Guest session. Reports live only in this browser. Close the window and they are gone. Create account or sign in to keep them.
Assessment

Evaluate your existing AI governance policy

Answer every control below. Yes, partial, no, or not applicable, with a short evidence note where you can. Your answers drive a maturity report scored against the PXB playbook and the four frameworks in scope.

00
Reviewer
01
Discovery and Inventory
PXB-01.1 · Estate inventory

Do you maintain a current, complete inventory of every LLM API key, AI licence (Copilot / ChatGPT Enterprise / Gemini), retrieval application, agent, and model endpoint (Azure OpenAI / Bedrock / Vertex / self-hosted) in use across the business?

The single most common gap. Without this, no policy above it holds.

NIST AI RMF · MAP 1.1NIST AI RMF · MAP 3.4NIST AI RMF · GOVERN 1.6 OWASP LLM · LLM03 OWASP Agentic · T9 MITRE ATLAS · AML.TA0002 ReconnaissanceMITRE ATLAS · AML.TA0000 ML Model Access
PXB-01.2 · Egress monitoring

Are proxy and firewall filters set for the major model endpoints, with traffic tagged by business unit?

Set proxy or firewall filters for major LLM API endpoints and tag traffic by business unit.

NIST AI RMF · MEASURE 2.6NIST AI RMF · MANAGE 4.1 OWASP LLM · LLM02 OWASP Agentic · T8 MITRE ATLAS · AML.TA0010 Exfiltration
PXB-01.3 · Shadow AI discovery

Do you use a CASB or Defender for Cloud Apps (or equivalent) to surface unsanctioned AI tools employees are pasting data into?

Employees route around bans within a week without a sanctioned path.

NIST AI RMF · MAP 4.1NIST AI RMF · MANAGE 3.1 OWASP LLM · LLM02 OWASP Agentic · T3 MITRE ATLAS · AML.TA0002 Reconnaissance
PXB-01.4 · Embedded AI features

Does the inventory include AI features quietly added to tools you already own (CRM, ITSM, analytics, code editors, collaboration)?

Features get switched on without an intake and become part of your estate.

NIST AI RMF · MAP 1.1NIST AI RMF · MAP 3.4 OWASP LLM · LLM03 OWASP Agentic · T3 MITRE ATLAS · AML.TA0001 Initial Access
02
Data Classification
PXB-02.1 · Data tiers defined

Have you formally defined which data classes (public / internal / confidential / regulated) may be sent to which category of AI tool?

Governance follows data sensitivity, not enthusiasm for a use case.

NIST AI RMF · GOVERN 1.1NIST AI RMF · MAP 2.3NIST AI RMF · MEASURE 2.10 OWASP LLM · LLM02OWASP LLM · LLM04 OWASP Agentic · T1 MITRE ATLAS · AML.TA0009 Collection
PXB-02.2 · DLP on the prompt path

Do you have DLP inspecting the prompt path to block credentials, source code, and customer information from leaving in a prompt?

The major DLP platforms all inspect the prompt path now.

NIST AI RMF · MANAGE 2.2NIST AI RMF · MEASURE 2.10 OWASP LLM · LLM02OWASP LLM · LLM05 OWASP Agentic · T8 MITRE ATLAS · AML.TA0010 Exfiltration
PXB-02.3 · Retention terms in writing

Do you have zero-data-retention or equivalent retention agreements with your model providers, in writing?

Default APIs often retain data. Close it contractually, do not assume.

NIST AI RMF · GOVERN 6.1NIST AI RMF · GOVERN 6.2 OWASP LLM · LLM02OWASP LLM · LLM03 OWASP Agentic · T8 MITRE ATLAS · AML.TA0010 Exfiltration
PXB-02.4 · Training clause review

Have you reviewed the specific tier and terms for each provider to confirm your inputs and outputs are not used to train their models?

Consumer terms and some enterprise tiers still permit provider use for model improvement.

NIST AI RMF · GOVERN 6.1NIST AI RMF · MAP 4.1 OWASP LLM · LLM04 OWASP Agentic · T1 MITRE ATLAS · AML.T0020 Poison Training Data
03
Tiered Approved Tools
PXB-03.1 · Tier 1 self-service defined

Is there a sanctioned, logged, DLP-covered Tier 1 tool set (e.g. Copilot for M365, Gemini for Workspace) with no per-use approval friction?

If the sanctioned tool is painful and the public one is easy, you lose.

