§ Free AI Governance Tools·client-side · no sign-up

Real governance artifacts, generated in your browser.

Fourteen free, interactive AI tools. Enter a little, get a real, downloadable artifact (a tiered AI register, a governance maturity self-assessment, a Gen-AI risk scorecard, an AI workflow readiness read, an inventory CSV, a risk-tier read, a policy doc, a NIST AI RMF checklist, a model-risk-tier read, a tailored vendor DDQ, a set of AI incident scenarios, a shadow-AI exposure read, a regulatory crosswalk, an exam-readiness evidence pack) built right in the page. No account, no upload, no waiting on a sales call.

Each tool is a starting point built by senior practitioners, with the fields and framework references that actually matter, dated and kept current.

Every tool runs entirely in your browser — nothing you enter is sent to a server.
Open the AI Governance Control Center
§ The tools·fourteen tools, all free

Pick the artifact you need right now.

01 · Stack spine

AI Inventory & Risk-Tiering Wizard

Build a client-side AI register, compute a transparent risk tier (materiality × data sensitivity × deployment × autonomy), see the controls it calls for under NIST AI RMF and SR 26-2, and export to CSV and JSON. The shared spine the rest of the stack reads.

Query intent: "AI inventory risk tiering tool / AI register"
Open the wizard →
02 · Gen-AI risk

Gen-AI Risk Scorecard

Score a generative-AI use case on hallucination, prompt injection, data leakage, third-party LLM dependency, and human oversight. Export a board-ready Markdown summary or save the score to the browser-local AI register.

Query intent: "Gen AI risk scorecard / AI governance risk assessment"
Open the scorecard →
03 · Maturity

AI Governance Maturity Self-Assessment

Benchmark your AI governance program against the four NIST AI RMF functions (Govern, Map, Measure, Manage) with finserv expectations mapped in. Get a maturity score per function and overall, a board-ready summary, and save each attempt to track the delta over time. Exports CSV and JSON.

Query intent: "AI governance maturity assessment / NIST AI RMF maturity model"
Open the self-assessment →
04 · Readiness

AI Workflow Readiness Calculator

Answer six questions about one business workflow and get a readiness band — ready to pilot, close but gapped, or not yet — with the specific gaps to close before you build.

Query intent: "AI workflow readiness / AI readiness calculator"
Open the calculator →
05 — Inventory

AI System Inventory Generator

Build an AI system & use-case register with EU AI Act-relevant fields and a worked example, then export it as CSV and Markdown.

Query intent: "AI system inventory template / register"
Open the generator →
06 — Risk tiering

EU AI Act Risk Classifier

Answer a short wizard and get a defensible risk tier — prohibited, high, limited, or minimal — with the obligations and the current deadline status.

Query intent: "EU AI Act risk classification / high-risk"
Open the classifier →
07 — Policy

AI Acceptable-Use Policy Generator

Pick clauses with healthcare, finserv, and govcon variants and download a complete AI acceptable-use policy instead of starting from a blank page.

Query intent: "AI acceptable use policy template"
Open the generator →
08 — Checklist

NIST AI RMF Checklist Generator

Work a tabbed checklist across Govern, Map, Measure, and Manage, track status per function, and export the whole thing to CSV.

Query intent: "NIST AI RMF checklist / implementation"
Open the generator →
09 · Model risk

Model Risk Tiering Calculator

Answer five questions and get a materiality-based read: whether an AI system is a model in scope of SR 26-2, and if so a structured Tier 1, 2, or 3 with the validation and monitoring that follow.

Query intent: "model risk tiering calculator / AI model risk tier"
Open the calculator →
10 · Vendor DDQ

AI Vendor Due Diligence Questionnaire

Answer three questions and assemble a tailored DDQ to send an AI vendor: governance, model validation, data and security, third and fourth parties, incident response, contract rights, and monitoring, with the framework drivers that apply to you.

Query intent: "AI vendor due diligence questionnaire / AI vendor DDQ generator"
Open the generator →
11 · Incident readiness

AI Incident Scenario Builder

Pick an AI use case (lending, fraud, customer service, underwriting, or trading) and your firm type to get pre-built incident scenarios — model failure, LLM data leakage, deepfake fraud, and more — plus a 10-question "does your IR plan answer this?" checklist.

Query intent: "AI incident response tabletop / AI incident scenario builder"
Open the builder →
12 · Shadow AI

Shadow AI Inventory Quiz

Answer ten questions about your visibility into employee AI-tool use and get an exposure score — low, medium, or high — plus the common unsanctioned AI tools in your industry and a sample AI acceptable-use-policy framework outline to build from.

Query intent: "shadow AI assessment / unsanctioned AI tools / ChatGPT employee policy"
Take the quiz →
13 · Regulatory crosswalk

Regulatory Crosswalk / Regulation Explorer

Map an AI use case to the finserv regimes that govern it — SR 26-2 (with the generative/agentic governance gap), ECOA/Reg B fair lending, BSA/AML, GLBA, NYDFS Part 500, NIST AI RMF, and state AI laws — filterable by regulator and jurisdiction, each with a citation and effective date. Versioned, exports CSV and JSON.

Query intent: "AI regulation crosswalk / which regulations apply to AI / SR 26-2 fair lending mapping"
Open the crosswalk →
14 · Evidence pack

Exam-Readiness Evidence-Pack Generator

Turn your browser-local AI register into a regulator-friendly evidence package: model and use-case inventory, ownership, risk classification, control coverage, and the gaps still open for exam-readiness. Exports PDF and Markdown. Answers the examiner's first questions — where is AI used, who owns it, how is risk classified.

