Two questions, really. Can your organisation use AI well? And could it show anyone that it does? Forty-two plain-English questions answer both, scored separately, because the gap between the two is usually the finding.
42 questions · under 12 minutes · no account, no card, no sales call required to receive your report.
Been asked for ISO/IEC 42001 by name — in a tender, a customer questionnaire, or by an insurer? That is a different question, and there is a different assessment for it. Go to the ISO/IEC 42001 assessment →
Eight questions establish your sector, size, EU exposure and whether AI touches decisions about people. This decides which standards are relevant to you and nobody else.
42 plain-English questions across eight dimensions. Nothing to look up. “Not sure” is a valid answer — and a useful one.
Two scores — Readiness and Governance — each placed in one of four maturity bands, with the critical questions weighted double.
Prioritised findings, in your language, weighted so the ones that matter most come first, with the regulator named if one applies to you.
Exactly one recommendation. If the honest answer is “nothing, revisit in six months”, that is what the report says.
Eight dimensions, grouped into two scores. Readiness asks whether your organisation can use AI well. Governance asks whether it can prove it. They are scored separately on purpose, because the gap between them is usually the finding.
Can you use AI well? Five dimensions.
Can you prove it? Three dimensions.
If you have been asked for ISO/IEC 42001 specifically, there is a separate assessment mapped directly to the standard’s clauses and controls — eight domains, eight Stage 1 gates, and a control-by-control gap register. See the ISO/IEC 42001 assessment →
AI is in use, but nothing about it has been decided, owned or written down yet.
Good instincts and some real practice, held informally — it works because of who is there, not because of what is in place.
Written, followed and owned. The structure exists; the remaining gaps are specific rather than general.
Evidenced, reviewed on a schedule, and improved when something goes wrong. Ready to be examined by someone else.
Four steps. You answer, we score, the findings are written up, and you get one recommended next step — by email, immediately, whether or not you ever speak to us.
42 questions, under 12 minutes, no jargon and nothing to look up. “Not sure” is a valid answer to every one of them.
Two scores across eight dimensions, with the critical questions weighted double, each placed in one of four maturity bands.
Scored against your sector and size, with the findings that carry the most weight named in plain language — and Dr. Mahdi Seify reads every submission personally afterwards.
Exactly one recommendation. If it is “nothing, revisit in six months”, the report says that instead.
Most AI maturity tools hand you a list of twenty things to fix. This one ends with a single recommended next step. A business given ten priorities has been given none.
The free assessment is scored on what you tell us. Everything above it examines the evidence behind those answers. You are never moved up a rung by the report — it recommends one next step, and sometimes that step is “nothing, revisit in six months”.
Scored on what you report. Eight dimensions, two scores, one next step, emailed immediately.
From £297 and from £950. Someone looks at the evidence behind one named issue, or one business area.
From £2,000. Up to a week, on-site and remote, report plus live debrief — then the policy, the approval gate and the controls if you want them built.
Five reference frameworks, named plainly. Where a standard is mentioned anywhere on this site, you will find one clause saying what it is actually for — because a standard nobody can explain is decoration, not grounding.
The management-system standard for AI — how an organisation governs AI on an ongoing basis, the way ISO/IEC 27001 does for information security.
Guidance on managing AI risk — how to identify, assess and treat the risks a specific AI system creates.
Guidance on AI system impact assessment — how to work out the effect on the people an AI-supported decision is about.
The US risk-management framework built on four functions — Govern, Map, Measure, Manage — widely used as a practical structure regardless of jurisdiction.
EU law that sorts AI systems into risk categories and attaches obligations to each. It can apply to a UK business whose AI output is used in the EU.
General information, not legal advice. This position is re-verified every 90 days.
Yes, and often more than organisations running bespoke systems. Most of the exposure we find sits in general-purpose tools used informally: client or patient information pasted into free accounts, no record of which decisions the output influenced, and nobody with the authority to say no to a new tool. A single widely used assistant, unmanaged, is a bigger governance gap than a well-documented custom system.