NIST AI RMF · GOVERN 1.1NIST AI RMF · MANAGE 1.3 OWASP LLM · LLM02 OWASP Agentic · T3
PXB-03.2 · Tier 2 registered use

Do teams building retrieval applications or agents on Azure OpenAI / Bedrock / Vertex have to register through a defined intake process?

Registered use, not ungoverned use.

NIST AI RMF · MAP 1.1NIST AI RMF · GOVERN 3.2 OWASP LLM · LLM06 OWASP Agentic · T2OWASP Agentic · T3
PXB-03.3 · Tier 3 high-risk review

Do customer-facing systems, autonomous agents, and high-value-decision systems receive a full review (threat model, red team, HITL, kill switch) before launch?

Tier 3 is where the actual damage lives.

NIST AI RMF · MAP 5.1NIST AI RMF · MEASURE 2.7NIST AI RMF · MANAGE 2.1 OWASP LLM · LLM06OWASP LLM · LLM09 OWASP Agentic · T2OWASP Agentic · T6OWASP Agentic · T7OWASP Agentic · T13 MITRE ATLAS · AML.TA0011 Impact
PXB-03.4 · Sanctioned path is the easy path

Is the sanctioned path measurably easier and faster for employees than routing around it?

Behavioral truth. If the safe path is painful, adoption collapses.

NIST AI RMF · GOVERN 4.1 OWASP LLM · LLM02 OWASP Agentic · T3
04
Intake Process
PXB-04.1 · Use case + decision authority

Does the intake capture the use case and its decision authority (advisory vs autonomous)?

Advisory and autonomous systems carry very different risk.

NIST AI RMF · MAP 1.1NIST AI RMF · MAP 5.1 OWASP LLM · LLM06 OWASP Agentic · T2OWASP Agentic · T6
PXB-04.2 · Data classes on I/O and fine-tune

Does the intake capture the data classes touched on input, output, and any fine-tuning?

Fine-tuning bakes data into weights and cannot be unlearned cleanly.

NIST AI RMF · MAP 2.3NIST AI RMF · MEASURE 2.10 OWASP LLM · LLM02OWASP LLM · LLM04 OWASP Agentic · T1 MITRE ATLAS · AML.T0020 Poison Training Data
PXB-04.3 · Model, hosting, retention

Does the intake capture which model, its hosting location, and its retention terms?

You cannot audit what you did not record.

NIST AI RMF · MAP 3.4NIST AI RMF · GOVERN 6.1 OWASP LLM · LLM03
PXB-04.4 · Human-in-the-loop points

Does the intake capture where humans review, approve, or override the AI system?

HITL is a control only if it is documented and enforced.

NIST AI RMF · MANAGE 1.3NIST AI RMF · MEASURE 3.3 OWASP LLM · LLM06OWASP LLM · LLM09 OWASP Agentic · T6OWASP Agentic · T7OWASP Agentic · T10
PXB-04.5 · Failure mode, rollback, kill switch owner

Does the intake capture the failure mode, rollback procedure, and named kill-switch owner?

A kill switch without a named owner is a claim, not a control.

NIST AI RMF · MANAGE 2.4NIST AI RMF · MANAGE 4.1 OWASP LLM · LLM06 OWASP Agentic · T2OWASP Agentic · T13 MITRE ATLAS · AML.TA0011 Impact
PXB-04.6 · Bias and fairness scope

Does the intake determine whether bias and fairness are in scope? (HR, lending, healthcare, legal are automatic yes.)

Automatic yes for HR, lending, healthcare, legal.

NIST AI RMF · MAP 5.1NIST AI RMF · MEASURE 2.11 OWASP LLM · LLM09 OWASP Agentic · T7
05
Technical Controls
PXB-05.1 · Identity on every agent

Does every agent have its own service principal with least-privilege scopes, using managed identities rather than shared secrets or API keys?

Without this, everything else in this section is unenforceable.

NIST AI RMF · MANAGE 1.3NIST AI RMF · MANAGE 2.2 OWASP LLM · LLM06 OWASP Agentic · T3OWASP Agentic · T9 MITRE ATLAS · AML.TA0004 PersistenceMITRE ATLAS · AML.TA0007 Discovery
PXB-05.2 · Tool and action allowlists

Do agents that can email, delete, spend money, or call external systems operate under an explicit allowlist with rate limits?

Blast radius is set here.

