The AI Governance RADAR: Five Questions That Test Your Actual Exposure

Ashish KunalFounder — Pyroniq·
The AI Governance RADAR is a five-question diagnostic for testing whether your AI governance rests on evidence or assumption: Registry (how many AI tools have live access right now?), Awareness (is each tool's training behaviour documented?), Documentation (is there a signed DPA for every tool processing personal data?), Access audit (are any tokens still active for employees who have left?), and Recency (when did you last audit, and what changed?). Each must be answerable from documentation. The RADAR does not tell you that you are safe — it tells you where the gaps are.

Assumption is not governance

Most security leaders I speak with can describe their AI governance concern clearly. Very few can answer the same five questions from documented evidence rather than assumption. That distinction matters, because a regulator does not ask what you believed — it asks what you can show.

The five questions

RRegistry

How many third-party AI tools have active access to your data environment right now?

Not how many are on your approved list — how many hold live authorisations at this moment. These two numbers diverge, sometimes by a factor of ten. The approved list is policy. Active authorisations are technical reality.

AAwareness

For each of those tools, is its training behaviour documented?

Does the tool train on your company's content? This requires a documented answer from the vendor's data processing terms — not a sales assurance. If your answer rests on assumption, that gap is itself a compliance failure waiting to be discovered. See the TRACE Score for how to document this systematically.

DDocumentation

Do you have a signed DPA with every AI tool processing personal data on your behalf?

Not a privacy policy acceptance — a signed Data Processing Agreement specifying purpose, data categories, retention period, security obligations, and breach notification. This is a legal requirement under DPDPA, including for the long tail of tools employees authorised individually.

AAccess audit

Are any active access tokens associated with employees who have already left?

I have yet to find an organisation that ran this audit and got zero. Offboarding and OAuth grant management run on separate systems, maintained by separate teams, with no synchronisation between them. The gap is structural; the liability is not. This is the ghost token problem.

RRecency

When did you last audit your AI tool landscape — and what has changed since?

If the answer is "never" or "more than 90 days ago", you are describing a situation that no longer exists. The landscape shifts every quarter: new tools appear, vendors update their data processing terms without announcement, permissions change.

What most organisations actually score

QuestionWhat it checksTypical answer
RegistryAre active tools mapped?Rarely
AwarenessIs training behaviour documented?Almost never
DocumentationIs a DPA signed?Often missing
Access auditHave ghost tokens been checked?Almost never
RecencyAudited in the last 90 days?Rarely

These five questions are the floor of any AI governance programme. Without documented answers to all five, everything built on top — risk scoring, vendor management, board reporting — rests on assumption. Which of the five is your organisation least confident answering with documentation today?

Answer Registry and Access Audit in about six minutes.

A free Pyroniq scan maps every live AI tool authorisation and flags grants from departed employees.

Run Free Scan →

This article is for awareness only and does not constitute legal advice. DPDPA obligations depend on your organisation's specific circumstances — confirm them with qualified counsel.