ai · security · skills
← Assessments

What a finished pack can look like

Compatible-standard reports are lenses on AI Controls Matrix (AICM) answers from the function diagnostic — the AI Consensus Assessments Initiative Questionnaire (AI-CAIQ) is the attestation view of that spine, shown as a sample. Not certification.

Govern · maturity coverage · 2 of 4

Your team adopted AI before you decided anything.

Data Security. Answer for Hooli.

Pick the line that matches where you are today, least to most mature. Each question is a real control objective; the verification note says where to confirm it. 10/10 to answer.

Re-assessing Hooli. A rated sample: illustrative answers are loaded, nothing is saved. Change what improved and the maturity and the gate recompute live.

Data Security
DSP-01Is there a written rule for how data used by AI is protected and kept private?

verify · Ask for the data security & privacy policy and check it addresses AI training and inference data.

DSP-04Is the data flowing into and out of your AI classified by how sensitive it is?

verify · Sample the data feeding a model and check whether each source carries a sensitivity label.

CEK-03Is sensitive AI data encrypted, both stored and in transit?

verify · Confirm encryption on the AI data stores and the channels carrying training/inference data.

DSP-07Is data protection built into how AI data pipelines are designed, not bolted on after?

verify · Review a recent pipeline design doc for protection controls decided up front.

DSP-08Are privacy protections (minimisation, purpose limits) applied by default to personal data the AI touches?

verify · Check whether personal data is minimised and purpose-limited before it reaches a model.

CEK-12Are the encryption keys protecting AI data rotated and managed on a defined schedule?

verify · Pull the key-management records: rotation dates and ownership for the AI data keys.

DSP-09Do you run a data protection impact assessment when AI processing could affect people’s privacy?

verify · Ask for the most recent impact assessment tied to an AI use case and its refresh date.

DSP-17Does the most sensitive data the AI handles get the strongest protection, verified by evidence?

verify · Take the highest-sensitivity data class and trace its controls end to end with evidence.

Governance
HRS-15Are the data security and privacy team trained on using AI safely and verifying its output?

verify · Ask for this team’s training record and whether it covers verifying AI output.

GRC-15Is there a named person accountable for reviewing how AI uses sensitive data?

verify · Get the name and the review cadence; confirm it is a real responsibility.