Toolkit
The Estate Test
Twelve questions. Twenty minutes. A map of what fails first.
Answer as the organization actually is, not as the policy says it is. No means you cannot show it today. Partly means pieces exist that would not survive a serious look. Yes means evidence you can put on the table this afternoon.
You do not need a board of directors to take this. If you run a school, a shop, or a help desk, read “board” as the people who would have to explain the week to parents, customers, or a superintendent.
How to take it
- One sitting. Do not assign homework between questions.
- The honest person in the room answers. The optimistic person does not.
- Mark one box per question. No averages.
- When you finish, you will have a map — not a grade, not a certification, not a vendor score.
The twelve questions
01 · Visibility
Do you have an inventory of every AI system and agent running here — including the ones nobody bought?
If the answer is a list of approved tools, you are counting purchases, not what is running.
| No — cannot show this today | Partly — pieces exist; would not survive scrutiny | Yes — evidence we can put on the table |
02 · Visibility
Can you name the model, the vendor, and the data each production AI system is allowed to touch?
Version drift is how last quarter’s approved tool becomes this quarter’s incident.
| No — cannot show this today | Partly — pieces exist; would not survive scrutiny | Yes — evidence we can put on the table |
03 · Visibility
Do you know how much of the workforce is putting organization data into unsanctioned AI tools?
Shadow AI is usually already there, even when the official line is “we don’t use AI.”
| No — cannot show this today | Partly — pieces exist; would not survive scrutiny | Yes — evidence we can put on the table |
04 · Control
Which AI systems can take actions — send mail, change records, move money, write code — without a human approving the step?
If you cannot name the agents that can act, you do not have a gate.
| No — cannot show this today | Partly — pieces exist; would not survive scrutiny | Yes — evidence we can put on the table |
05 · Control
If an agent goes off-policy, can you stop it in minutes — and prove that you did?
A verbal “we would just turn it off” is not a kill switch, and logs the agent can rewrite are not evidence.
| No — cannot show this today | Partly — pieces exist; would not survive scrutiny | Yes — evidence we can put on the table |
06 · Control
Are high-value actions protected against deepfake and agent impersonation — payroll, wire, access grant, grade change, production change?
Seeing and hearing the boss is no longer evidence. A second channel on a number you already have is.
| No — cannot show this today | Partly — pieces exist; would not survive scrutiny | Yes — evidence we can put on the table |
07 · Accountability
Who owns AI risk by name — not by committee?
If you have no board, name the superintendent, owner, or operator who would answer a reporter tomorrow. A committee with no named owner is how risk becomes nobody’s job.
| No — cannot show this today | Partly — pieces exist; would not survive scrutiny | Yes — evidence we can put on the table |
08 · Accountability
When did that person last receive a written AI brief at the same standard as a budget or safety paper?
If AI is a verbal update at the end of the agenda, it is not governed.
| No — cannot show this today | Partly — pieces exist; would not survive scrutiny | Yes — evidence we can put on the table |
09 · Accountability
Is there a named owner for shadow AI, for agents that can act, and for concentration in one model vendor?
Three different failure modes. One “AI person” is usually covering none of them.
| No — cannot show this today | Partly — pieces exist; would not survive scrutiny | Yes — evidence we can put on the table |
10 · Enablement
Have leaders been briefed on what AI can actually do on this estate — not a vendor demo?
A demo is a sales artifact. A briefing is a map of your own exposure.
| No — cannot show this today | Partly — pieces exist; would not survive scrutiny | Yes — evidence we can put on the table |
11 · Enablement
Has the workforce been told what they may put into AI tools, and what happens if they don’t follow that?
Policy that cannot be followed on a Tuesday does not get followed.
| No — cannot show this today | Partly — pieces exist; would not survive scrutiny | Yes — evidence we can put on the table |
12 · Enablement
If a regulator, insurer, parent, customer, or reporter asked for evidence of AI governance tomorrow, what would you hand them?
Evidence assembled the week of the ask is a fire drill, not a system.
| No — cannot show this today | Partly — pieces exist; would not survive scrutiny | Yes — evidence we can put on the table |
How to read the map
Do not add the Yes answers and call it a score. Look at which cluster went red first.
| Cluster | Questions | If this cluster is mostly No / Partly |
|---|---|---|
| Visibility | 01–03 | You cannot govern what you have not named. Start with a shadow-AI inventory of what is actually running. |
| Control | 04–06 | Something can already act. Put a human gate on mail, payroll, records, and access. Add a callback on a number you already have. |
| Accountability | 07–09 | Risk has no owner. Write one name next to AI risk before you buy another tool. |
| Enablement | 10–12 | The estate may be fine on paper and undefended in the hallway. Brief the people who will be fooled first. |
What to do with a No
Pick the first cluster that failed. Run one control this week. Do not start a program.
- Visibility failed → list every AI tool and agent you can find in 60 minutes. Unofficial counts.
- Control failed → pick one high-value action (payroll change, password reset, wire, grade change). Require a second channel.
- Accountability failed → write one name on a page. That person gets the next brief.
- Enablement failed → ten-minute staff talk: what they may paste into a chatbot, and how to verify a boss who calls in a hurry.
What this is not
- Not a grade, a maturity model, or a certification.
- Not a Check Point product or a vendor assessment.
- Not an offer of consulting. There is nothing to book at the end of this page.
- Not legal, audit, or insurance advice.
I am a sales engineer at Check Point Software. Views are my own. This instrument is independent, vendor-neutral, and is not a Check Point product, offer, or endorsement. I do not discuss customers, prospects, or non-public product information.