Query intent: "AI governance audit readiness / AI evidence pack / pass an AI audit"
Open the generator →
15 · Workbook library

Workbook & Resource Center

One filterable front door to the finserv compliance workbook library — 16 real GLBA, NYDFS Part 500, NYDFS Part 23, CCPA/CPRA, NIST CSF, NIST AI RMF, Reg S-P, and FINRA workbooks and templates. Filter by entity type, regulation, role, and lifecycle stage, then add several to a governance kit and request them together. Free to browse; each download keeps its existing work-email gate.

Query intent: "GLBA workbook / NYDFS Part 500 template / finserv compliance library / AI governance resources"
Open the Resource Center →
16 · Cited assistant

Ask DSE

Ask a plain-English question about AI governance, AI/model risk, or financial-services compliance and get a concise answer drawn only from DSE's published writing — with a deep-link citation to the exact article and section behind every claim. If the corpus doesn't answer it, Ask DSE says so instead of guessing. A readiness aid, not legal advice.

Query intent: "AI governance question / SR 26-2 explained / EU AI Act chatbot obligations / model risk answer"
Ask a question →

Last reviewed: 2026-07-01 · Wave 2 stack tool added — the Gen-AI Risk Scorecard now reads from and writes to the shared browser-local register behind the AI Governance Control Center. Building the data foundation these tools assume? Start with a free data engineering assessment. Regulation references are date-stamped and re-checked quarterly — accuracy is the point.

§ Cybersecurity proof & diagnostic assets·eight assets, all free

Crawlable proof for conventional cybersecurity.

01 · CSF 2.0 profile

NIST CSF 2.0 Current-vs-Target Profile Workbook

Rate all 22 NIST CSF 2.0 categories on the CSF 2.0 Implementation Tiers, set targets, and read a gap table sorted by largest gap. Exports CSV. Self-diagnostic — not an assessment or a tier certification.

Query intent: "NIST CSF 2.0 current vs target profile / CSF gap analysis template"
Open the workbook →
02 · CISA CPGs

CISA CPG Baseline Scorecard

Score each of the eight CISA Cross-Sector CPG goal families, see coverage, and get your next three discussion items — the highest-impact goals not yet implemented. Exports CSV. Discussion starters, not a compliance result.

Query intent: "CISA CPG scorecard / cross-sector cybersecurity performance goals checklist"
Open the scorecard →
03 · Sample deliverable

Cybersecurity Assessment Sample Excerpt

A synthetic slice of a DSE assessment: a finding register and a roadmap slice, built with our bounded-evidence method. Structure is real; every entry is invented. Not client data.

Query intent: "cybersecurity risk assessment example / sample findings report"
See the sample →
04 · Identity evidence

Microsoft 365 & Identity Evidence Checklist

The client-provided exports a point-in-time identity review gathers: admin roles, conditional access, MFA registration, app consents, legacy auth, guest access, and audit-log retention. A readiness aid, not a scan.

Query intent: "Microsoft 365 security review checklist / Entra identity evidence"
Open the checklist →
05 · IR decision card

Incident Response: The First 60 Minutes

A one-page decision card for the opening hour: who declares, who isolates, who to call, what to preserve, and what not to do. A planning aid for your team's own plan — DSE does not provide live incident response.

Query intent: "incident response first hour checklist / ransomware first 60 minutes"
Open the card →
06 · Restore evidence

Backup & Recovery Test Worksheet

Record RTO/RPO targets, the last real restore-test date, and the evidence per critical system — plus a standard for what counts as restore evidence. Turns "we have backups" into proof they restore.

Query intent: "backup restore test worksheet / RTO RPO recovery test template"
Open the worksheet →
07 · Role comparison

vCISO vs MSP vs MDR: Who Owns What

One screen comparing vCISO, MSP, and MDR across accountability, scope, what each owns and does not own, buyer, and how each fails. No vendor names, no pricing. DSE is the vCISO layer, not an MSP or MDR.

Query intent: "vCISO vs MSP vs MDR / who owns security detection response"
Open the comparison →
08 · Insurance evidence

Cyber Insurance Evidence Checklist

The control-evidence artifacts underwriting applications commonly request — MFA, EDR, backup tests, IR plan, patching, privileged access, training — with evidence-artifact and as-of-date columns. DSE is not a broker.

Query intent: "cyber insurance application evidence / underwriting security questionnaire checklist"
Open the checklist →

Cybersecurity proof & diagnostic assets (DSE-591) · self-diagnostic and print-friendly · every framework citation checked against csrc.nist.gov and cisa.gov. These are readiness aids, not assessments, audits, or certifications.

§ When you want it done for you·fixed-fee, senior-only

Turn a free artifact into a funded engagement.

The tools get you started. When you need an auditor-ready governance program or to find where staff are leaking data into AI, a principal scopes a fixed-fee engagement in a 30-minute call.

§ What these are·and what they aren't

Templates and starting points. Not certification.

DSE provides AI governance and compliance readiness consulting. We are not an accredited certification body and do not issue ISO/IEC 42001 certificates or certify EU AI Act or NIST AI RMF compliance. We cannot guarantee passing an audit or avoiding enforcement, and we do not provide legal advice. We work alongside your counsel.

Every artifact these tools generate is a template and a starting point — readiness, not a warranty of an outcome we do not control. Review the output with your counsel before adopting it.