Évaluation gratuite du risque Shadow AI
Faites le point sur vos risques Shadow AI
Répondez à 8 questions sur l’usage de l’IA et vos contrôles actuels. Consultez un score indicatif et les points à examiner. Aucun e-mail requis pour le résultat.
Cette autoévaluation repose sur vos réponses. Elle n’analyse ni les appareils ni les comptes IA. Le score ne mesure pas une probabilité de violation de données.
Combien de collaborateurs compte votre organisation ?
Plus il y a de personnes, plus la surface d'usage d'IA non autorisée est étendue.
Free audit checklist
Shadow AI Risk Assessment Checklist
Aona's free interactive Shadow AI assessment provides an indicative 0 to 100 review-priority score from your answers. This checklist turns those dimensions into questions for IT, security and compliance. Record the teams, devices, AI services and review period in scope, then validate the reported controls with observed evidence and synthetic tests.
Visibility and discovery
- Build a scoped AI inventory
For the teams, devices, client paths and review period in scope, which AI apps were observed and which areas remain unverified?
- Move beyond surveys
Is your visibility based on real usage telemetry rather than self-reporting or an annual questionnaire?
- Map the data flows
Do you know which AI tools receive company data via typed prompts, copy-paste or file uploads?
Policy and acceptable use
- Publish a written AI policy
Is an AI acceptable-use policy written, communicated and acknowledged by every employee?
- Name approved tools and banned data
Does the policy list approved tools, prohibited data categories and an approval path for new tools?
- Enforce it technically
Is the policy backed by controls at the point of use, rather than relying on trust alone?
Controls at the point of use
- Block sensitive data in real time
Can you stop PII, client data, credentials or source code before it reaches an AI tool?
- Test redaction where supported
For the chosen AI app, input and client path, does a synthetic test confirm which data is removed and whether the remaining content is permitted?
- Cover files, not just prompts
Do your controls inspect file uploads as well as typed text?
Sanctioned AI adoption
- Offer approved alternatives
Have you sanctioned enterprise-grade options for the ChatGPT, Copilot, Gemini and Claude use cases employees already have?
- Review account and service settings
For each approved AI service and account type, have owners confirmed training use, identity, retention and processing-location settings?
- Make approval fast
Is there a well-known, fast route to request a new AI tool so employees do not route around IT?
Incident readiness
- Have a response plan
Is there a documented plan for an AI-related data exposure, with named owners and timelines?
- Test your detection
Would your monitoring actually flag sensitive data pasted into an unsanctioned AI tool today?
- Learn from near-misses
Are past AI incidents and near-misses reviewed for root cause and fed back into controls?
Device and identity foundations
- Enrol devices
Are endpoints under MDM or Intune so AI controls can be deployed and enforced at scale?
- Centralise identity
Is access to sanctioned AI tools governed through SSO, with Entra or a similar identity provider?
- Account for unmanaged devices
Do you know how much AI usage happens on BYOD and unmanaged devices, and is it in scope?
One A4 page, no email required. You can also print this section directly from your browser.
FAQ
Questions fréquentes
Comment mon score de risque Shadow AI est-il calculé ?
L'évaluation est-elle gratuite ?
Qu'est-ce que j'obtiens à la fin ?
En quoi est-ce différent d'une évaluation de conformité ou de maturité ?
What is a Shadow AI risk assessment?
Vérifiez les contrôles derrière vos réponses
Choisissez une application d’IA, un accès via navigateur ou application de bureau et un prompt ou fichier synthétique. Examinez avec Aona les réponses de la politique, les preuves et les prérequis d’installation.