The Shadow AI Self-Audit: Five Questions to Run on Your Own Organisation
A five-question self-audit you can run on your own company in about five minutes. No tool, no install, no gate. Find out where your AI audit trail actually stops.
Most companies don't have an AI problem. They have an unmeasured one.
The difference matters. A problem you can name, you can fix. A gap you can't see, you can't close. This page is a five-question audit you can run on your own organisation in about five minutes. No tool, no install, no email required.
It's not a quiz. There are no right answers. There's only whether you can answer them with a real yes, or whether the honest answer is "I'd have to go find out."
Run it. Then score yourself at the end.
How to use this
Five questions. Answer each one the way your organisation would actually answer it - not the way you'd hope it would.
For each question, be honest about the gap. A "yes" counts only if you could produce the evidence today, not next week.
At the end, count your real yeses. That number is where you stand.
The five questions
1. Can you name every AI tool in use?
Not the ones on the approved list. Every one.
The personal subscriptions. The free tiers. The tool someone found that "works fine." The one in a spreadsheet that's never been mentioned in a meeting.
What a yes looks like: you can list them, and the list is current, not from a meeting three months ago.
What a no means: your actual AI inventory is bigger than your approved one, and the difference is the exposure.
The tell: if your inventory lives in a personal spreadsheet on someone's laptop, it's not an inventory. It's a liability you don't know about.
2. For each tool, what can it reach?
Not what it's supposed to reach. What it can reach.
Does it have access to customer data? Financial records? Source code? Internal documents? Can it write, or only read? Can it act, or only suggest?
What a yes looks like: you can say, for each tool, what it can touch and what it can't.
What a no means: the boundary is a policy, not a control. And a policy doesn't stop anything.
The tell: if the answer is "it depends on who's using it," the tool doesn't know its own limits. That's the gap.
3. What runs unattended, and what waits for a human?
This is the approval threshold question. The one that separates a governed environment from an ungoverned one.
Some actions are low-risk and high-frequency - the AI should just do them and log them. Other actions cross a line - money moves, data leaves, a record changes - and those should stop and wait for a person.
What a yes looks like: you can point to the line. You know which side of it each action falls on.
What a no means: everything either runs or nothing does. There's no threshold, so there's no control.
The tell: if you can't name a single action that's required to wait for a human, you don't have thresholds. You have hope.
4. If it touched something sensitive, where does the trail stop?
This is the one that matters most.
If the AI in your environment moved a sensitive record this week, can you show what it touched, who authorised it, when, and what it did with it afterwards?
What a yes looks like: the answer is a record you can pull, not a process you'd have to reconstruct.
What a no means: the trail stops at the tool. And that's exactly where a breach stops being an incident and becomes a liability you can't explain.
The tell: if you'd have to "go find out," the trail doesn't exist. It's assumed. And assumed trails don't hold up in a review, a regulator's office, or a court.
5. Who would you call - and would they know?
The last question is about the person, not the tool.
If this surfaced tomorrow, who owns it? And more importantly - do they already know, or would they be finding out for the first time?
What a yes looks like: there's a named owner, and they're already in the loop.
What a no means: the gap is owned by nobody, which means it's owned by everyone, which means it's owned by no one.
The tell: if the answer to "who owns this?" is "that's a good question," you've found your gap.
Score yourself
Count the questions you could answer with a real yes - evidence you could produce today, not next week.
| Real yeses | Where you stand |
|---|---|
| 5 | You're in the minority who'd know. The trail holds. Keep it that way. |
| 3–4 | Partial visibility. You can see most of it, but the trail has a gap somewhere. Find it before it's found for you. |
| 1–2 | Unmeasured. You have AI in the environment and no reliable way to say what it did. |
| 0 | The trail stops at the tool. This is the most common state - and it's fixable. |
What the numbers say
We surveyed 141 engineers across 92 companies. The headline finding: 87% had no formal process for approving the AI tools their teams use.
Not "we're working on it." Not "it's on the roadmap." No.
And the usage was fragmented - at most companies, no two engineers used the same tool.
That's not a failure of intent. It's what happens when there's no shared decision about what's allowed. Each person optimised for their own speed, and the organisation ended up with a dozen invisible AI surfaces it can't see, let alone govern.
If you scored 1–2 or 0, you're not an outlier. You're the majority. And that's not a comfort - it's a reason to be the one who closes the gap first.
The snapshot vs the full audit
This page is a snapshot. It tells you where the gap is. It doesn't tell you the size of it.
The full audit does. It's a vendor-neutral report that maps every AI tool in your organisation, what each one can reach, and - the part most people haven't thought about - where the audit trail actually stops.
Free. Nothing installed. Nothing to rip out. You get the report either way, whether you ever talk to us again or not.
You don't owe us a decision. You owe yourself the map.
Run the full AI Exposure Audit →
A note on what this is not
This isn't a pitch. It's a mirror.
If you ran the five questions and got a real yes on all five, close this tab. You're in the 3%, and that's the point of the audit - to find out, not to be sold.
If you didn't, the gap is real, it's common, and it's fixable. And the cheapest way to find out exactly where it is is the full audit.
That's the whole thing. No urgency, no countdown, no "limited spots." The gap doesn't care about your quarter. It just needs to be seen.