Kostenlose Risikobewertung für Shadow AI
Prüfen Sie Ihre Shadow-AI-Risiken
Beantworten Sie 8 Fragen zu KI-Nutzung und vorhandenen Kontrollen. Sehen Sie einen Orientierungswert und nächste Prüfschritte. Das Ergebnis ist ohne E-Mail verfügbar.
Diese Selbsteinschätzung basiert auf Ihren Antworten. Sie scannt keine Geräte oder KI-Konten. Der Wert ist keine gemessene Wahrscheinlichkeit eines Datenvorfalls.
Wie viele Mitarbeitende hat Ihr Unternehmen?
Mehr Menschen bedeuten mehr Angriffsfläche für nicht genehmigte KI-Nutzung.
Free audit checklist
Shadow AI Risk Assessment Checklist
Aona's free interactive Shadow AI assessment provides an indicative 0 to 100 review-priority score from your answers. This checklist turns those dimensions into questions for IT, security and compliance. Record the teams, devices, AI services and review period in scope, then validate the reported controls with observed evidence and synthetic tests.
Visibility and discovery
- Build a scoped AI inventory
For the teams, devices, client paths and review period in scope, which AI apps were observed and which areas remain unverified?
- Move beyond surveys
Is your visibility based on real usage telemetry rather than self-reporting or an annual questionnaire?
- Map the data flows
Do you know which AI tools receive company data via typed prompts, copy-paste or file uploads?
Policy and acceptable use
- Publish a written AI policy
Is an AI acceptable-use policy written, communicated and acknowledged by every employee?
- Name approved tools and banned data
Does the policy list approved tools, prohibited data categories and an approval path for new tools?
- Enforce it technically
Is the policy backed by controls at the point of use, rather than relying on trust alone?
Controls at the point of use
- Block sensitive data in real time
Can you stop PII, client data, credentials or source code before it reaches an AI tool?
- Test redaction where supported
For the chosen AI app, input and client path, does a synthetic test confirm which data is removed and whether the remaining content is permitted?
- Cover files, not just prompts
Do your controls inspect file uploads as well as typed text?
Sanctioned AI adoption
- Offer approved alternatives
Have you sanctioned enterprise-grade options for the ChatGPT, Copilot, Gemini and Claude use cases employees already have?
- Review account and service settings
For each approved AI service and account type, have owners confirmed training use, identity, retention and processing-location settings?
- Make approval fast
Is there a well-known, fast route to request a new AI tool so employees do not route around IT?
Incident readiness
- Have a response plan
Is there a documented plan for an AI-related data exposure, with named owners and timelines?
- Test your detection
Would your monitoring actually flag sensitive data pasted into an unsanctioned AI tool today?
- Learn from near-misses
Are past AI incidents and near-misses reviewed for root cause and fed back into controls?
Device and identity foundations
- Enrol devices
Are endpoints under MDM or Intune so AI controls can be deployed and enforced at scale?
- Centralise identity
Is access to sanctioned AI tools governed through SSO, with Entra or a similar identity provider?
- Account for unmanaged devices
Do you know how much AI usage happens on BYOD and unmanaged devices, and is it in scope?
One A4 page, no email required. You can also print this section directly from your browser.
FAQ
Häufige Fragen
Wie wird meine Risikobewertung für Shadow AI berechnet?
Ist die Bewertung kostenlos?
Was erhalte ich am Ende?
Wie unterscheidet sich das von einer Compliance- oder Reifegrad-Bewertung?
What is a Shadow AI risk assessment?
Prüfen Sie die Kontrollen hinter Ihren Antworten
Wählen Sie eine KI-App, den geplanten Zugriff per Browser oder Desktop-App und einen synthetischen Prompt oder eine Datei. Prüfen Sie mit Aona die Richtlinienreaktionen, Belege und Voraussetzungen für die Installation.