Answer 30 questions
Five questions per dimension. Pick the answer closest to your reality. Don't overthink. The check works on accurate self-reporting, not aspirational thinking.
your auditor or attacker does.
The AI Posture Check is a free 30-question self-assessment that scores your AI security across six dimensions and maps your gaps to OWASP LLM Top 10, NIST AI RMF, and ISO 42001. Built and operated by CWS.
Five questions per dimension. Each dimension maps to specific controls in OWASP LLM Top 10, NIST AI RMF, and ISO 42001 Annex A.
AI policy, accountable owner, inventory, framework alignment.
Explore GovernanceClassification, controls, logging, vendor data terms, subject rights.
Explore DataInjection testing, input validation, output filtering, OWASP LLM mapping, red-teaming.
Explore PromptSelection, version control, hallucination testing, retirement, theft prevention.
Explore ModelRate limiting, monitoring, isolation, incident response, audit logging.
Explore RuntimeDue diligence, contracts, attestations, onboarding, continuous monitoring.
Explore VendorThe Posture Check evaluates six dimensions (governance, data, prompt, model, runtime, vendor) that map into CWS's eight-domain AI Security Program. The check gives you a fast self-scored snapshot. The full program adds AI supply chain, monitoring and response, transparency and oversight, and regulatory compliance as paid engagement workstreams.
Model provenance, third-party model risk, dataset lineage, signed-model controls.
Continuous detection across AI workloads. AI-specific incident response runbooks.
Explainability, documentation, board-level reporting, human-in-the-loop controls.
EU AI Act, NIST AI RMF, ISO 42001, sector regulators. Mapping plus audit-ready evidence.
Five questions per dimension. Pick the answer closest to your reality. Don't overthink. The check works on accurate self-reporting, not aspirational thinking.
Total score plus per-dimension scores. Color-coded tier from Foundation to Leading. Specific gap callouts referencing the questions you scored low on.
Per-dimension breakdown, prioritized recommendations, and framework-aligned next steps render right in your browser. From there: keep going alone, schedule a paid Standard Audit, or book a Discovery Call with CWS. No email required to see results.
Free self-assessment, fixed-fee paid audit, or quarterly retained program. Each engagement led by senior CWS engineers.
30-question self-assessment
Senior-engineer paid review of your specific AI deployments
Continuous AI security for portfolio-scale AI deployments
The defining LLM-application security risk catalog. The AI Posture Check questions on prompt and runtime dimensions map directly.
Read the guideAI Risk Management Framework. Govern, Map, Measure, Manage. Increasingly cited in US regulator guidance.
Read the guideInternational standard for AI management systems. Certifiable. Enterprise buyers increasingly ask for it.
Read the guideTiered risk obligations including high-risk system requirements. Phased enforcement through 2027.
Read the guideAdversary tactics and techniques against AI systems. Adversarial machine learning threat catalog.
Read the guideA free, 30-question self-assessment that scores your AI security across six dimensions: governance, data, prompt, model, runtime, and vendor. Output is a per-dimension score, an overall tier (Foundation, Developing, Mature, or Leading), and an in-browser results page with prioritized recommendations. No email required.
Eight to twelve minutes for most users. Faster if you know your environment well.
No. It is a self-assessment. You answer multiple-choice questions about your governance, controls, and posture. No technical scans. No data ever leaves your browser. We do not capture your email or any personal data to show you results.
Your results render in the browser instantly: total score, per-dimension breakdown, prioritized recommendations, and framework-aligned next steps. From there you can print the page, walk away, or click through to the CWS contact form to discuss a paid follow-up. CWS does not contact you unless you reach out first.
The free check is self-reported. A paid Standard Audit is delivered by a senior CWS engineer reviewing your actual AI deployments, including adversarial testing. The free check is calibration; the paid audit is verification.
OWASP LLM Top 10, NIST AI RMF, ISO 42001, EU AI Act, and MITRE ATLAS. Your gap report includes specific framework references for each weak dimension.
Either. Most users take it at the organization level. If you want a deployment-specific assessment with adversarial testing, the paid Standard Audit is the right path.
CWS. We are a cybersecurity professional services firm that delivers AI security programs through channel partners and directly to enterprises.
Free, 10 minutes, instant in-browser results. No email required. No sales call unless you book one.