Toolbox

All tools in the Toolbox

Appendix D · Interactive tool

AI risk assessment

A structured walkthrough of the risks in your AI use. Answer the questions and you get a summary and the points needing the most attention. Everything is calculated in your browser.

Inventory

Is there a register of every AI system used in the organisation?

Does the register also include informally used tools (shadow AI)?

Does every AI system have a named owner?

Data handling

Is it defined which data may and may not be entered into external AI services?

Are there controls preventing personal data or sensitive information from being shared with external AI services?

Is it established where data is processed and stored (jurisdiction)?

Do contracts govern the supplier right to use entered data for model training?

Model security

Have the AI systems been tested for robustness against adversarial attacks and prompt injection?

Are there processes for handling hallucinations and incorrect output?

Is interaction with AI systems logged for traceability?

Human oversight

Is there human oversight for decisions of material consequence that are based on AI?

Is it clear who carries responsibility for AI based decisions?

Are affected parties informed that AI is used in decision processes?

Regulatory compliance

Have you assessed which AI systems are classified as high risk under the AI Act?

Are AI risks included in the general risk analysis?

Is there an AI policy approved by the leadership?