AI risk assessment for marketing teams
Eight questions on how your team actually uses AI. You get an exposure tier, the two or three places your risk is concentrated, and the approval workflow that fits — not a generic policy template. It scores in your browser and nothing is stored.
How widely is AI already used across your marketing work?
Does your marketing make performance, pricing or comparative claims?
How regulated or claim-sensitive is your sector?
What kind of information gets pasted into AI tools?
Is there a written rule for what AI may and may not be used for?
What happens before AI-assisted content is published externally?
If a published claim were challenged, could you show what evidences it?
Since adopting AI, has your content held its distinctiveness?
Exposure sets the workflow, not the other way round
Governance that costs more than the risk it removes does not get followed, which is worse than none at all because it creates a false record of control. So the approval model scales with what is actually at stake.
Contained exposure
AI use is limited, or the controls around it are already doing their job. The risk here is complacency rather than exposure: as usage widens, the informal checks that work today stop scaling. Keep the rules light, write them down, and revisit them when adoption steps up.
Workflow: Light-touch approval
Moderate exposure
AI is embedded enough to matter and the controls have not caught up. Nothing here is alarming on its own, but the combination — daily use, external publishing and no documented boundary — is how unevidenced claims and quiet data leaks happen. A single reviewer and a short evidence habit closes most of it.
Workflow: Single-reviewer approval
Elevated exposure
You have real exposure: AI in regular use, claims or regulated content in play, and no reliable record of what was checked. This is where a challenged claim becomes a scramble and where confidential detail has probably already been pasted into a public tool. Governance here is genuinely urgent, and cheap relative to the risk.
Workflow: Tiered approval with recorded evidence
Critical exposure
Heavy AI use, claim-sensitive output, sensitive data in public tools and no gate anywhere. The realistic assumption is that something has already gone out that you could not defend if it were questioned. Fix the data boundary and the publish gate this week; the documentation can follow.
Workflow: Gated approval with an audit trail
The AI Governance Starter Pack
The templates that turn your result into something operational: a one-page AI use policy, a risk register with starter rows already written, and a tiered approval workflow with the pre-publication checks to go with it.
- A one-page AI use policy your team will actually read
- A risk register with six starter rows most marketing teams need
- A three-tier approval workflow sized to real exposure
- A six-question pre-publication checklist for your content brief
- A session plan for completing the pack with the people who publish
PDF · 10 pages · templates, not legal advice. Your details are used to send the pack and nothing else.
Questions about the AI risk assessment
What does the AI risk assessment actually measure?
How is the exposure tier calculated?
Why does the recommended approval workflow have tiers rather than one rule?
Is anything I enter stored or sent anywhere?
Is this legal advice?
Do you use AI in your marketing consultancy work?
Why should I use you as my marketing consultant rather than an agency?
What makes you different from other Fractional CMOs and marketing consultants?
How much does a marketing consultant cost compared with hiring a Marketing Director?
Do you work with B2B, retail and SaaS businesses?
How quickly will I see results from working with a marketing consultancy?
Will you replace my team or agency?
How do you measure success, and how am I kept accountable to it?
What does the first conversation involve, and is there any commitment?
Where to go next
A few things worth reading — and the pages most people move to from here.
Related insights
- AIAI in SME Marketing: Where It Genuinely Helps and Where It Wastes MoneyA practical view of where AI earns its place in a small marketing function.
- AIThe AI Operating Model: What a Small Marketing Team Should Automate FirstWhich marketing tasks to hand to AI, which to keep human, and how to govern the difference.
Want the governance built rather than described?
The assessment tells you where the exposure is. A governance engagement puts the policy, the register, the brand-safety standards and the approval workflow in place with the team that has to use them.
