Richard Taylor Consultancy
Shadow AI Health Check for Small Businesses
© Richard Taylor Consultancy, 2025. All rights reserved.
Web: https://www.rtconsultant.co.uk

SECTION 1 – INTRODUCTION
Shadow AI already sits inside many small businesses. Staff sign up for AI tools with personal email addresses. They paste client information into prompts. No one in leadership has a clear view.
This health check helps you:
  • Spot where shadow AI already appears in your business
  • Gauge the level of risk
  • Prepare for a focused AI strategy conversation
It works best for owner-managers and senior leaders in businesses with roughly 5 to 200 staff.
Time needed: around 20 to 30 minutes.

SECTION 2 – HOW TO USE THIS GUIDE
Work through each section in order. For every closed question, pick the answer that feels closest to your business today. Note your score for each question. Add section scores, then total score at the end. Use the reflection prompts to collect examples and questions for follow-up.
Scoring for each closed question
A = 0 points (good control)
B = 1 point (some risk)
C = 2 points (high risk)
Red flag answers
Any C answer highlights a high risk area. Even a modest total score with several Cs deserves attention.

SECTION 3 – VISIBILITY OF AI USE

Q1. How aware are you of AI tools in day-to-day work?
A. We hold a clear list of AI tools in use and who uses them.
B. I know some tools in use, although the list feels incomplete.
C. I have little or no idea which AI tools staff use.

Q2. How often do staff sign up for AI tools on their own?
A. Staff use accounts supplied or approved by the business.
B. Some staff use their own accounts for work tasks.
C. Most AI use sits on personal accounts that the business does not see.

Q3. Where do staff access AI tools?
A. Primarily from work devices with standard security in place.
B. Mix of work and personal devices.
C. Largely from personal phones or home laptops outside any IT oversight.

Q4. Do you have any written guidance on AI use?
A. We have a short, clear policy and people know where to find it.
B. AI use appears in one or two documents, though staff rarely refer to them.
C. No written guidance exists yet.
Section 3 score: ____ / 8
Reflection prompt
Where do you think AI use is highest in your business today (for example sales, marketing, operations, finance, HR)?
Notes:

SECTION 4 – DATA AND CONFIDENTIAL INFORMATION

Q5. Do staff enter customer or client names into public AI tools such as ChatGPT?
A. Only in approved tools with clear rules and safeguards.
B. Sometimes, although staff try to limit detail.
C. Often, including full names and context.

Q6. Do staff paste emails, documents or reports with personal data into AI prompts?
A. Not without prior checks and clear guidance.
B. Sometimes, when time pressure rises.
C. Regularly, as part of normal working habits.

Q7. Do staff ever paste sensitive information into AI tools (for example health details, financial history, legal issues, HR records)
A. Staff have clear rules and avoid this type of data in public tools.
B. I suspect this happens occasionally in tricky cases.
C. I know this happens and have seen examples.

Q8. How do you handle client or supplier concern about AI use and data?
A. We can explain our approach, tools and controls in plain terms.
B. We answer on a case-by-case basis.
C. We would struggle to answer detailed questions about AI and data.
Section 4 score: ____ / 8
Reflection prompt
Write down any examples where staff used AI with live customer or client information.
Notes:

SECTION 5 – CHATGPT AND DATA CONTROLS

Q9. Do staff use their own ChatGPT accounts for work?
A. No, staff only use approved business or enterprise accounts.
B. Some staff use their own accounts for work tasks.
C. Most AI work runs through personal ChatGPT accounts.

Q10. How well do you understand the "Data Controls" section in ChatGPT settings?
A. I understand those settings and how they relate to business risk.
B. I know the menu exists, though I feel unsure what it changes.
C. I had not heard of those settings until now.

Q11. Have you heard staff say something like "I switched off sharing in ChatGPT so this is safe"?
A. No, staff receive clear training on what those settings do and do not do.
B. I have heard this once or twice.
C. I hear this often and I am not fully confident it is correct.

Q12. Do you hold a clear record of which staff have changed their ChatGPT data settings?
A. Yes, for business accounts this sits under central control.
B. We have partial visibility at best.
C. No, each person manages their own settings.
Section 5 score: ____ / 8
Reflection prompt
Note any beliefs or myths you have heard inside the business about ChatGPT data settings.
Notes:

SECTION 6 – SECURITY AND ACCESS CONTROL

Q13. Where do AI tools store prompts, files and outputs for your staff?
A. In locations reviewed by IT or an external adviser.
B. Mix of checked and unchecked locations.
C. We do not know where data is stored or processed.

