GRC readiness check
Answer 20 questions about your policies, risk register, controls, evidence and AI governance. You get a maturity level from 1 to 5, a score for each area and a prioritised list of gaps with what to do next. Print it or save it as PDF.
Nothing you answer leaves your browser. Takes about 5 minutes.
Your GRC readiness
| Area | Score | Progress |
|---|
Close the gaps faster
AI Governance Toolkit Starter
$199 one-time
AI use and governance policy (Word), AI system inventory and risk register (Excel), AI system risk assessment (Excel) and a 30-day start-here plan. Instant download.
AI Governance Toolkit Professional
$599 one-time
Everything in Starter, plus an ISO/IEC 42001 gap assessment workbook, a NIST AI RMF mapping, AI vendor contract clauses and a days 31–90 plan. Instant download.
Agent Trust Cloud 90-day founding pilot
$7,395 fixed fee, 90 days
An owner for every AI agent and machine identity you run, what each one can reach, and audit evidence you keep. The fee is credited in full to your first year if you continue.
Pay by card · instant download · see our refund policy
Prices in US dollars.
Gap list
What the check covers
- Policies and ownership: an approved policy set, yearly reviews, staff acknowledgement and a named GRC owner.
- Risk register: key risks listed, rated with a written method, owned and reviewed.
- Controls: mapped to a framework, access reviews, vendor checks and a tested incident plan.
- Evidence and monitoring: one evidence library, scheduled collection, leadership metrics and control testing.
- AI governance: an AI inventory, an AI acceptable use policy, risk assessment before use and controls on AI agents.
Gaps on foundational questions answered No or Partly are high priority. See the GRC maturity model for what each level means.
Questions
What is GRC readiness?
Governance, risk and compliance (GRC) readiness is how far you can show that policies are owned, risks are recorded and treated, controls work and evidence exists, before an auditor, a customer's security review or a regulator asks.
How is the maturity level worked out?
Each answer scores 0 to 3 and is multiplied by the question's weight (3 for foundational questions, 2 for the rest). The overall percentage sets the level: under 20% Initial, 20 to 39% Developing, 40 to 59% Defined, 60 to 79% Managed, 80% or more Optimised.
Why is AI governance included?
AI tools and agents now handle company data and take actions. An AI inventory, an acceptable use policy, risk assessment before use and owners with limited permissions for agents belong in the same GRC programme as any other risk.
Is anything I answer stored or sent?
No. The score and gap list are worked out in this page. Nothing is stored after you close the tab, and the page blocks outgoing requests.
Is this an audit or a certification?
No. It's a quick self-assessment to find gaps and decide what to fix first.