Where does your organization stand on AI risk today?
That is the question printed on the back of the book, and this is the assessment that answers it. Twenty questions across the four Culture AIR-MAP™ phases, about 10 minutes, free. You get a stage placement, a reading on each phase, and three actions to start on Monday.
Everything here is Lite Culture AIR-MAP™ Self-Assessment, reproduced from Gears Don’t Guess, Appendix A (canonical PDF, Tribe Copy).
This browser will not let the page keep your progress, so a refresh starts you over. The assessment itself works normally.
Before you start
This assessment places your organization on the Culture AIR-MAP™ maturity scale and points to your next move. It is the Lite version. You leave with a four-stage placement, three Monday-morning actions, and a one-page scorecard you can take to your management team or your board.
- How long
- About 10 minutes on your own.
- What it asks
- 20 questions, plus three over-control signals per phase.
- What you get
- A stage placement, a per-phase reading, and three actions.
How to score
Each question scores 0, 1, or 2. Sum the five questions per phase for a phase score from 0 to 10. Sum the four phase scores for a total from 0 to 40.
- 0No. You don’t do this. Or you used to and stopped. Or you’ve talked about it but no one owns it.
- 1Partial. You do this informally, inconsistently, or in pockets. It happens often enough to be visible but not often enough to be reliable.
- 2Yes. You do this, you’ve documented it, and it operates on a known cadence. Someone owns it.
If you can’t answer a question without checking with someone first, that’s information too. Score it 0 for now and move on. The goal of the Lite assessment is a placement, not a perfect score. The uncertain answers are part of your next move.
Phase 1. Discovery and Inventory
Maps to Part 2 (Chapters 3 through 6).
Discovery and Inventory is where you map every AI tool, workflow, and integration in use today. The phase answers one question: what’s actually running?
Phase 2. Measure and Score
Maps to Part 3 (Chapters 7 through 9).
Measure and Score is where you assess your governance maturity against an honest standard. The phase answers: where does our program stand, and can we show it?
Phase 3. Mitigation and Innovation
Maps to Part 4 plus the start of Part 5 (Chapters 10 through 13).
Mitigation and Innovation is where you close the gaps the assessment revealed and adjust the controls that have drifted into over-control. The phase answers: are we lowering risk in a way that still lets people do useful work?
Phase 4. Maintenance
Maps to the rest of Part 5 plus Part 6 (Chapters 14 through 17).
Maintenance is the ongoing operating discipline that keeps the program working as AI vendors, tools, and use cases keep changing. The phase answers: will this program survive the next twelve months without falling apart?
Lite Culture AIR-MAP™ Self-Assessment
· gearsdontguess.com
Your result
Over-control found
Organizational maturity
0/ 40
Forming
No stage is claimed.
Your total reached the Leading band. The book reserves that stage for four phases in the 6 to 10 zone with no over-control signal firing.
Your phases
Phase 1.Discovery and Inventory
0 / 10
Basic controls
Phase 2.Measure and Score
0 / 10
Basic controls
Phase 3.Mitigation and Innovation
0 / 10
Basic controls
Phase 4.Maintenance
0 / 10
Basic controls
Your three Monday-morning actions
Printing uses your browser's own "save as PDF" option. The file is written on your machine and never leaves it.
Subscribe to Inflection Point
Inflection Point is Kip Boyle's newsletter, every other week, on what is actually changing in AI and cyber risk. It starts as soon as you subscribe, and a separate note goes out when the templates and the one-page scorecard are up. Your answers above stay in this browser and are never sent anywhere.
Email signup opens shortly. Check back, or reach Cyber Risk Opportunities directly at info@cyberriskopportunities.com.
The scale, in full
Everything the assessment scores against, straight from Appendix A. Read it before you answer or after you see a result. It does not change either way.
Phase scoring: the innovation-balance scale
| Phase score | Zone | What it means |
|---|---|---|
| 0 to 2 | No governance | High risk. The phase is essentially unmanaged. |
| 3 to 5 | Basic controls | Moderate risk. The phase exists in pockets but isn’t reliable. |
| 6 to 10 | Balanced governance | Optimal. The phase reduces risk without blocking useful work. |
| Any score, if a signal below fires | Over-controlled | Innovation blocked. Failure mode on the same scale as 0 to 2. |
Over-control is rare to self-diagnose, because most management teams don’t recognize it in their own organization. So apply this cue. If any of the three signals below describe a phase, mark that phase over-controlled no matter what the questions added up to and follow the over-control next-move guidance in the stage table.
How to spot over-control in a phase:
- The cycle time for approving a new AI tool exceeds 12 weeks from request to answer.
- Employees route their work around the approved path because the path is slower than the work.
