This is a sample assessment using fictional organization data. All company names, tool counts, and findings are illustrative. Run your own assessment →
Project Compass — AI Governance Platform
Executive Summary Report
AI Governance Assessment
Meridian Financial Services
Assessment DateJuly 14, 2025
AnalystCompass Platform
Log SourceDNS + HTTP Proxy (180 days)
FrameworkNIST AI RMF · OWASP LLM Top 10
SAMPLE DATA — FOR DEMONSTRATION PURPOSES ONLY — NOT A REAL ASSESSMENT
AI Tools Detected
12
across 3 categories
Governance Risk Score
67/100
maturity: 33%
Controls Flagged
9
of 19 assessed
Assessment Date
Jul 14
2025
Overall Risk Posture
HIGH RISK

Meridian Financial Services has 12 AI tools actively generating network traffic, 3 of which are classified as Critical risk due to their exposure to sensitive financial data with no documented governance controls. Immediate action is required.

No formal AI usage policy in place; all 12 tools are unsanctioned
3 critical-risk tools (ChatGPT, Copilot, Claude) with no data handling agreements
No vendor risk assessments completed; OWASP LLM06 exposure confirmed
Incident response plan does not address AI-specific failure modes
67 RISK SCORE / 100
Higher = more exposure
Risk Distribution
Critical
3
High
4
Medium
3
Low
2
Detected AI Tools

12 AI Tools Identified

# Tool Category Risk OWASP Exposure First Seen
01
ChatGPT
OpenAI
Generative AI — Chat Critical LLM01 LLM06 Jan 12, 2025
02
GitHub Copilot
Microsoft
Generative AI — Code Critical LLM06 LLM09 Feb 3, 2025
03
Claude
Anthropic
Generative AI — Chat Critical LLM01 LLM06 Mar 8, 2025
04
Cursor
Anysphere
Generative AI — Code High LLM06 Apr 20, 2025
05
Perplexity AI
Perplexity AI
AI Search High LLM06 LLM09 Mar 14, 2025
06
Midjourney
Midjourney Inc.
Generative AI — Image High LLM07 Feb 28, 2025
07
Jasper
Jasper AI
Generative AI — Marketing High LLM06 May 5, 2025
08
Microsoft Copilot
Microsoft
Generative AI — Productivity Medium LLM09 Apr 1, 2025
09
Grammarly Business
Grammarly
AI Writing Assistant Medium LLM06 Jan 3, 2025
10
Adobe Firefly
Adobe
Generative AI — Creative Medium LLM07 Jun 10, 2025
11
Notion AI
Notion Labs
AI Productivity Low Mar 22, 2025
12
Google Gemini
Google
Generative AI — Chat Low LLM09 May 30, 2025
NIST AI RMF Gap Analysis

Governance Control Findings

GOVERN 1.1
AI Risk Management Policy
No formal AI usage policy governing employee use of external AI tools. Staff are using 12 tools without documented authorization or data classification guidance.
GAP
GOVERN 1.2
Accountability Structures
Three critical-risk AI tools in active use with no designated owner, approval record, or business justification on file.
GAP
MAP 1.1
AI Use Case Cataloging
All 12 detected AI tools lack documented use cases. No inventory exists prior to this assessment.
GAP
MAP 1.6
Third-Party AI Risk
No vendor risk assessments on file for ChatGPT, Claude, or Copilot. Data residency and retention terms have not been reviewed.
GAP
MEASURE 2.5
Ongoing AI Monitoring
No automated monitoring for new AI tool adoption is in place. This assessment was the first detection effort; cadence is undefined.
PARTIAL
MANAGE 1.3
AI Incident Response
Existing IR plan does not address AI-specific failure modes including prompt injection, sensitive data disclosure, or model abuse.
GAP
Recommended Actions

Priority Remediation Steps

1
Restrict access immediately to ChatGPT, GitHub Copilot, and Claude pending policy review and signed data handling agreements with each vendor.
2
Draft an AI Acceptable Use Policy within 30 days covering approved tools, permitted use cases, data classification rules, and employee acknowledgment requirements.
3
Assign tool owners to all 12 detected AI tools and complete a vendor risk questionnaire for each within 60 days. Prioritize critical-risk tools first.
4
Establish quarterly log analysis to detect new AI tool adoption. Define a monthly review cadence with the security team to maintain an up-to-date AI inventory.
5
Update the Incident Response plan to address AI-specific risks: prompt injection (LLM01), sensitive data disclosure (LLM06), and over-reliance on AI outputs (LLM09).
Ready to run your own assessment?
Upload your actual logs and get a real report — no IT team required. Runs entirely in your browser.
Run Assessment → Try Demo First