NIST AI RMF · MANAGE 2.2NIST AI RMF · MANAGE 2.4 OWASP LLM · LLM06OWASP LLM · LLM10 OWASP Agentic · T2OWASP Agentic · T4 MITRE ATLAS · AML.TA0005 Defense EvasionMITRE ATLAS · AML.TA0011 Impact
PXB-05.3 · Prompt injection defences

Do you treat any external content (email, web, documents, retrieval results) as untrusted, with structured outputs and output filtering, and design so the blast radius is bounded when injection succeeds?

The right question is: what does the agent lose access to when it happens?

NIST AI RMF · MANAGE 2.2NIST AI RMF · MEASURE 2.7 OWASP LLM · LLM01OWASP LLM · LLM05OWASP LLM · LLM07 OWASP Agentic · T1OWASP Agentic · T6OWASP Agentic · T12 MITRE ATLAS · AML.T0051 LLM Prompt Injection
PXB-05.4 · Logging as forensic surface

Do you log every prompt, response, tool call, and retrieved document for a meaningful retention window, treating the logs themselves as sensitive with access controls?

The logs will contain the same regulated data as the prompts. Treat them accordingly.

NIST AI RMF · MEASURE 2.8NIST AI RMF · MANAGE 4.1 OWASP LLM · LLM02OWASP LLM · LLM05 OWASP Agentic · T8 MITRE ATLAS · AML.TA0009 Collection
PXB-05.5 · Rate and spend limits

Are per-agent and per-tenant rate and spend limits enforced to bound cost and denial-of-service risk?

Unbounded consumption is both a cost problem and a DoS risk.

NIST AI RMF · MANAGE 2.4 OWASP LLM · LLM10 OWASP Agentic · T4 MITRE ATLAS · AML.TA0011 Impact
PXB-05.6 · Output validation

Do you refuse to execute model output blindly (no eval on generated code, read-only SQL roles, sanitised rendering)?

Do not eval() model output. Do not run generated SQL without a read-only role.

NIST AI RMF · MANAGE 2.2NIST AI RMF · MEASURE 2.7 OWASP LLM · LLM05 OWASP Agentic · T2OWASP Agentic · T11 MITRE ATLAS · AML.T0050 Command and Scripting Interpreter
PXB-05.7 · Ongoing evaluation, not just launch review

Does every Tier 2 or Tier 3 system have a regression suite for safety, accuracy, and injection resistance, run on a schedule and before any material change?

A launch red team is a snapshot, not evaluation. Models drift.

NIST AI RMF · MEASURE 2.3NIST AI RMF · MEASURE 2.6NIST AI RMF · MEASURE 4.2 OWASP LLM · LLM01OWASP LLM · LLM04OWASP LLM · LLM09 OWASP Agentic · T5OWASP Agentic · T7 MITRE ATLAS · AML.T0043 Craft Adversarial Data
06
Third Party and Supply Chain
PXB-06.1 · AI-aware vendor questionnaire

Has your vendor questionnaire been updated to ask which model, which provider, whether your data trains their model, retention terms, sub-processors, evaluation and red-team results, and change-notification commitments?

Every SaaS vendor now claims to be AI-powered.

NIST AI RMF · GOVERN 6.1NIST AI RMF · GOVERN 6.2NIST AI RMF · MAP 4.1 OWASP LLM · LLM03 OWASP Agentic · T1 MITRE ATLAS · AML.T0010 ML Supply Chain Compromise
PXB-06.2 · Pin and scan self-hosted models

For any self-hosted models, do you pin versions, establish provenance, and scan artefacts for malicious payloads?

HuggingFace pickle exploits are real. This is a documented supply chain vector.

NIST AI RMF · GOVERN 6.1NIST AI RMF · MANAGE 3.2 OWASP LLM · LLM03OWASP LLM · LLM04 OWASP Agentic · T1 MITRE ATLAS · AML.T0010 ML Supply Chain CompromiseMITRE ATLAS · AML.T0018 Backdoor ML Model
PXB-06.3 · Contract for change

Do your provider contracts require notice of material model changes, a rollback window, and the right to re-evaluate before a new version becomes the default?

Providers rev their models. Your paper should keep pace.

NIST AI RMF · GOVERN 6.1NIST AI RMF · MANAGE 4.2 OWASP LLM · LLM03
07
People and Ownership
PXB-07.1 · Named accountable owner per system

Does every deployed AI system have a single named accountable owner in the business?

