How scoring works

How the AI Posture Check scores your security.

Up to five weighted questions drawn from six dimensions, ending at one of four stages from Crawl to Sprint. Here is exactly how it works.

Questions
Up to 5, adaptive from your answers
Stages
4: Crawl, Walk, Run, Sprint
Axes
Program across, controls in operation up
Frameworks
OWASP LLM Top 10, NIST AI RMF, ISO 42001
The Posture Quadrant
RUN Controls running ahead of the program SPRINT Program and controls in place and audited CRAWL No sanctioned AI and no policy WALK Policy and owner first, controls uneven PROGRAM · POLICY, OWNER, INVENTORY, VENDOR TERMS → CONTROLS IN OPERATION · PROMPT, MODEL, RUNTIME → EXAMPLE PLACEMENT · YOUR DOT IS DRAWN FROM YOUR ANSWERS YOU · Q 03
An example placement. Yours is drawn from your own answers.
How it works

How the AI Posture Check works

Three answers to a question at a time, each one chosen from what you answered before.

01

Answer up to five questions

Each question is chosen from what you answered before. Pick the answer closest to your reality and don't overthink it. The check only works if you answer with what is true today.

02

Watch your position move

Each answer moves a dot on the Posture Quadrant: program across, controls up. Hover an answer before you pick it to see where it lands.

03

Choose how your stage is delivered

Your stage, where you are and what moves you to the next stage, is sent to your work email or talked through live with a CWS engineer. The stage itself never shows on screen.

Scoring rules

Every branch has a threshold.

Your first answer picks one of four branches. Each branch can end at one of two neighbouring stages, and its remaining questions are the ones that separate those two. The weights of your answers are summed and compared to that branch's threshold. The thresholds are a first cut by CWS engineers, not calibrated against a dataset, and we will say so until they are.

0 Absent, or no AI in scope yet1 Aware of the gap, or informal only2 In progress or partially in place3 Documented, operational, audited
BranchStages it separatesThresholdMaximum weight
Branch A Always Crawl Not applicable 6
Branch B Crawl or Walk 8 13
Branch C Walk or Run 9 14
Branch D Run or Sprint 12 15
Six scoring dimensions

Coverage without overlap.

Each OWASP LLM Top 10 risk and each NIST AI RMF function maps to one of these six dimensions.

What you receive

You choose how your stage arrives.

Both paths give you the same result: your stage, the move to the next one, and the framework citations behind it.

By email

Your stage, from Crawl to Sprint, the one move that takes you to the next stage, and the framework citation behind every question you answered, written so you can forward it to your board.

In a live conversation

Twenty minutes with a CWS engineer who closes these gaps for a living, free. They walk through your stage, answer the question it raises, and tell you plainly whether a paid audit is worth booking yet.

Privacy

What happens with your answers.

Your answers stay in this browser tab and clear when you close it. The tool resolves your stage client-side, and nothing about your result shows on screen until you choose how to receive it.

Two things leave the page on their own. Your stage and the weight of each answer are recorded in our site analytics with no name or email attached, so we can see which gaps are common. And if you choose the live conversation, your stage and weight travel as URL parameters to wearecws.com/contact.

If you give a work email, it is used once, to send you your stage. If you choose the live conversation instead, a CWS engineer follows up once, for that conversation. CWS does not contact you beyond the delivery you chose.

Questions

The questions we get most.

Why these six dimensions?

They map to the way AI security risk surfaces: who governs it, what data feeds it, what prompts it receives, what model runs it, how it operates in production, and which third-party vendors deliver it. Each OWASP LLM Top 10 risk and each NIST AI RMF function maps to one of these six.

Why weights from 0 to 3 instead of 1 to 5 or yes/no?

Yes/no loses the difference between "we know we need this" and "we have it documented and operational." Five points adds noise without signal. Four weights force a decision: absent, aware, in progress, or operational.

How does the branch decide between its two stages?

Your first answer picks one of four branches. Each branch can end at one of two neighbouring stages, and its remaining questions are the ones that separate those two. The weights of your answers are summed and compared to that branch's threshold. The thresholds are a first cut by CWS engineers; they are not calibrated against a dataset, and we will say so until they are.

Does the score change as my AI footprint grows?

It should. The Posture Check describes one day. Take it again each quarter or after any material change to your AI deployments, and watch the direction more than any single result.

Why do recommendations differ by score band?

An organization at Crawl needs to stand up a policy and an inventory. One at Run needs continuous monitoring, red teaming, and vendor attestation review. The same dimension produces different recommendations at different stages.

What happens with my answers?

They stay in your browser. The tool resolves your stage client-side using sessionStorage, and the stage is not shown on screen: after the last question you choose to have it emailed or to talk it through live with a CWS engineer. Two things leave the page on their own. Your stage and the weight of each answer are recorded in our site analytics with no name or email attached, so we can see which gaps are common. And if you choose the live conversation, your stage and weight travel as URL parameters to wearecws.com/contact. Your email, if you give it, is used once to send your stage.

Ready when you are

Ready to find out where you stand?

Free, a few minutes, and your stage arrives the way you choose: by email, or live with a CWS engineer.