The AI Governance RADAR: Five Questions That Test Your Actual Exposure
Assumption is not governance
Most security leaders I speak with can describe their AI governance concern clearly. Very few can answer the same five questions from documented evidence rather than assumption. That distinction matters, because a regulator does not ask what you believed — it asks what you can show.
The five questions
How many third-party AI tools have active access to your data environment right now?
Not how many are on your approved list — how many hold live authorisations at this moment. These two numbers diverge, sometimes by a factor of ten. The approved list is policy. Active authorisations are technical reality.
For each of those tools, is its training behaviour documented?
Does the tool train on your company's content? This requires a documented answer from the vendor's data processing terms — not a sales assurance. If your answer rests on assumption, that gap is itself a compliance failure waiting to be discovered. See the TRACE Score for how to document this systematically.
Do you have a signed DPA with every AI tool processing personal data on your behalf?
Not a privacy policy acceptance — a signed Data Processing Agreement specifying purpose, data categories, retention period, security obligations, and breach notification. This is a legal requirement under DPDPA, including for the long tail of tools employees authorised individually.
Are any active access tokens associated with employees who have already left?
I have yet to find an organisation that ran this audit and got zero. Offboarding and OAuth grant management run on separate systems, maintained by separate teams, with no synchronisation between them. The gap is structural; the liability is not. This is the ghost token problem.
When did you last audit your AI tool landscape — and what has changed since?
If the answer is "never" or "more than 90 days ago", you are describing a situation that no longer exists. The landscape shifts every quarter: new tools appear, vendors update their data processing terms without announcement, permissions change.
What most organisations actually score
| Question | What it checks | Typical answer |
|---|---|---|
| Registry | Are active tools mapped? | Rarely |
| Awareness | Is training behaviour documented? | Almost never |
| Documentation | Is a DPA signed? | Often missing |
| Access audit | Have ghost tokens been checked? | Almost never |
| Recency | Audited in the last 90 days? | Rarely |
These five questions are the floor of any AI governance programme. Without documented answers to all five, everything built on top — risk scoring, vendor management, board reporting — rests on assumption. Which of the five is your organisation least confident answering with documentation today?
Answer Registry and Access Audit in about six minutes.
A free Pyroniq scan maps every live AI tool authorisation and flags grants from departed employees.
This article is for awareness only and does not constitute legal advice. DPDPA obligations depend on your organisation's specific circumstances — confirm them with qualified counsel.