Transparency & Disclosure Assessment
Whether people know when they are dealing with AI, when content is synthetic, and why an AI-informed decision went against them: disclosure, labelling, explanations and documentation.
20 questions · about 5 min · 6 domainsStart
-
Privacy and fairnessEU
AI & Data Privacy Assessment
Whether you can justify, limit and explain each use of personal data to train or run AI: lawful basis, DPIAs, transparency, individuals' rights, transfers and vendors. For DPOs and privacy leads.
23 questions · about 6 min · 6 domainsStart
-
RegulationColorado
Colorado AI Act Readiness Assessment
Colorado's law on automated decision-making technology in consequential decisions: scope, developer documentation, notices, adverse-outcome explanations, consumer rights and records.
22 questions · about 6 min · 6 domainsStart
-
RegulationUnited States
US State AI Law Exposure Assessment
Your exposure to US state AI laws: state footprint, notices for automated decisions, bias audits, chatbot and synthetic media rules, consumer rights and how you track new laws.
24 questions · about 6 min · 6 domainsStart
-
RegulationAsia-Pacific
Asia-Pacific AI Regulation Assessment
Which Asia-Pacific AI rules reach your services, from China's generative AI measures to Singapore's governance framework and Korea's AI Basic Act: applicability, the main national regimes and how you track change.
23 questions · about 6 min · 6 domainsStart
-
RegulationGlobal
AI in Healthcare Compliance Assessment
Clinical AI carries patient-safety, device-regulation and data-protection duties at once: intended use, the regulatory route, patient data, clinical validation, clinician oversight and post-market monitoring.
21 questions · about 6 min · 6 domainsStart
-
Standard or frameworkGlobal
ISO/IEC 42001 Readiness Assessment
How close your AI management system is to an ISO/IEC 42001:2023 certification audit: seven domains following clauses 4 to 10 and the Annex A controls, checked the way an auditor samples evidence.
23 questions · about 6 min · 7 domainsStart
-
Standard or frameworkGlobal
NIST AI Risk Management Framework Assessment
How far your AI risk practice matches the outcomes in the NIST AI RMF: GOVERN, MAP, MEASURE and MANAGE, plus the Generative AI Profile.
22 questions · about 6 min · 5 domainsStart
-
Standard or frameworkGlobal
AI System Impact Assessment (ISO/IEC 42005)
How you assess what your AI systems do to individuals, groups and society, following the guidance in ISO/IEC 42005:2025: scoping, stakeholders, mitigation, records and review triggers.
21 questions · about 6 min · 6 domainsStart
-
Standard or frameworkGlobal
SOC 2 for AI Companies Assessment
Getting an AI product ready for a SOC 2 examination: the AICPA Trust Services Criteria applied to training data, model changes, customer data segregation and output integrity. A self-assessment is not a SOC 2 report.
25 questions · about 7 min · 7 domainsStart
-
SecurityGlobal
AI Security Controls Assessment
Securing AI end to end: threat modelling for machine learning, access to models and data, adversarial testing, secure deployment, monitoring and incident handling.
22 questions · about 6 min · 6 domainsStart
-
SecurityGlobal
Generative AI & LLM Security Assessment
Prompt injection, data leakage, excessive agency and the rest of the OWASP Top 10 for LLM Applications, turned into checks you can evidence, from input handling to access control and red teaming.
22 questions · about 6 min · 6 domainsStart
-
SecurityGlobal
AI Agent & Autonomy Risk Assessment
AI agents that call tools, send email or change records need tighter limits than a chatbot: how you scope autonomy and permissions, how you stop them, and how you test and watch them.
23 questions · about 6 min · 6 domainsStart
-
SecurityGlobal
AI Supply Chain Security Assessment
The models, datasets, libraries and hosted services under your AI: provenance, integrity checks, vulnerability management and the MLOps pipeline.
21 questions · about 6 min · 6 domainsStart
-
SecurityGlobal
AI Incident Response Readiness Assessment
When a model misbehaves, who hears first and how fast it can be switched off: detection, triage, containment, investigation, notification and learning for AI incidents.
