Would your last AI project pass the gate?
Six questions a CEO can answer. Behind them, the 22 checks a regulated production system answers for. 60 seconds. Your answers never leave this browser.
Not sure counts as no. An auditor counts it the same way.
We wrote the 22 checks behind these questions. They map to what DORA, NIS2, and GDPR ask of a production system.
Score 0 of 6
Your auditor asks who approved last month's changes. What do they get?
A reportAn archaeology projectNot sure
Behind this question: 4 of the 22 checks
- Could you produce a record of who changed what, when, and why?
- Did every change go through a documented change-control step?
- If AI is in the loop, could you show conformity evidence this quarter?
- Are its logs centralized and retained per your policy?
The code AI wrote for you this week. Six months from now?
It keeps itself patchedSomeone has to rememberNot sure
Behind this question: 4 of the 22 checks
- Was the code hardened against a written security policy, not reviewed by eye?
- Are its IAM roles least-privilege, and has anyone checked since launch?
- Are all secrets out of the code, stored and rotated?
- Do you have a current SBOM and a patch cadence?
Part of your cloud goes down tonight.
We stay up, and we would knowWe would find out from customersNot sure
Behind this question: 5 of the 22 checks
- Would you know it is degrading before a user tells you?
- Is someone on call for it, in writing?
- Are SLOs and error budgets defined?
- Has a backup ever been restored on purpose, as a test?
- Would it survive one availability zone failing?
The team that built it leaves tomorrow.
New people could run itIt leaves with themNot sure
Behind this question: 5 of the 22 checks
- Are its integrations (ERP, IdP) documented outside the code?
- Does the documentation match what actually shipped?
- Do its tests check what the business asked for, not just what the code does?
- Could you rebuild the environment from the repository alone?
- Is there a tested rollback path, versioned with the delivery?
Where is your customer data, tonight?
We know, and we can prove itWe would have to ask someoneNot sure
Behind this question: 2 of the 22 checks
- Is threat detection watching it in production right now?
- Can you show where its data lives, and prove it stays there?
The regulator announces a visit next month.
We print a reportWe start building a binderNot sure
Behind this question: 2 of the 22 checks
- Did a DPIA exist before the build started?
- Does a written threat model exist for it?
0 of 6 is normal. That is the point.
When you want to see one of your projects pass all 22, that is the demo. Book a demo