This is the Govern function of NIST AI RMF in one sentence.

NIST AI RMF · GOVERN 2.1NIST AI RMF · GOVERN 2.2 OWASP Agentic · T8OWASP Agentic · T13
PXB-07.2 · AI champions in each business unit

Do you have identified AI champions in each business unit who surface real use cases and act as the local governance touchpoint?

They know the real use cases before central governance does.

NIST AI RMF · GOVERN 3.2NIST AI RMF · GOVERN 5.1
PXB-07.3 · Training at three levels

Do you train all staff on safe usage, developers on secure agent patterns, and executives on the risk vocabulary needed to make decisions?

Same skill areas, three different depths.

NIST AI RMF · GOVERN 2.2NIST AI RMF · GOVERN 2.3 OWASP LLM · LLM02OWASP LLM · LLM05 OWASP Agentic · T10
08
Regulatory Posture
PXB-08.1 · EU AI Act scope and readiness

Have you determined whether the EU AI Act applies (extraterritorial reach if your AI touches anyone in the EU), and mapped your obligations for prohibited practices, GPAI, and any high-risk (Annex III) systems?

Prohibited and GPAI rules are already enforceable. High-risk timing may shift under the Digital Omnibus package; verify current status.

NIST AI RMF · GOVERN 1.1NIST AI RMF · GOVERN 4.1 OWASP LLM · LLM09 OWASP Agentic · T7
PXB-08.2 · NIST AI RMF alignment

Have you aligned your AI program to the NIST AI RMF core functions (Govern, Map, Measure, Manage) and the Generative AI Profile?

Voluntary framework, but de facto US baseline and often required in federal contracts.

NIST AI RMF · GOVERN 1.1
PXB-08.3 · Sector and state rules

Have you mapped the sector-specific and state rules that apply (HIPAA, GLBA, banking model risk (SR 11-7), SEC AI disclosure, Colorado AI Act, NYC AEDT, CA AB 2013, etc.)?

The state-level list grows quarterly. Map only what touches you.

NIST AI RMF · GOVERN 1.1NIST AI RMF · GOVERN 4.1 OWASP LLM · LLM09 OWASP Agentic · T7
PXB-08.4 · ISO 42001 posture

Have you decided whether to pursue ISO 42001 certification of an AI management system?

Worth pursuing if you want a certifiable AI management system.

NIST AI RMF · GOVERN 1.1
09
Incident Readiness
PXB-09.1 · AI-specific incident playbooks

Do you have written incident playbooks for: production jailbreak, prompt-injection exfiltration, harmful hallucination, agent acting outside scope, poisoned retrieval corpus?

Assume something will go wrong and rehearse it.

NIST AI RMF · MANAGE 2.4NIST AI RMF · MANAGE 4.1 OWASP LLM · LLM01OWASP LLM · LLM02OWASP LLM · LLM04OWASP LLM · LLM09 OWASP Agentic · T1OWASP Agentic · T2OWASP Agentic · T5OWASP Agentic · T6OWASP Agentic · T13 MITRE ATLAS · AML.TA0011 Impact
PXB-09.2 · Kill switch documented and tested

For every autonomous agent, is the kill switch documented and has it been pulled in a drill?

An untested kill switch is a claim, not a control.

NIST AI RMF · MANAGE 2.4NIST AI RMF · MANAGE 4.3 OWASP LLM · LLM06 OWASP Agentic · T2OWASP Agentic · T13 MITRE ATLAS · AML.TA0011 Impact
PXB-09.3 · Tabletop with legal and comms

Have you tabletopped an AI incident jointly with legal and communications?

The response is as much legal and reputational as it is technical.

NIST AI RMF · GOVERN 4.3NIST AI RMF · MANAGE 4.1 OWASP LLM · LLM09 OWASP Agentic · T7OWASP Agentic · T10
PXB-09.4 · Evidence preservation

On incident, do you snapshot model version, system prompt, tool configuration, and the offending session log at the time of the event?

Providers roll models forward. If you did not capture state, you cannot reconstruct what happened.

NIST AI RMF · MEASURE 2.8NIST AI RMF · MANAGE 4.1 OWASP LLM · LLM03 OWASP Agentic · T8 MITRE ATLAS · AML.TA0009 Collection
10
Metrics
PXB-10.1 · Activity metrics tracked

Do you track: percentage of AI use cases inventoried vs discovered, time to approve an intake, percentage of agents with dedicated identity and logging, and red-team / evaluation findings closed within SLA?

