Skip to main content
Compliance Self-Assessment

AI Compliance Readiness Checklist

A self-assessment across six major compliance frameworks for AI usage. Check off the controls you have in place and get an instant readiness score — so you know exactly where the gaps are before your next audit.

Quick Answer: This checklist helps you assess your organization's readiness across SOC 2, HIPAA, GDPR, ISO 27001, PCI DSS, and NIST AI RMF — the six frameworks most commonly required for AI data protection. Check off each control you have in place to get a per-framework score and an overall readiness rating. The assessment takes about 5 minutes and runs entirely in your browser — no data is sent anywhere.

Overall Readiness
0% — Not Started
0/48 controls met

AICPA framework for service organization controls — security, availability, processing integrity, confidentiality, and privacy.

SOC 2 Readiness0/80%

How Shield Maps to Your Compliance Architecture

YOUR ORGANIZATIONStaff UserSHIELDREDACTIONEXTERNAL — OUTSIDE YOUR BOUNDARYChatGPTClaudeCopilotSOC 2HIPAAGDPRISOREDACTED DATA ONLY✕ Direct data path blocked

Frequently Asked Questions

This checklist is a self-assessment tool — it helps you gauge your readiness across six major frameworks in about 5 minutes. It does not replace a formal audit by a qualified assessor. Think of it as a gap analysis starter: it shows you which control domains need attention before you engage auditors or pursue certification. Each item maps to real framework requirements, but the checklist uses plain-language summaries — not the exact control language an auditor would test against.
Start with the framework your customers or regulators demand. If you sell to US healthcare, start with HIPAA. If you serve EU customers, start with GDPR. If you're a B2B SaaS company, SOC 2 is the most common starting point — it builds security controls that benefit every other framework. NIST AI RMF is the best starting point for AI-specific governance regardless of industry.
A 100% score on this checklist means you've addressed the high-level control domains for each framework. It does not mean you have evidence, documentation, or operational maturity for every sub-control. Use this checklist as a conversation starter with your compliance team or external auditor — they'll help you identify the evidence gaps and testing requirements that go beyond this self-assessment.
Shield addresses the data protection layer that sits at the intersection of every framework: keeping sensitive data (PII, PHI, PCI, secrets) from reaching external AI providers. By redacting data before it leaves your machine, Shield helps satisfy data minimization requirements under GDPR, PHI disclosure controls under HIPAA, cardholder data protection under PCI DSS, and vendor risk management under SOC 2 and ISO 27001 — all at the local gateway level, before data reaches ChatGPT, Claude, Copilot, or any AI model.
Re-assess quarterly at minimum, or whenever you add a new AI tool, change AI providers, enter a new regulated market, or sign an enterprise customer with specific compliance requirements. AI adoption moves fast — a tool your team adopts today might process data that wasn't in scope during your last assessment.
This interactive checklist runs entirely in your browser — nothing is sent to our servers. You can screenshot or print your results for internal reference. For a persistent compliance tracking system with evidence collection and auditor sharing, you'll want a dedicated GRC (governance, risk, and compliance) platform.

Ready to Close Your Compliance Gaps?

Shield installs in minutes and gives you the data protection layer that every compliance framework requires. Your sensitive data — PII, PHI, cardholder data, and secrets — stays on your machines, never reaching ChatGPT, Claude, or Copilot.

Talk to Our TeamHow Shield Works

Last updated: July 21, 2026