AI governance means having clear oversight, rules and accountability for how AI is used. It helps organisations understand which AI tools are being used, what data is involved, who is responsible, what risks may arise, and how AI use is reviewed, monitored and controlled.
This questionnaire helps us understand how AI tools, AI-enabled systems and AI-related risks are managed across your organisation. There are no right or wrong answers. If you are unsure about anything, select or write "Not sure".
- This is not a formal audit, legal compliance review or certification assessment.
- Do not include names, client details, service-user information, confidential case details or personal data in your answers. Describe situations, roles, tools and processes in general terms only.
- Your responses are stored securely for up to 12 months, used solely for this assessment and other related work, and shared only with our AI provider (Anthropic) to help analyse your data, after which they are discarded. All reports are professionally reviewed by a qualified consultant before delivery.
Tick one, this helps us understand your regulatory context.
Briefly describe your main services or activities.
Tick all that apply.
Approximate figures are sufficient. Enter zero or Not applicable where a category does not apply.
Tick all that apply.
This is different from simply being aware of some AI use. It means actively checking across every team, service and role, including tools staff, volunteers or contractors may have adopted informally without it being approved or recorded.
Tick all that apply. Include tools built or trained in-house, not just third-party or off-the-shelf AI.
What does API mean? An API lets one system or tool connect directly to an AI model or service behind the scenes. For example, a website, dashboard or internal tool that sends information to OpenAI, Anthropic or another AI provider automatically.
This is your organisation's AI use case register, a working list of AI tools and uses, not a directory of every AI-branded feature in every product. It does not need to cover every tool, just the ones that matter most for risk, cost or reliance. A rough sense of purpose, provider and who is affected is far more useful than a perfectly completed table. If the risk level is not yet known, say so, that uncertainty is itself a useful finding.
| Tool / System | Purpose | Provider | Who Uses It | Data Entered | People Affected | Internal Responsible Role | Known / Suspected Risk | Approved? |
|---|
Select all that apply. The same tool may fit more than one statement because the statements capture different facts. For example, an organisation-operated questionnaire that connects to an existing AI service fits both the connection or configuration statement and the developed or commissioned tool statement. When you select an option, we will ask who directly interacts with the AI covered by it. You are not being asked to determine your organisation's legal status.
This is about whether children are likely to use the service in reality, not whether access is merely technically possible. Consider the service's subject matter, presentation, marketing, access controls, user evidence and whether similar services are used by children. Select Not sure if this has not been assessed.
For example: internal use, use involving personal or sensitive data, use affecting decisions about clients, customers, service users or residents, safeguarding-related use, automated decision-making, or developing/training an AI model in-house.
Tick all that apply. If no AI risk assessment has been carried out yet, select that option rather than guessing at factors, this gives a clearer and more accurate picture than an inaccurate answer.
For example risk scoring, eligibility assessment, prioritisation, safeguarding triage, treatment or coaching planning, or service/product recommendations.
This asks about the organisation's general review practice across its AI uses. The next question separately checks whether any particular system makes a final decision about an identifiable individual without meaningful human involvement.
This is a narrower legal screening question. Answer Yes if even one system does this, even if human review applies to most other AI-supported outcomes.
A legal effect changes or determines someone's legal rights, legal status, contractual position or entitlement. A similarly significant effect has a serious and noticeable impact on their circumstances, choices or opportunities. Examples may include access to employment, pay, credit, insurance, housing, education, healthcare, benefits or an important product or service. Routine low-impact recommendations, content ordering or administrative assistance would not normally qualify, although the same outcome may be significant for a child or someone experiencing vulnerability. Select Not sure if the likely practical impact has not been assessed.
For example: inaccurate outputs, unsafe responses, bias or unfair treatment of particular groups, poor explanations, over-reliance by staff, or outcomes that cannot be justified.
This applies where a person communicates directly with an AI chatbot, assistant or other interactive system, or where AI has a material role in an outcome affecting them and knowing about that role would help them understand or respond to it. It does not normally apply merely because someone used AI behind the scenes for research, brainstorming, drafting or administration, where a person reviewed the work, took responsibility for it and the AI did not materially determine the outcome. Select Not applicable only if nobody interacts directly with AI and AI does not materially influence an outcome affecting them. The later EU AI Act questions separately check specific legal disclosure duties.
This applies only where a decision is made without meaningful human review and may have a legal or similarly significant effect on an identifiable individual. The question is disabled automatically where the preceding answers confirm that it does not apply.
This includes any uses that require senior approval or are not allowed at all. For example: entering client, customer or therapy records into public AI tools; using AI for safeguarding or eligibility decisions without human review; uploading special category data such as health, disability, immigration or criminal record information; or using AI for recruitment scoring without assessment.
This means checking the external provider, not just deciding whether the AI use case is allowed. It includes standalone AI tools, AI features built into existing software, AI assistants, chatbots, transcription tools, analytics tools or other external services that use AI.
Tick all that apply. If a provider assessment process has not been set up yet, select that option, this is a normal starting point, not a mark against you.
If you are a sole trader or the only person responsible for the organisation, select the option that says so, this is not treated as a gap, just a different structure.
This means internal guidance, a policy, an acceptable-use statement or other written rules. Professional qualifications or training do not by themselves mean that organisational guidance exists.
Include relevant courses, qualifications, continuing professional development, role-specific instruction or recorded internal training.
Include tools supplied by the organisation, personal accounts used for work, and AI features built into other software.
This may be included in onboarding, contracts, operating instructions, policies or role-specific training.
Equivalent does not require identical training. It means that people carrying out comparable work receive guidance covering the same relevant risks, rules and responsibilities.
Examples include data protection, equality, consumer, employment, confidentiality, intellectual-property, professional and sector-specific requirements. EU AI Act requirements may also apply where there is an EU connection.
Personal data is information relating to an identified or identifiable living individual. It includes names, contact details, customer and employee records, identifiers, location data, recordings, photographs, opinions and information that can identify someone when combined with other data. A DPIA is a structured process for identifying and reducing data-protection risks. It examines what personal data will be used, why it is needed, who may be affected, what could go wrong and which safeguards are required. A DPIA must be completed before processing data in a way that is likely to result in a high risk to individuals.
Tick all that apply. The "systematic and extensive evaluation" option below has a plain-English explanation underneath it, since the legal wording is dense.
Tick all that apply.
For example funder or commissioner contracts, client/customer contracts, data processing agreements, confidentiality clauses, or restrictions on the use of third-party AI tools.
Tick all that apply.
Tick all that apply. These are a small number of AI uses that are banned outright under the EU AI Act, regardless of how carefully they are used. The questions after this one ask about a different thing, a duty to tell people when AI is being used, so you may see a similar-sounding topic again below, that is not a mistake.
The three questions below are separate from the checklist above. They ask about a duty to disclose that AI is being used, not about whether the use is banned, so it is possible to answer yes here even if none of the banned categories above applied, and vice versa.
This is about a disclosure duty, not a ban, you may have already mentioned a similar, narrower situation above if it also fell within a banned category, that does not need repeating here in a different way, just answer for this system as deployed.
For example an AI-generated or AI-edited video, image or audio clip that looks or sounds real. This is about a duty to label the content as AI-generated, not about whether making it is allowed.
This applies to AI-generated or AI-edited text published for the public, for example a news-style or public-interest article, not routine AI-assisted writing that a person reviews and takes responsibility for.
Tick up to three.
Thank you for completing this questionnaire. Your responses are being reviewed by Social Catalyst UK and a personalised report will be emailed to you shortly.
If you have any questions in the meantime, please contact antony@socialcatalystuk.com.