Back to the library
Diagnostic previewAdvanced

AI Diagnostic

Assesses AI governance and usage, inspired by ISO/IEC 42001, the NIST AI RMF and the EU AI Act.

52-83 min
104 questions
11 domains

A preview of the first questions

Click an answer to see what a Kaliteq assessment feels like. Nothing is ever saved here.

1

À quel stade se situe globalement l'usage de l'IA dans votre organisation ?

2

Votre organisation dispose-t-elle d'une vision IA formalisée et communiquée ?

3

La stratégie IA est-elle explicitement alignée avec les objectifs stratégiques de l'entreprise ?

4

Disposez-vous d'une feuille de route IA formalisée avec des priorités claires ?

Another 100 questions await you

This is only a preview of the diagnostic

Continue to discover all the questions and get your personalized analysis.

Start my free trial
Over 104+ questions
AI-assisted analysis
Personalized recommendations
Full report
Risk matrix
Smart Hub
Data Room
7-day trial

15+ diagnostics available · 1000+ maturity questions · AI built in

What is the AI Diagnostic ?

Assesses AI governance and usage, inspired by ISO/IEC 42001, the NIST AI RMF and the EU AI Act.

Objective : Évaluer la gouvernance et les usages de l'IA dans mon organisation.

An AI governance diagnostic assesses how an organization oversees the design, deployment and supervision of its artificial intelligence uses, whether internal tools (conversational assistants, automation) or systems embedded in products. Unlike a technical model audit (bias testing, robustness), this diagnostic focuses on governance: who decides, who supervises, how risks are identified and treated, and how uses are documented.

The EU AI Act, coming into force in stages since 2024, along with frameworks like ISO/IEC 42001 and the NIST AI RMF, now shape expectations around AI governance. Few organizations, particularly SMEs and mid-sized companies, currently have a clear view of their own maturity on this topic: this diagnostic objectively measures the gap against these frameworks, without aiming for immediate certification, to prioritize the most urgent actions.

What this diagnostic gives you

A clear view of your actual AI uses

Map the AI uses across your organization, including the ones that often fly under the IT department's radar (AI tools adopted spontaneously by teams).

An assessment of your AI Act exposure

Identify whether your AI uses fall into a risk category regulated by the EU AI Act, and the level of obligations that follow.

Structured governance without bureaucratic overkill

Get recommendations sized to your organization, without aiming for a governance setup disproportionate for an SME.

A base for your internal AI policy

The diagnostic's findings and recommendations feed directly into drafting or updating your AI usage policy.

An approach aligned with recognized frameworks

The diagnostic draws on ISO/IEC 42001, the NIST AI RMF and the AI Act, to stay consistent with current expectations from clients, investors and regulators.

Who is it for?

A diagnostic designed to be run without prior expertise, though each profile draws different value from it.

Executive / Management

Measures the company's exposure to AI-related risks and obligations, to arbitrate priorities without relying on technical jargon.

CIO / CTO

Structures the technical governance of AI (data access, model oversight, vendor dependency) beyond mere tool choices.

Innovation / Digital transformation lead

Objectively assesses the organization's AI maturity before launching new use cases, to avoid stacking tools without a governance framework.

CISO

Assesses AI-specific security and confidentiality risks (data leaks through third-party tools, dependency on a single vendor).

Legal / Compliance lead

Anticipates AI Act obligations and documents high-risk uses, ahead of an audit or a due diligence.

Domains assessed

Each domain is made up of factual questions, with no unnecessary jargon.

IA & Gouvernance des Modèles

Usage de l'IA, gouvernance des modèles, risques réglementaires et politiques internes

Data & IA Engineering

Architecture data, qualité des pipelines, gouvernance des données et MLOps

Methodology

The AI Diagnostic is inspired by ISO/IEC 42001, the NIST AI RMF and the EU AI Act — without claiming official conformity to these frameworks, which remain the only recognized certification path.

What you get

A map of AI uses and risks

A per-domain summary (governance, data, security) of identified uses and their risk level.

A position against the AI Act

An estimate of the level of obligations applicable to your AI uses, based on the risk categories defined by the EU regulation.

Prioritized recommendations

Concrete actions to structure AI governance, ranked by urgency and implementation effort.

A Progress Plan tracked over time

Every recommendation becomes a tracked action with a status and a comment, to steer the organization's progressive compliance.

Ready to get started?

Start this diagnostic now and get your first recommendations after just a few questions.

Start my free trial

Frequently asked questions

Does this diagnostic certify AI Act compliance?

No. It is a self-assessment that positions your AI uses against the AI Act's risk categories, with no official certification value. It objectively measures your level of readiness and helps prioritize actions, ahead of formal legal advice if needed.

Does the diagnostic cover employee use of tools like ChatGPT?

Yes. The use of consumer conversational assistants by teams, often outside any formal framework, is part of what is assessed: access governance, awareness, and handling of sensitive data shared with third-party tools.

Do we need to build our own AI models for this diagnostic to be relevant?

No. The vast majority of organizations concerned use third-party AI tools (assistants, automation, tools embedded in their business software) rather than building their own models. The diagnostic is designed for both cases, with most questions applicable as soon as an AI tool is used within the organization.

What is the difference between this diagnostic and ISO/IEC 42001 certification?

ISO/IEC 42001 is a certifiable standard, audited by an accredited body, that defines an AI management system. The Kaliteq diagnostic draws on it to structure its assessment, without issuing a certification: it objectively measures the gap with the standard and, if the company wishes, prepares for a later certification process.

Is this diagnostic suited to a company that is just starting to use AI?

Yes, this is in fact the profile that gets the most value from it: it sets a governance framework from the very first uses, rather than having to catch up once AI is already widely deployed without oversight.

How long does the AI Diagnostic take?

The AI Diagnostic includes around 104 questions across 2 domains, roughly 52 to 83 minutes for a first pass. Answers remain editable as long as the diagnostic has not been finalized.

Which domains does the AI Diagnostic cover?

The AI Diagnostic covers the following domains: IA & Gouvernance des Modèles, Data & IA Engineering.

Who should answer the AI Diagnostic in my organization?

Typically, management answers the governance-related questions, while operational leads answer the questions in their domain (e.g. CISO or IT director for cybersecurity, CTO for development). Kaliteq lets you invite several contributors on the same diagnostic, each answering the domains that concern them.

What methodology is the AI Diagnostic based on?

The AI Diagnostic is inspired by ISO/IEC 42001, the NIST AI RMF and the EU AI Act — without claiming official conformity to these frameworks, which remain the only recognized certification path.

What does the report generated at the end of the AI Diagnostic contain?

At the end of the diagnostic, Kaliteq generates a report structured by domain: maturity level, identified strengths, risks prioritized by impact and remediation effort, and recommendations automatically turned into a tracked Progress Plan. The report is based exclusively on the answers provided and any associated documents, with full traceability to their source.

Is the AI Diagnostic suited to a small or mid-sized business?

Yes. The AI Diagnostic is rated "avance" difficulty. Its advanced level covers more technical topics; it is best completed with input from an operational lead in the domain (CISO, CTO, IT director…). Kaliteq is designed for organizations of any size, with no dedicated team required to run the diagnostic.

One engine shared by every diagnostic

Adaptive questionnaires, intelligent Data Room, Smart Hub RAG engine and automated reports: discover the tools shared by every Kaliteq diagnostic.

Discover Kaliteq's solutions