Home Services Scorecard About Contact Governance Book a consultation

AI Deployment
Risk Scorecard

Find out where your AI actually stands — free, in plain English, in about two minutes. Tell it what your AI does and which protections you already have: it grades where you stand today, then shows the cheapest set of upgrades to close the gap. Under the hood it's a real risk model — spanning all ten categories of the OWASP Top 10 for LLM Applications (2025), structured by the NIST AI Risk Management Framework — the same one behind our paid assessment.

Interactive assessment

Where you stand today — and the cheapest way up.

Tell us about your AI in plain terms and tick the protections you already run. The score is your situation today, not a sales pitch — and the plan is the cheapest set of upgrades that closes the most risk within your budget. We check every combination; the numbers match our paid assessment exactly.

Tick what's genuinely in place — this is what makes the score yours. If you're not sure what one means, it's usually not there yet.

how protected you are today
after upgrades
upgrade cost
best possible

The plan builds on what you already have and picks the cheapest set of upgrades that stops the most risk within your budget — every combination checked, not a rule of thumb. This is the rough cost to implement protections, not the price of an assessment.

What could go wrongOWASPImpactTodayAfter upgrades

Impact reflects how bad a successful attack would be for your setup — it rises with more sensitive data and more powerful actions (hover for the exact score). "Today" and "after upgrades" show how much of the modeled attack risk is stopped. The codes are categories from the OWASP Top 10 for LLM Applications (2025) — the industry-standard list of AI risks (hover a code for its name). Full methodology below.

Your upgrade plan

What's still exposed (after the upgrades)

Good / Better / Best

Run more than one AI system?

A few systems isn't a few separate bills.

Most protections are platform — built once, they cover every system that shares the risk. Set a profile above, add it below, then add your others: the tool shows what securing them separately would cost versus one shared platform.

What the paid assessment actually tests — your biggest risks

These are real tests from our attack battery, chosen for your profile. The scorecard estimates; the assessment runs them against your actual AI.

Where these numbers come from — methodology & framework alignment

This section is for your IT person, auditor, or insurer — you don't need it to use the tool. It exists so they can check our work.

Severity

severity = base_weight(surface) × data_multiplier × action_multiplier — base weights reflect worst-case impact (exfiltration and irreversible actions weigh highest, cost/availability lowest); data sensitivity scales public 0.6 · internal 1.0 · PII 1.3 · PHI/financial 1.6; action authority scales read-only 0.7 · drafts 1.0 · can-send 1.4 · can-transact 1.7 (applied to action-capable surfaces).

Coverage

Each in-scope surface is modeled at three escalation levels. A basic attack is stopped by one relevant control; a fully escalated attack (level 3) requires defense-in-depth — two independent controls. Coverage is the severity-weighted share of those attack variants stopped. Surfaces with only a single possible control are flagged as un-layerable residual risk — we tell you that instead of hiding it, because the honest ceiling below 100% is what makes the rest of the number credible.

The plan

The recommended plan treats what you already have as free, forces on anything your compliance regime mandates, then finds the exact cost-minimal set of additions that maximizes coverage under your budget — proven by enumerating every configuration, not guessed. Effort figures use an illustrative unit of ≈$1,000 of implementation effort; they are a scoping estimate, not a quote.

Frameworks

  • The surface catalog spans all ten categories of the OWASP Top 10 for LLM Applications (2025); each profile scopes the subset that applies to it. Autonomous-agent deployments are assessed against the OWASP Agentic Top 10 (ASI01–ASI10) in the paid tier.
  • The flow follows the NIST AI RMF: this scorecard performs a light Map + Measure; the plan is your Manage; recurring re-assessment is Govern.
  • Our red-team batteries are informed by MITRE ATLAS.

Honest limits

This is a modeled, standards-aligned estimate from the profile you enter — it accesses none of your systems and is not a certification. The paid assessment inspects and tests the real deployment. The weights are transparently stated precisely so you can challenge them; that's the opposite of a black-box score.

Get your full, deterministic assurance report

This scorecard is a fast estimate. AIIS delivers the complete assessment — a deterministic, control-by-control evaluation of every threat surface, a red-team test plan tailored to your deployment, an implementation plan, and monthly governance so each release stays safe. We'll follow up with your detailed report and a short walkthrough.

Your profile, posture & score are included automatically.
Why AIIS

The empty middle.

Too small for the Big-Four AI-governance consultancies, too risky for the prompt-engineering hobbyists.

01

Enterprise discipline, SMB scale

Identity, security, data protection, and monitoring — the operational rigor that decides whether an AI project survives contact with a real business.

02

Standards-aligned, not invented

The risk model spans all ten categories of the OWASP Top 10 for LLM Applications (2025), and the assessment follows the NIST AI Risk Management Framework's Map–Measure–Manage–Govern flow — the vocabulary your auditors, insurers, and enterprise customers already use. Deterministic and re-runnable, so you can prove your AI got safer.

03

We say what we can't fix

Some risks have a single point of control and can't be layered away. We flag them plainly. That honesty is exactly why what we do secure holds.

How an engagement works

Start low-risk. Grow into it.

Begin with an assessment. Grow into deployment, build, and ongoing care.

Line A

Assess & Advise

The full assurance report on your AI deployment. Fixed fee, pure expertise, zero risk to your systems.

Line B

Deploy & Empower

Implement the identity & data controls — SSO/RBAC, audit logging, DLP, PII redaction — and train your team.

Line C

Automate & Build

Build the guardrails — injection defense, tool allowlists, human approval on one-way doors, and a red-team eval gate in CI.

Line D

Care & Govern

Re-run the assurance pass every release, watch for drift, report coverage monthly. Your AI stays safe as it changes.