Questions people actually ask
Do I need this if we only use ChatGPT?
Yes, and often more than organisations running bespoke systems. Most of the exposure we find sits in general-purpose tools used informally: client or patient information pasted into free accounts, no record of which decisions the output influenced, and nobody with the authority to say no to a new tool. A single widely used assistant, unmanaged, is a bigger governance gap than a well-documented custom system.
Does the EU AI Act apply to a UK business?
It can. The EU AI Act applies on the basis of where the output is used, not only where the provider is established — so a UK business whose AI output is used by people in the EU can fall in scope. GPAI obligations came into force on 2 August 2026; high-risk obligations were deferred to 2 December 2027 under the Digital Omnibus package. Two questions in the assessment appear only if you tell us you operate in, sell into or serve customers in the EU, and they establish whether this is worth your attention. Position verified 3 September 2026; general information, not legal advice.
What’s the difference between AI readiness and AI compliance?
Readiness is a measure of how well prepared your organisation is: whether AI use is owned, documented, reviewed and evidenced. Compliance is a formal determination against a specific standard or regulation, made by a body with the authority to make it. This assessment measures readiness — a score, a maturity profile and prioritised findings. It never states that an organisation is or is not compliant with anything, because that is not a claim we are in a position to make.
Will this tell me whether we’re compliant?
No. It tells you where you stand and what the standards actually ask of you, which is what most organisations are missing. Anyone selling you a compliance verdict from a questionnaire is selling you something they cannot deliver.
We’re a small clinic — is this overkill?
No. A small regulated practice usually has a shorter list of AI tools and a shorter route to fixing what matters, which makes the assessment quicker and the findings more actionable, not less. The free tier takes under twelve minutes and costs nothing. If you tell us you are regulated, the report names the regulator likely to take an interest in how you use AI — ICO, CQC, GDC or MHRA depending on what you do.
How long does it take, and what do you need from us?
The free self-assessment is 42 questions and takes most people under twelve minutes. Nothing needs looking up, no technical knowledge is required, and “Not sure” is a valid answer to every question — knowing what you don’t know is part of what this measures. Your scored report comes back by email within two working days. The paid tiers need more of your time: a Mini Scan is about two hours remote, a Quick Scan about a day, and a Full Audit up to a week combining on-site and remote work.
What happens after the assessment?
You receive a report with your readiness and governance scores, what they mean, the findings that matter most for an organisation like yours, and exactly one recommended next step. Sometimes that step is “nothing, revisit in six months” — and when it is, that is what the report says. Nothing else happens until you have read it. No sales call is required to receive it, and we send it whether or not you book anything.
Who sees our answers, and how is our data handled?
Submissions go to VisionXY7 and are reviewed by Dr. Mahdi Seify. Data is encrypted in transit and at rest, hosted in the UK or EEA, and handled under ISO/IEC 27001-aligned practice. Consent to receive the report and consent to marketing are asked separately, and either can be withdrawn. We never ask for documents, and we ask you not to put personal, client or patient information in the free-text boxes. Records are kept for 24 months and then deleted or irreversibly anonymised, and you can ask for deletion at any time without logging in to anything. The full detail is in the assessment privacy notice.
Do you certify us against ISO/IEC 42001?
No — and no consultancy can. ISO/IEC 42001 certification can only be granted by a certification body accredited under ISO/IEC 42006. What VisionXY7 does is prepare you for that assessment: a gap assessment against the standard, the policy and control framework to close what is missing, and an independent internal review before you engage an accredited body. If a consultancy offers to certify you against ISO/IEC 42001, they are describing something they are not able to do, and that is worth knowing before you sign anything.