Fourteen free, interactive AI tools. Enter a little, get a real, downloadable artifact (a tiered AI register, a governance maturity self-assessment, a Gen-AI risk scorecard, an AI workflow readiness read, an inventory CSV, a risk-tier read, a policy doc, a NIST AI RMF checklist, a model-risk-tier read, a tailored vendor DDQ, a set of AI incident scenarios, a shadow-AI exposure read, a regulatory crosswalk, an exam-readiness evidence pack) built right in the page. No account, no upload, no waiting on a sales call.
Each tool is a starting point built by senior practitioners, with the fields and framework references that actually matter, dated and kept current.
Build a client-side AI register, compute a transparent risk tier (materiality × data sensitivity × deployment × autonomy), see the controls it calls for under NIST AI RMF and SR 26-2, and export to CSV and JSON. The shared spine the rest of the stack reads.
Score a generative-AI use case on hallucination, prompt injection, data leakage, third-party LLM dependency, and human oversight. Export a board-ready Markdown summary or save the score to the browser-local AI register.
Benchmark your AI governance program against the four NIST AI RMF functions (Govern, Map, Measure, Manage) with finserv expectations mapped in. Get a maturity score per function and overall, a board-ready summary, and save each attempt to track the delta over time. Exports CSV and JSON.
Answer six questions about one business workflow and get a readiness band — ready to pilot, close but gapped, or not yet — with the specific gaps to close before you build.
Build an AI system & use-case register with EU AI Act-relevant fields and a worked example, then export it as CSV and Markdown.
Answer a short wizard and get a defensible risk tier — prohibited, high, limited, or minimal — with the obligations and the current deadline status.
Pick clauses with healthcare, finserv, and govcon variants and download a complete AI acceptable-use policy instead of starting from a blank page.
Work a tabbed checklist across Govern, Map, Measure, and Manage, track status per function, and export the whole thing to CSV.
Answer five questions and get a materiality-based read: whether an AI system is a model in scope of SR 26-2, and if so a structured Tier 1, 2, or 3 with the validation and monitoring that follow.
Answer three questions and assemble a tailored DDQ to send an AI vendor: governance, model validation, data and security, third and fourth parties, incident response, contract rights, and monitoring, with the framework drivers that apply to you.
Pick an AI use case (lending, fraud, customer service, underwriting, or trading) and your firm type to get pre-built incident scenarios — model failure, LLM data leakage, deepfake fraud, and more — plus a 10-question "does your IR plan answer this?" checklist.
Answer ten questions about your visibility into employee AI-tool use and get an exposure score — low, medium, or high — plus the common unsanctioned AI tools in your industry and a sample AI acceptable-use-policy framework outline to build from.
Map an AI use case to the finserv regimes that govern it — SR 26-2 (with the generative/agentic governance gap), ECOA/Reg B fair lending, BSA/AML, GLBA, NYDFS Part 500, NIST AI RMF, and state AI laws — filterable by regulator and jurisdiction, each with a citation and effective date. Versioned, exports CSV and JSON.
Turn your browser-local AI register into a regulator-friendly evidence package: model and use-case inventory, ownership, risk classification, control coverage, and the gaps still open for exam-readiness. Exports PDF and Markdown. Answers the examiner's first questions — where is AI used, who owns it, how is risk classified.
One filterable front door to the finserv compliance workbook library — 16 real GLBA, NYDFS Part 500, NYDFS Part 23, CCPA/CPRA, NIST CSF, NIST AI RMF, Reg S-P, and FINRA workbooks and templates. Filter by entity type, regulation, role, and lifecycle stage, then add several to a governance kit and request them together. Free to browse; each download keeps its existing work-email gate.
Ask a plain-English question about AI governance, AI/model risk, or financial-services compliance and get a concise answer drawn only from DSE's published writing — with a deep-link citation to the exact article and section behind every claim. If the corpus doesn't answer it, Ask DSE says so instead of guessing. A readiness aid, not legal advice.
Last reviewed: 2026-07-01 · Wave 2 stack tool added — the Gen-AI Risk Scorecard now reads from and writes to the shared browser-local register behind the AI Governance Control Center. Building the data foundation these tools assume? Start with a free data engineering assessment. Regulation references are date-stamped and re-checked quarterly — accuracy is the point.
Rate all 22 NIST CSF 2.0 categories on the CSF 2.0 Implementation Tiers, set targets, and read a gap table sorted by largest gap. Exports CSV. Self-diagnostic — not an assessment or a tier certification.
Score each of the eight CISA Cross-Sector CPG goal families, see coverage, and get your next three discussion items — the highest-impact goals not yet implemented. Exports CSV. Discussion starters, not a compliance result.
A synthetic slice of a DSE assessment: a finding register and a roadmap slice, built with our bounded-evidence method. Structure is real; every entry is invented. Not client data.
The client-provided exports a point-in-time identity review gathers: admin roles, conditional access, MFA registration, app consents, legacy auth, guest access, and audit-log retention. A readiness aid, not a scan.
A one-page decision card for the opening hour: who declares, who isolates, who to call, what to preserve, and what not to do. A planning aid for your team's own plan — DSE does not provide live incident response.
Record RTO/RPO targets, the last real restore-test date, and the evidence per critical system — plus a standard for what counts as restore evidence. Turns "we have backups" into proof they restore.
One screen comparing vCISO, MSP, and MDR across accountability, scope, what each owns and does not own, buyer, and how each fails. No vendor names, no pricing. DSE is the vCISO layer, not an MSP or MDR.
The control-evidence artifacts underwriting applications commonly request — MFA, EDR, backup tests, IR plan, patching, privileged access, training — with evidence-artifact and as-of-date columns. DSE is not a broker.
Cybersecurity proof & diagnostic assets (DSE-591) · self-diagnostic and print-friendly · every framework citation checked against csrc.nist.gov and cisa.gov. These are readiness aids, not assessments, audits, or certifications.
The tools get you started. When you need an auditor-ready governance program or to find where staff are leaking data into AI, a principal scopes a fixed-fee engagement in a 30-minute call.
DSE provides AI governance and compliance readiness consulting. We are not an accredited certification body and do not issue ISO/IEC 42001 certificates or certify EU AI Act or NIST AI RMF compliance. We cannot guarantee passing an audit or avoiding enforcement, and we do not provide legal advice. We work alongside your counsel.
Every artifact these tools generate is a template and a starting point — readiness, not a warranty of an outcome we do not control. Review the output with your counsel before adopting it.