5 scorecards, one for each side of the job you were handed. Fifteen plain-language questions each, about five minutes, and a scored report with the specific gaps you’d need to close. They are all free — take them in any order, and your answers are saved as you go.
Can you name every AI tool in use, who owns it, and what happens when one gets something wrong? The questions a board actually asks.
Do you have one org-wide risk register with named owners, agreed scoring, and a quarterly view your board can read?
Devices, subscriptions, systems, and access — do you know what you own, what it costs, and who can still log in after they leave?
What personal data do you hold, why, how long do you keep it — and could you answer a deletion request or a breach correctly?
What do you tell people about their information, who else sees it, and could someone exercise their rights without chasing you?
Answer honestly — these are for your own planning, not a compliance certification. No score is ever shared, published, or shown to anyone but you.