Activity metrics tell you the program is running.

NIST AI RMF · MEASURE 1.1NIST AI RMF · MEASURE 4.2
PXB-10.2 · Outcome metrics tracked

Do you track: DLP interventions on outbound prompts (and what would have leaked), count of near-miss and actual incidents with mean time to contain, and cost per business unit?

Outcome metrics tell you the program is working. Cost per BU makes finance an ally.

NIST AI RMF · MEASURE 2.7NIST AI RMF · MEASURE 4.2NIST AI RMF · MANAGE 1.4 OWASP LLM · LLM02 OWASP Agentic · T4
CAD
Cadence and Phasing
PXB-CAD.1 · Weeks 1 to 4

Have you completed the weeks-1-to-4 baseline (discovery, egress logs, shadow AI surfaced, named executive sponsor, interim acceptable-use rule)?

The foundation that everything else assumes.

NIST AI RMF · GOVERN 1.1NIST AI RMF · MAP 1.1 OWASP LLM · LLM02 OWASP Agentic · T3
PXB-CAD.2 · Months 2 to 3

Have you completed the months-2-to-3 milestones (DLP on prompt path live, Tier 1 tools rolled out with training, intake live for Tier 2/3)?

The point at which the program becomes operational.

NIST AI RMF · MANAGE 1.3NIST AI RMF · MAP 1.1 OWASP LLM · LLM02 OWASP Agentic · T3
PXB-CAD.3 · Quarter 2

Have you completed the quarter-2 milestones (technical baseline on every registered system, first tabletop)?

The point at which the technical controls become the enforced default.

NIST AI RMF · MANAGE 2.2NIST AI RMF · MANAGE 4.1 OWASP LLM · LLM06 OWASP Agentic · T2OWASP Agentic · T3
PXB-CAD.4 · Ongoing

Do you have an ongoing rhythm (vendor process updated, board metrics quarterly, regulatory posture reviewed twice a year)?

The bit programmes forget to build.

NIST AI RMF · GOVERN 1.5NIST AI RMF · GOVERN 6.2NIST AI RMF · MEASURE 4.2 OWASP LLM · LLM03
AP
Anti-Pattern Check
PXB-AP.1 · Policy first, discovery never

Have you published policy without first mapping the estate?

A published policy over an unmapped estate is decoration.

NIST AI RMF · MAP 1.1 OWASP LLM · LLM02 OWASP Agentic · T3
PXB-AP.2 · Banning the public tools and hoping

Have you relied on a ban of public AI tools without offering a sanctioned path?

Employees route around bans within a week.

NIST AI RMF · GOVERN 1.1NIST AI RMF · MANAGE 3.1 OWASP LLM · LLM02 OWASP Agentic · T3
PXB-AP.3 · One-off vendor questionnaire

Is your AI vendor assurance a one-time purchase gate rather than a continuous process?

AI features ship monthly. Assurance has to keep pace.

NIST AI RMF · GOVERN 6.1NIST AI RMF · GOVERN 6.2 OWASP LLM · LLM03 MITRE ATLAS · AML.T0010 ML Supply Chain Compromise
PXB-AP.4 · Launch red team as evaluation

Are you treating a launch red team as ongoing evaluation?

Models drift. A one-time review ages out in weeks.

NIST AI RMF · MEASURE 2.3NIST AI RMF · MEASURE 4.2 OWASP LLM · LLM01OWASP LLM · LLM04 OWASP Agentic · T5 MITRE ATLAS · AML.T0043 Craft Adversarial Data
PXB-AP.5 · Kill switch on paper

Are any of your kill switches undrilled?

If no one has pulled it in a drill, it does not exist.

NIST AI RMF · MANAGE 2.4NIST AI RMF · MANAGE 4.3 OWASP LLM · LLM06 OWASP Agentic · T2OWASP Agentic · T13 MITRE ATLAS · AML.TA0011 Impact
PXB-AP.6 · Governing the model, not the surfaces

Are you spending disproportionate effort on prompt engineering the model rather than the identity, logging, and allowlists around it?

Prompt engineering does not compensate for missing identity, logging, or allowlists.

NIST AI RMF · MANAGE 2.2 OWASP LLM · LLM01OWASP LLM · LLM06 OWASP Agentic · T2OWASP Agentic · T9
of controls answered