- Tools sit on the approved tools list with zero usage three months after approval.
If you see any one of those, you have an over-control problem in that phase even when your other answers look strong. Over-control kills programs the same way no controls do, just more quietly.
Total interpretation: organizational maturity
| Total score | Stage | What the organization usually looks like |
|---|---|---|
| 0 to 12 | Forming | No inventory, no classification, no tiers, no exception process. AI risk is unmanaged. Shadow AI is in use; no one is tracking it. The conversation is still “should we ban it.” |
| 13 to 22 | Building | Inventory exists. Classification card published. Approved tools list under construction or freshly published. Program owner named, but the role is still defining itself. Specification work hasn’t started. |
| 23 to 31 | Operating | Program owner active and respected. Specifications written for high-stakes workflows. At least one specification metric tracked. Board update produced quarterly. Vendor diligence run on new AI vendors. |
| 32 to 40 | Leading | All four phases score in the 6 to 10 zone with no over-control signal firing. Maintenance cadence has run at least one full cycle. Over-control is monitored on the same scale as under-control. AI risk is a standing category on the risk register. |
What to do next, by stage
Three Monday-morning actions per stage. Each action names the chapter you will want to return to.
Formingtotal 0 to 12
- Run the financial-records sweep this week. Corporate cards, accounts payable, expense reports, last 90 days. Search for AI vendor names. You’ll find tools no one told you about. That’s the point. (Chapter 3; Chapter 13 Days 1 to 30.)
- Publish the data classification card. Three levels: Public, Confidential, Restricted. One page. Restricted data goes only to a local LLM. (Chapter 4.)
- Name the program owner. A line-of-business person with formal authority and informal trust. Not the CISO. Not the CIO. Not the head of IT. (Chapter 7.)
Buildingtotal 13 to 22
- Publish your approved tools list, even with three tools on it. A short visible list beats a long list that’s in progress. Your employees need a path. (Chapter 13, Days 31 to 60.)
- Write a specification for one high-stakes workflow this week. Pick something your team already uses AI for. Write what a correct output looks like before anyone prompts the AI again. (Chapter 8 Habit 1.)
- Add one specification metric to your next status meeting. The easiest place to start is “AI outputs rejected after review this month.” Track it for one quarter. If the number is zero, you’ve learned something important. (Chapter 8 Habit 5; Chapter 9.)
Operatingtotal 23 to 31
- Run the four-question vendor diligence on your most data-sensitive AI vendor. Does it learn from your data? What’s the model lineage? What can it do without a human? And who are its vendors? One vendor, one to three hours. (Chapter 12.)
- Identify one over-controlled area and unlock it. Find one place where the policy is blocking the work it was meant to enable. Adjust the control instead of adding another one. (Chapter 6; Chapter 15.)
- Draft the calibrated internal-message template with your General Counsel. Half a day with the General Counsel. Save it where your management team can find it on a Saturday morning. The first time you need it, you’ll spend minutes instead of hours. (Chapter 16.)
Leadingtotal 32 to 40
- Run a quarterly failure-pattern review. Your own incidents plus published cases. Apply at least one lesson to your controls. The pattern is the asset; isolated incidents aren’t. (Chapter 17.)
- Audit each phase for over-control signals. Use the three cues above. Over-control hides best in mature programs because mature programs don’t look like they’re failing. (Phase scoring overlay above.)
- Pressure-test the program owner role for succession. If your program owner left next week, who picks it up? If the answer is “no one” or “we’d hire,” your program isn’t durable yet. (Chapter 7.)
Over-control override
If any phase is marked over-controlled, treat that phase as your priority regardless of total score. Pick the matching action below.
- Phase 1 over-controlled. Cut your inventory or classification process to one page and one weekly meeting. Detailed inventory you can’t keep current is worse than a one-page inventory you can.
- Phase 2 over-controlled. Cut a measurement, dashboard, or review from your cycle. Programs over-controlled in Phase 2 die from measurement overhead, not under-measurement.
- Phase 3 over-controlled. Apply the Operating action 2 above (identify one over-controlled area and unlock it). Set a date for the unlock.
- Phase 4 over-controlled. Cut a recurring review meeting or cadence from your operating rhythm. If three quarterly reviews could be one annual review with the same effect, make the change.
When the Lite assessment isn’t enough
The Lite assessment places you on the maturity scale and points to your next move. It doesn’t run the program for you. Three signals tell you it’s time for a deeper engagement:
- The score reveals work too large for your existing operations to absorb.
- Regulators or auditors require a documented assessment.
- An incident has just happened, and the next twelve months will be measured against your response.
If one of these describes your situation, learn more about the full Culture AIR-MAP™ engagement at air-map.io.