23 questions · about 6 min · 6 domainsStart
-
SecurityGlobal
Shadow AI Discovery Assessment
Whether you can see staff use of unapproved AI tools, offer sanctioned alternatives and stop sensitive data leaving, from telemetry to training.
21 questions · about 6 min · 6 domainsStart
-
Governance and riskGlobal
AI Governance Maturity Assessment
A framework-neutral view of how well AI is governed in practice: accountability, policy, inventory, and how risk, monitoring and training really work. For boards, CISOs and risk leads.
25 questions · about 7 min · 7 domainsStart
-
Governance and riskGlobal
AI Policy & Acceptable Use Assessment
Whether your AI policy works on a busy day: approved tools, the data that must never go into a prompt, training and enforcement.
23 questions · about 6 min · 7 domainsStart
-
Governance and riskGlobal
AI Model & Data Inventory Readiness
Whether your inventory of AI systems, models and datasets is complete, current, owned and tied into your risk and change processes.
21 questions · about 6 min · 6 domainsStart
-
Governance and riskGlobal
AI Adoption Readiness Assessment
Before AI moves from pilots to production: use cases, data, skills, governance, security and privacy, value measures and change.
24 questions · about 6 min · 7 domainsStart
-
Governance and riskGlobal
AI Procurement Controls Assessment
Controls on AI that arrives through purchases: intake, risk tiering, due diligence, contract terms, pilots, renewal and exit.
23 questions · about 6 min · 6 domainsStart
-
Governance and riskGlobal
Third-Party AI Vendor Risk Assessment
Where AI sits inside the products you buy, what each vendor does with your data, and what your contracts, monitoring and exit plans cover.
24 questions · about 6 min · 6 domainsStart
-
Governance and riskUnited States
AI Model Risk Management Assessment
Model risk from build to retirement: inventory and tiering, development standards, independent validation, monitoring, change control and vendor models. For model risk, validation and audit teams.
25 questions · about 7 min · 6 domainsStart
-
Privacy and fairnessGlobal
AI in Hiring & Employment Bias Assessment
AI in recruiting, screening and promotion: tool inventory, bias audits, candidate notices, human review, vendor terms and records.
25 questions · about 7 min · 6 domainsStart
-
Privacy and fairnessGlobal
Algorithmic Bias & Fairness Assessment
How you define fairness, test data and outcomes across groups, mitigate, monitor and govern algorithms that shape decisions about people.
23 questions · about 6 min · 6 domainsStart
-
Privacy and fairnessGlobal
Responsible AI Principles Assessment
Whether published AI principles change how systems are approved, tested and run: accountability, fairness, transparency, privacy, safety and human oversight.
23 questions · about 6 min · 6 domainsStart
After the score
A low domain score points at work to do. The free templates turn the recorded duties into the registers and documents an auditor asks for, the obligations say what each law requires with its source, and the applicability check narrows which duties may reach you.
Frequently asked questions
Are the AI self-assessments free?
Yes. Each is a short questionnaire answered in the browser, with a score for each domain at the end. No account is needed, and a PDF report can be requested by email.
How long does an AI self-assessment take?
Most take five to seven minutes: about 20 to 28 questions across five to seven domains. The list shows the question count and the expected time for each.
Which assessment should I start with?
If the EU AI Act may apply to you, the EU AI Act Readiness and AI System Risk Classification assessments. For a framework-neutral view, the AI Governance Maturity assessment. For a certification goal, ISO/IEC 42001 Readiness. For US state laws, the US State AI Law Exposure assessment.
Does a good score mean we are compliant?
No. A self-assessment shows where you stand against the questions it asks; it is not an audit, a certification or legal advice. Use the score to decide what to evidence next, and the templates and obligations on this site to do it.
Where do the self-assessments run?
On Certifyi, a related product. They are listed here because they cover the same laws and frameworks as the records; nothing on this site requires an account there.