web analytics
Uncategorized — July 2026

AI Audit: Score 5 Dimensions Free in 35 Minutes

An AI audit is the fastest way to find out what AI is actually running in your business, what it costs, and whether you could defend it if someone asked. Today the AI audit opens in beta, and the first 100 people who run it get the full report free, with no restrictions.

The short answer: an AI audit is an operational diagnostic that scores five dimensions of AI use at once, tool inventory, cost mapping, performance and value, risk and exposure, and governance and accountability. It takes about 35 minutes and 127 questions, and it produces a report that names each gap, ranks it, and ties it to a documented action. The SRJ AI audit normally costs $399. It is free for the first 100 beta participants who agree to report problems they find.

On this page

What an AI audit actually measures

Most leadership teams cannot answer a simple question about their own operation: what AI is running here, who owns it, what it costs, what it returns, and what happens if someone asks us to defend it. That is not carelessness. It is a consequence of how AI arrived.

AI did not enter most businesses as a procurement decision that anyone tracked. It arrived as a feature switched on inside software the company already owned. The meeting recorder started summarizing. The CRM started drafting. The design tool started generating. Nobody approved any of it as AI, so nobody inventoried it. The gap between the tools leadership can name and the tools actually running is shadow AI, and it is where governance failures live.

The audit closes that gap by measuring operating reality rather than intent. It is not a survey, and it is not a maturity model dressed up as a quiz. It is the same instrument used inside six-figure consulting engagements, made available directly to a single operator who knows the business.

The five dimensions every AI audit should score

Why an AI audit has to measure all five together

The five dimensions are tangled together in practice, so measuring one in isolation produces a partial picture that misses what matters. A tool that is not on anyone’s inventory has no cost owner, no performance baseline, no risk classification, and no accountable executive. Audit only the tools and you learn nothing about exposure. Audit only the risk and you cannot tell which risks attach to systems that are also producing real value. The audit earns its name by holding all five in view at the same time.

Why this AI audit is free for the first 100

The audit is in beta, and the first 100 people who run it receive the full report at no cost. Not a teaser, not top-line scores with the useful part behind a paywall. The complete report, with no restrictions, normally $399.

The condition is feedback. If a question reads ambiguously, if an industry classification does not fit your business, if a score lands in a way that contradicts what you know to be true about your own operation, we want to hear it plainly. That trade is deliberate. A hundred senior operators stress-testing a diagnostic against a hundred real businesses is worth considerably more than a hundred times $399, and it produces a better instrument for everyone who runs it later.

Run the AI audit free, while the first 100 places last.

About 35 minutes, 127 questions, five dimensions, and a full report inside your account.

Who should run an AI audit first

The clearest case looks like this. A mid-market company, two hundred people, no AI strategy document and no AI ban. Marketing bought a writing tool. Sales turned on the CRM’s built-in assistant. Engineering uses a coding assistant that a manager expensed. Someone in HR is screening applications with a tool the vendor describes as decision support. Finance has no line item called AI because every one of those charges landed inside an existing subscription.

Nothing has gone wrong yet, which is exactly why this is the right moment. The company has real AI adoption, real spend, and real exposure, and no single person can describe any of the three. The audit is written for a senior operator who knows the business, not for forwarding to IT. It should be answered by someone who can speak to what is actually happening.

What to do after your AI audit: the free reference stack

The audit tells you where you stand. Interpreting the result takes reference material, so all of it now lives in one place on the new Resources page, free and maintained against primary sources.

Both standards it is most often measured against are public. The NIST AI Risk Management Framework organizes AI risk work around govern, map, measure, and manage. ISO/IEC 42001 sets out the requirements for an AI management system. Both start from the same prerequisite: you cannot govern what you have not listed.

From AI audit to defensible governance

The audit answers where you stand. A different question is arriving in boardrooms, and it is harder: is this program defensible if someone tests it?

Four stakeholders now ask it. A board member asks who signed off on the customer-facing model. A regulator asks for documentation of how a decision affecting a person was made. An acquirer’s diligence team asks for an AI attestation. A cyber, E&O, or D&O carrier puts AI questions on the renewal application. The question is never what tools are you using. It is what do you hand them.

The AI Risk & Governance Review™, Volume III of The Operating Discipline for AI Library™, is the operating model for converting audit findings into that answer. It sets out a 6-Step Review producing a per-use-case governance dossier, the AI Governance Framework Crosswalk™ mapping each dossier to the frameworks a regulator or acquirer will reach for, the AI Accountability Matrix™ placing executive ownership, and three operating logs that satisfy ISO/IEC 42001 Clauses 9 and 10.

AI audit FAQ

How long does an AI audit take?

About 35 minutes, covering 127 questions across the five dimensions. It is designed to be completed in one sitting by one senior person rather than circulated for collective input.

How is an AI audit different from a security audit?

A security audit asks whether systems are protected against attack. An AI audit asks whether AI use is inventoried, costed, performing, risk-classified, and governed. The two overlap on exposure and share almost nothing else. A company can pass a security audit while having no idea which AI tools are handling customer data.

When should a company run its first AI audit?

Before anything has gone wrong. The useful moment is when adoption is real but undocumented, which for most mid-market companies is right now. Running one after an incident, a diligence request, or a regulator’s letter means assembling evidence under a deadline set by someone else.

Does an AI audit require technical staff?

No. It is written for an executive who understands the operation. The questions concern ownership, spend, data, and accountability rather than model architecture.

What does the AI audit cost after the beta?

The Snapshot tier is a one-time $399 product for a single operator. Team-wide assessment with variance analysis is priced on request. During the beta the full report is free for the first 100 participants.

It is difficult to govern something before you have looked at it squarely.

It is free for the first 100, and takes about 35 minutes.

More Insights

Other essays from the practice.

View all writing
Want to talk through your AI posture? Start with a conversation.
Begin the Engagement

Bring AI under operating control.

A 30-minute consultation to scope the question your leadership team needs answered. No deck, no pitch. A conversation about where your organization currently stands and what the right next step looks like.

Schedule a Free AI Consultation