Self-assessment
Find your gaps before an auditor does.
A structured assessment of your AI deployment against the four capabilities of the standard — scored, mapped clause by clause to the EU AI Act, NIST AI RMF and ISO/IEC 42001, and returned as a prioritised gap register.
Questions about this assessment
Is this a certification or an audit?
No. It is a structured self-assessment designed to show you where you stand before an external assessment. It produces a gap register, not a pass mark, and it confers no compliance status. Treat it as preparation for a review rather than a substitute for one.
Is this tool itself an AI system?
No, and deliberately so. It is a deterministic rule set — a fixed question bank, fixed weights and arithmetic — which is why we can publish exactly how it scores. Under Article 3(1) of the EU AI Act an AI system is one that infers from its input how to generate outputs, and Recital 12 states plainly that the definition does not extend to systems based on rules defined solely by natural persons to automatically execute operations. Nothing here infers anything. A governance tool should be able to explain its own output completely, and one that scored you by model could not.
Are my answers stored or sent anywhere?
No. The assessment runs entirely in your browser. Answers are saved to your own device so you can return to them, and are never transmitted to any server. There is no sign-up and no tracking on the assessment itself.
Which frameworks does it assess against?
The four capabilities of the AI Human Proof standard, with every question mapped to the corresponding clauses in the EU AI Act, NIST AI RMF and ISO/IEC 42001 — and to GDPR Article 22 where the system makes decisions about people. One pass produces evidence against all of them, because the underlying controls substantially overlap.
How long does it take?
About 15 minutes. There are five scoping questions that determine which obligations apply to you, followed by 27 scored questions across the four capabilities. You can leave and return — your progress is kept on your device.
What counts as "evidenced" rather than "defined"?
Defined means a documented process exists and is followed. Evidenced means you could produce dated proof today — the assessment record, the sign-off, the log extract, the meeting minute. The distinction matters because external assessors fail organisations on missing evidence far more often than on missing controls.
This assessment supports preparation for external review. It is not a conformity assessment under the EU AI Act, not a certification, and not legal advice. Where a system is high-risk, formal conformity assessment and — for certain deployers — a fundamental rights impact assessment remain separate obligations. See EU AI Act compliance for what those involve.