How the AI Posture Check scores your security.
Up to five weighted questions drawn from six dimensions, ending at one of four stages from Crawl to Sprint. Here is exactly how it works.
- Questions
- Up to 5, adaptive from your answers
- Stages
- 4: Crawl, Walk, Run, Sprint
- Axes
- Program across, controls in operation up
- Frameworks
- OWASP LLM Top 10, NIST AI RMF, ISO 42001
How the AI Posture Check works
Three answers to a question at a time, each one chosen from what you answered before.
Answer up to five questions
Each question is chosen from what you answered before. Pick the answer closest to your reality and don't overthink it. The check only works if you answer with what is true today.
Watch your position move
Each answer moves a dot on the Posture Quadrant: program across, controls up. Hover an answer before you pick it to see where it lands.
Choose how your stage is delivered
Your stage, where you are and what moves you to the next stage, is sent to your work email or talked through live with a CWS engineer. The stage itself never shows on screen.
Every branch has a threshold.
Your first answer picks one of four branches. Each branch can end at one of two neighbouring stages, and its remaining questions are the ones that separate those two. The weights of your answers are summed and compared to that branch's threshold. The thresholds are a first cut by CWS engineers, not calibrated against a dataset, and we will say so until they are.
| Branch | Stages it separates | Threshold | Maximum weight |
|---|---|---|---|
| Branch A | Always Crawl | Not applicable | 6 |
| Branch B | Crawl or Walk | 8 | 13 |
| Branch C | Walk or Run | 9 | 14 |
| Branch D | Run or Sprint | 12 | 15 |
You choose how your stage arrives.
Both paths give you the same result: your stage, the move to the next one, and the framework citations behind it.
By email
Your stage, from Crawl to Sprint, the one move that takes you to the next stage, and the framework citation behind every question you answered, written so you can forward it to your board.
In a live conversation
Twenty minutes with a CWS engineer who closes these gaps for a living, free. They walk through your stage, answer the question it raises, and tell you plainly whether a paid audit is worth booking yet.
What happens with your answers.
Your answers stay in this browser tab and clear when you close it. The tool resolves your stage client-side, and nothing about your result shows on screen until you choose how to receive it.
Two things leave the page on their own. Your stage and the weight of each answer are recorded in our site analytics with no name or email attached, so we can see which gaps are common. And if you choose the live conversation, your stage and weight travel as URL parameters to wearecws.com/contact.
If you give a work email, it is used once, to send you your stage. If you choose the live conversation instead, a CWS engineer follows up once, for that conversation. CWS does not contact you beyond the delivery you chose.
The questions we get most.
Why these six dimensions?
They map to the way AI security risk surfaces: who governs it, what data feeds it, what prompts it receives, what model runs it, how it operates in production, and which third-party vendors deliver it. Each OWASP LLM Top 10 risk and each NIST AI RMF function maps to one of these six.
Why weights from 0 to 3 instead of 1 to 5 or yes/no?
Yes/no loses the difference between "we know we need this" and "we have it documented and operational." Five points adds noise without signal. Four weights force a decision: absent, aware, in progress, or operational.
How does the branch decide between its two stages?
Your first answer picks one of four branches. Each branch can end at one of two neighbouring stages, and its remaining questions are the ones that separate those two. The weights of your answers are summed and compared to that branch's threshold. The thresholds are a first cut by CWS engineers; they are not calibrated against a dataset, and we will say so until they are.
Does the score change as my AI footprint grows?
It should. The Posture Check describes one day. Take it again each quarter or after any material change to your AI deployments, and watch the direction more than any single result.
Why do recommendations differ by score band?
An organization at Crawl needs to stand up a policy and an inventory. One at Run needs continuous monitoring, red teaming, and vendor attestation review. The same dimension produces different recommendations at different stages.
What happens with my answers?
They stay in your browser. The tool resolves your stage client-side using sessionStorage, and the stage is not shown on screen: after the last question you choose to have it emailed or to talk it through live with a CWS engineer. Two things leave the page on their own. Your stage and the weight of each answer are recorded in our site analytics with no name or email attached, so we can see which gaps are common. And if you choose the live conversation, your stage and weight travel as URL parameters to wearecws.com/contact. Your email, if you give it, is used once to send your stage.
Ready to find out where you stand?
Free, a few minutes, and your stage arrives the way you choose: by email, or live with a CWS engineer.