Sample Report — Demonstration Data

Sample Report — Demonstration Data

All figures below are illustrative sample data for a fictional organization.

62%Readiness

Pilot Ready

Sample Report — suitable for a controlled pilot with defined scope. Organization-wide deployment is not recommended until inventory and data access gaps are closed.

Readiness by assessment area

Sample Report — each area scored independently from 21 responses

Strategy and ownership

74%On track

AI inventory

41%High risk

Data and access

48%High risk

Risk and compliance

57%Attention

Security

78%On track

People and adoption

68%On track

Operations and evidence

55%Attention

Five critical findings

Sample Report — issues that block or materially delay enterprise AI deployment

  1. 01No maintained inventory of AI tools in use

    Six AI tools were identified during the assessment, of which two were unknown to IT. Without an inventory, risk reviews and licence control cannot be evidenced.

    AI inventory

    High risk
  2. 02Permissions have not been reviewed before assistant rollout

    Legacy shared drives and broad SharePoint permissions remain in place. A Copilot deployment would surface content to staff who should not see it.

    Data and access

    High risk
  3. 03Generative AI is not covered by an approved policy

    Acceptable-use guidance exists as an informal email. There is no approved policy, exception route or acknowledgement record.

    Risk and compliance

    High risk
  4. 04AI tool activity is not logged or monitored

    Security has no visibility of prompt activity or data movement into external AI services, preventing investigation of misuse.

    Security

    Attention
  5. 05No retention rule applies to prompts and AI outputs

    Chat histories are retained indefinitely by default, creating discoverable records outside the existing retention schedule.

    Data and access

    Attention

High-risk unknowns

Sample Report — answered Unknown where the exposure is material

  • Are AI vendors reviewed for data residency and sub-processors?

    Answered Unknown. Vendor terms determine whether regulated data may leave the region.

    Risk and compliance

  • Can unsanctioned personal AI accounts be identified?

    Answered Unknown. Shadow AI usage cannot be quantified or contained until it is measurable.

    AI inventory

  • Is AI prompt and output activity retained under a defined rule?

    Answered Unknown. Unmanaged retention creates unbounded disclosure exposure.

    Data and access

  • Does incident response cover AI-specific scenarios?

    Answered Unknown. Response time in an AI data-leak scenario is untested.

    Security

Quick wins

Sample Report — low effort actions that raise readiness within weeks

  • Publish an approved AI acceptable-use policy

    Adapt existing IT policy language and route through the leadership team for sign-off.

    Low effortHigh impact
  • Stand up a single AI tool register

    One maintained register with owner, use case, data types and renewal date per tool.

    Low effortHigh impact
  • Enable available AI audit logging in Microsoft 365

    Turn on existing tenant audit capability and grant the security team review access.

    Low effortMedium impact
  • Add an AI request route to the service desk

    A visible intake form reduces shadow AI and creates a decision trail.

    Low effortMedium impact

Recommended next steps

Sample Report — sequenced in the order we advise completing them

  1. 1Assign a named executive owner for AI adoption and governance.
  2. 2Complete a permissions and oversharing review on all repositories in scope for assistants.
  3. 3Approve and communicate the AI acceptable-use policy with an acknowledgement record.
  4. 4Establish the AI tool register and run a first discovery sweep for unsanctioned tools.
  5. 5Define retention rules for prompts, outputs and chat histories.

30/60/90-day action plan

Sample Report — remediation sequenced so each phase unblocks the next.

Days 0-30

Establish control
  • Confirm executive owner and governance forum with a monthly cadence.
  • Approve and publish the AI acceptable-use policy.
  • Create the AI tool register and record all known tools.
  • Enable AI audit logging and assign review responsibility.

Days 31-60

Reduce exposure
  • Complete the permissions and oversharing remediation for pilot repositories.
  • Apply sensitivity labels to high-risk document sets.
  • Run vendor reviews for the two AI tools under consideration.
  • Deliver role-specific training to finance, HR and legal teams.

Days 61-90

Scale with evidence
  • Launch a controlled pilot of 40 licences with defined success measures.
  • Report adoption, value and incident metrics to leadership.
  • Add AI scenarios to the incident response plan and test them.
  • Assemble the AI control evidence pack for customer questionnaires.