It can. The EU AI Act applies on the basis of where the output is used, not only where the provider is established — so a UK business whose AI output is used by people in the EU can fall in scope. GPAI obligations came into force on 2 August 2026; high-risk obligations were deferred to 2 December 2027 under the Digital Omnibus package. Two questions in the assessment appear only if you tell us you operate in, sell into or serve customers in the EU, and they establish whether this is worth your attention. Position verified 3 September 2026; general information, not legal advice.
Readiness is a measure of how well prepared your organisation is: whether AI use is owned, documented, reviewed and evidenced. Compliance is a formal determination against a specific standard or regulation, made by a body with the authority to make it. This assessment measures readiness — a score, a maturity profile and prioritised findings. It never states that an organisation is or is not compliant with anything, because that is not a claim we are in a position to make.
No. It tells you where you stand and what the standards actually ask of you, which is what most organisations are missing. Anyone selling you a compliance verdict from a questionnaire is selling you something they cannot deliver.
No. A small regulated practice usually has a shorter list of AI tools and a shorter route to fixing what matters, which makes the assessment quicker and the findings more actionable, not less. The free tier takes under twelve minutes and costs nothing. If you tell us you are regulated, the report names the regulator likely to take an interest in how you use AI — ICO, CQC, GDC or MHRA depending on what you do.
The free self-assessment is 42 questions and takes most people under twelve minutes. Nothing needs looking up, no technical knowledge is required, and “Not sure” is a valid answer to every question — knowing what you don’t know is part of what this measures. Your scored report arrives by email as soon as you finish. The paid tiers need more of your time: a Mini Scan is about two hours remote, a Quick Scan about a day, and a Full Audit up to a week combining on-site and remote work.
You receive a report with your readiness and governance scores, what they mean, the findings that matter most for an organisation like yours, and exactly one recommended next step. Sometimes that step is “nothing, revisit in six months” — and when it is, that is what the report says. Nothing else happens until you have read it. No sales call is required to receive it, and we send it whether or not you book anything.
Submissions go to VisionXY7 and are reviewed by Dr. Mahdi Seify. Data is encrypted in transit and at rest, hosted in the UK or EEA, and handled under ISO/IEC 27001-aligned practice. Consent to receive the report and consent to marketing are asked separately, and either can be withdrawn. We never ask for documents, and we ask you not to put personal, client or patient information in the free-text boxes. Records are kept for 24 months and then deleted or irreversibly anonymised, and you can ask for deletion at any time without logging in to anything. The full detail is in the assessment privacy notice.
No — and no consultancy can. ISO/IEC 42001 certification can only be granted by a certification body accredited under ISO/IEC 42006. What VisionXY7 does is prepare you for that assessment: a gap assessment against the standard, the policy and control framework to close what is missing, and an independent internal review before you engage an accredited body. If a consultancy offers to certify you against ISO/IEC 42001, they are describing something they are not able to do, and that is worth knowing before you sign anything.
This instrument is new, so there is no assessment case study to show you yet — and inventing one would be a strange way to open a conversation about governance. What there is instead is the method, and the person who built it.
The full method — the five-stage lifecycle mapped to ISO/IEC 42001 clauses, the eight dimensions, the maturity and evidence scales, and the standards crosswalk — is documented on his own site.
“Mahdi turned our complex ideas into clear, actionable solutions and delivered precisely what we needed. Professional, fast and strategically sharp.”
“Mahdi delivered a high-impact analytics and automation solution that improved our processes and added immediate operational value. Technically thorough and genuinely focused on embedding the solution.”
42 questions, under 12 minutes. Your scored report arrives by email straight away — a maturity profile across eight dimensions, and exactly one recommended next step. No account, no card, and no sales call required to receive it.
Start the free assessmentAsked for ISO/IEC 42001 specifically? That assessment is here →