Executive self-assessment

Shadow AI & Shadow IT Risk Assessment

Measure how much unsanctioned SaaS and AI use can create data, identity, customer, and compliance exposure—and whether the organization can see it.

Result logic

What this tool evaluates

Evaluates visibility, approved-use rules, sensitive data, vendors, identity, monitoring, reporting culture, and remediation.

Visibility 22%
Approved use 18%
Data exposure 22%
Vendor & identity risk 20%
Reporting & remediation 18%
0 / 10
0%
01 Can IT/security identify the major SaaS and AI tools employees use for business work?
02 Is there visibility into browser extensions, OAuth grants, unmanaged SaaS, and high-risk AI usage?
03 Is there a practical approved-tools list and a fast path for requesting new tools?
04 Are AI and SaaS rules specific enough that employees know what they may use and what data is restricted?
05 Are customer, personal, confidential, source code, credential, and regulated data restricted from unapproved tools?
06 Can the organization detect or investigate material sensitive-data movement into unapproved tools when necessary?
07 Are material AI/SaaS vendors reviewed for security, privacy, retention, training/data use, subprocessors, and location?
08 Are business SaaS/AI identities governed through SSO/MFA, joiner/mover/leaver, and ownership where appropriate?
09 Can employees report unsafe tools or request exceptions without fear or excessive friction?
10 Are recurring Shadow IT/AI causes fixed by improving approved alternatives, process speed, and guidance?