Eleven free, interactive AI tools. Enter a little, get a real, downloadable artifact (a tiered AI register, a Gen-AI risk scorecard, an AI workflow readiness read, an inventory CSV, a risk-tier read, a policy doc, a NIST AI RMF checklist, a model-risk-tier read, a tailored vendor DDQ, a set of AI incident scenarios, a shadow-AI exposure read) built right in the page. No account, no upload, no waiting on a sales call.
Each tool is a starting point built by senior practitioners, with the fields and framework references that actually matter, dated and kept current.
Build a client-side AI register, compute a transparent risk tier (materiality × data sensitivity × deployment × autonomy), see the controls it calls for under NIST AI RMF and SR 26-2, and export to CSV and JSON. The shared spine the rest of the stack reads.
Score a generative-AI use case on hallucination, prompt injection, data leakage, third-party LLM dependency, and human oversight. Export a board-ready Markdown summary or save the score to the browser-local AI register.
Answer six questions about one business workflow and get a readiness band — ready to pilot, close but gapped, or not yet — with the specific gaps to close before you build.
Build an AI system & use-case register with EU AI Act-relevant fields and a worked example, then export it as CSV and Markdown.
Answer a short wizard and get a defensible risk tier — prohibited, high, limited, or minimal — with the obligations and the current deadline status.
Pick clauses with healthcare, finserv, and govcon variants and download a complete AI acceptable-use policy instead of starting from a blank page.
Work a tabbed checklist across Govern, Map, Measure, and Manage, track status per function, and export the whole thing to CSV.
Answer five questions and get a materiality-based read: whether an AI system is a model in scope of SR 26-2, and if so a structured Tier 1, 2, or 3 with the validation and monitoring that follow.
Answer three questions and assemble a tailored DDQ to send an AI vendor: governance, model validation, data and security, third and fourth parties, incident response, contract rights, and monitoring, with the framework drivers that apply to you.
Pick an AI use case (lending, fraud, customer service, underwriting, or trading) and your firm type to get pre-built incident scenarios — model failure, LLM data leakage, deepfake fraud, and more — plus a 10-question "does your IR plan answer this?" checklist.
Answer ten questions about your visibility into employee AI-tool use and get an exposure score — low, medium, or high — plus the common unsanctioned AI tools in your industry and a sample AI acceptable-use-policy framework outline to build from.
Last reviewed: 2026-07-01 · Wave 2 stack tool added — the Gen-AI Risk Scorecard now reads from and writes to the shared browser-local register behind the AI Governance Control Center. Building the data foundation these tools assume? Start with a free data engineering assessment. Regulation references are date-stamped and re-checked quarterly — accuracy is the point.
The tools get you started. When you need an auditor-ready governance program or to find where staff are leaking data into AI, a principal scopes a fixed-fee engagement in a 30-minute call.
DSE provides AI governance and compliance readiness consulting. We are not an accredited certification body and do not issue ISO/IEC 42001 certificates or certify EU AI Act or NIST AI RMF compliance. We cannot guarantee passing an audit or avoiding enforcement, and we do not provide legal advice. We work alongside your counsel.
Every artifact these tools generate is a template and a starting point — readiness, not a warranty of an outcome we do not control. Review the output with your counsel before adopting it.