Seven questions, four ways to answer each. Honest beats flattering.
01
Do you have a written list of 'never paste' data types (client details, financials, health, contracts, source code)? A Yes — documented, and every staff member has read it. B Informal list — we've talked about it but not written it down. C We know what's sensitive, but there's no agreed rule. D No rules — staff use their own judgement.
02
Could your staff explain the difference between a public AI tool and an enterprise one? A Yes — every staff member could explain it confidently. B Most of the team could — a few would hesitate. C Only a couple of champions really understand it. D Honestly, we're not sure of the difference ourselves.
03
Whose accounts are your AI tools sitting on? A Company-owned accounts with single sign-on across the team. B Mostly company accounts — a few personal logins remain. C A mix of company and personal logins. D Mostly personal accounts — we don't really track it.
04
How do staff know which documents are sensitive and need special handling? A Documents are tagged or flagged in our system. B Sensitive material lives in clearly restricted folders. C Staff know by context — nothing is formally marked. D There's no separation — everything sits together.
05
How well do you understand how each AI tool you use treats your data (training, retention, geography)? A Documented for every tool, reviewed regularly. B Documented for the main tools we rely on. C We've skimmed the terms but nothing's written down. D We haven't checked.
06
When did you last review AI use against your obligations under the Privacy Act and related rules? A A formal review in the last 12 months. B An informal check in the last 12 months. C It's been more than 12 months. D We've never formally reviewed it.
07
If a client asked tomorrow how you use AI, how would you answer? A We'd send a written AI use statement we already share. B We'd give a clear, confident verbal answer. C We'd wing it and hope for the best. D We'd dread the question.