Organization Risk

Five-domain AI risk model with prioritized findings

AI Usage Risk

62/1004 pts

Tracks employee adoption of approved vs unapproved AI tools, prompt hygiene, and exposure of sensitive content to public LLMs.

Recommended actions
  • Publish approved AI tool list
  • Block public LLM domains on managed devices
  • Deliver Safe Use of ChatGPT module org-wide

Social Engineering Risk

54/1003 pts

Measures susceptibility to AI-generated phishing, smishing, vishing, and deepfake impersonation attacks.

Recommended actions
  • Run quarterly AI phishing simulations
  • Enable callback verification for wire transfers
  • Train executives on deepfake voice scenarios

Data Leakage Risk

71/1006 pts

Quantifies likelihood of sensitive data (PII, source code, contracts) leaving the organization via AI tools.

Recommended actions
  • Deploy DLP rules for AI endpoints
  • Audit ChatGPT/Copilot tenant logs weekly
  • Mandatory data handling module

Technical AI Security Risk

60/1002 pts

Application-layer exposure: insecure LLM integrations, prompt injection, RAG poisoning, model supply chain.

Recommended actions
  • Threat-model every GenAI feature
  • Add prompt injection tests to CI
  • AppSec training for all engineers

Policy Compliance Risk

78/1001 pts

Coverage and acknowledgment of AI acceptable use policy across the workforce.

Recommended actions
  • Require annual AI policy attestation
  • Localize policy for EU/APAC
  • Tie policy to onboarding

Risk Matrix

Impact vs likelihood — bubble sizes show finding counts

Rare
Possible
Likely
Almost Certain
Critical
1
Deepfake exec fraud
2
Vendor invoice fraud, Insider AI leak
1
BEC
High
2
Customer data leak, Fake candidates
1
Prompt injection
Medium
1
Shadow AI
2
Smishing, Voice phish
1
Policy drift
Low
1
Image gen misuse
1
Public LLM rumor
Likelihood →

Top Findings

Employees pasting customer data into external AI tools

Critical

Customer Support, Sales

Finance team vulnerable to AI-generated invoice fraud

High

Finance

HR lacks fake candidate / synthetic identity detection training

High

HR & Recruiting

Engineering team needs prompt injection awareness

Medium

Engineering, AppSec

Executives need deepfake verification protocol

Critical

Executive Team