Q14. Do staff use business email and single sign-on for AI tools?
A. Yes for all approved tools.
B. Some tools link to work email, others sit on personal accounts.
C. Mostly personal email accounts with separate passwords.

Q15. Have you added AI tools to your existing security and incident plans?
A. Yes, AI tools appear in security policies, training and incident response plans.
B. AI appears in some security conversations, though plans lack detail.
C. AI tools sit outside current security thinking.
Section 6 score: ____ / 6
Reflection prompt
Note any AI-related security incidents, near misses or worries raised by staff.
Notes:

SECTION 7 – GOVERNANCE, POLICY AND TRAINING

Q16. Do you have an agreed AI strategy or at least an AI use policy?
A. Yes, leaders agreed a simple strategy and shared policy with staff.
B. We have draft material and informal guidance.
C. We rely on common sense and ad-hoc decisions.

Q17. How clear are staff on what they must never paste into AI tools?
A. Staff receive clear training and examples of forbidden data.
B. Staff have seen some guidance, though understanding varies.
C. Staff rely on their own judgement.

Q18. Do you carry out Data Protection Impact Assessments (DPIAs) for higher risk AI uses (for example recruitment, profiling, large customer databases)
A. Yes, DPIAs cover all relevant high risk AI uses.
B. DPIAs exist for some projects.
C. We have never carried out a DPIA for AI.

Q19. How often do leaders review AI use and incidents across the business?
A. At least once a year, often more.
B. Only when an issue arises.
C. Never so far.
Section 7 score: ____ / 8
Reflection prompt
Where would you like AI to support the business in a more structured way over the next year
Notes:

SECTION 8 – TOTAL SCORE AND INTERPRETATION
Add your section scores.
Section 3: ____ / 8
Section 4: ____ / 8
Section 5: ____ / 8
Section 6: ____ / 6
Section 7: ____ / 8
Total score: ____ / 38
How to read your score
0 to 10 points
Low visible shadow AI risk
You appear to hold a good grip on AI use. Controls exist and staff have some clarity. Focus on regular review, short refresher training, and better alignment between AI and business goals.
11 to 20 points
Shadow AI present in pockets
AI use has started to spread with mixed levels of control. Focus on a short AI strategy, clear policy, and a tidy list of approved tools. Address any C answers first.
21 to 30 points
Significant unmanaged AI use
Shadow AI appears across several teams with weak oversight. Risk sits around data protection, security and client trust. You need a structured AI strategy, priority actions and clear ownership at senior level.
31 points or more
High shadow AI exposure
AI use across the business sits largely outside formal control. There is a realistic risk of data breaches, client concern and regulatory attention. You need urgent action on AI strategy, governance and training.
Red flags, regardless of total score
Pay close attention if you answered C to any of these questions:
  • Q5, Q6 or Q7, staff frequently use live customer or client data in public AI tools
  • Q9, most AI use sits on personal ChatGPT accounts
  • Q13, no one knows where AI tools store or process data
  • Q18, no DPIAs for high risk AI use
These answers highlight areas where risk sits high even if your total score looks modest.

SECTION 9 – WHAT TO DO NEXT
Short term actions you are able to start alone
  • Make a simple list of AI tools in use and who uses them
  • Identify where customer or client personal data enters AI tools
  • Share a short message with staff that explains:
  • Which tools they should use for work
  • Data types they must never paste into public tools
  • Who to speak to if they feel unsure
Medium term actions where expert support helps
  • Design a light AI strategy that fits your size and sector
  • Decide which tools to approve and which to block or phase out
  • Align AI use with data protection, security and HR policies
  • Run short training sessions for staff and managers
  • Plan regular review of AI use, incidents and new opportunities

SECTION 10 – HELP FOR SME OWNERS
SME owners and leadership teams who recognise that AI is already in their business, but feel unsure how to bring order and safety to it need to have an AI Strategy in place.
Typical outcomes from an AI strategy project:
Clear view of where AI already appears in your business
Simple principles for safe and productive AI use
Short list of approved tools and use cases
Policy and training material in plain language
Roadmap for the next 6 to 12 months
If your score suggests shadow AI risk, or if this guide raised new concerns, a structured conversation will help.
Contact details
© Richard Taylor Consultancy, 2025. All rights reserved.
Made with