Sixteen questions, about twelve minutes. At the end you’ll know — bluntly, and possibly for the first time — how much of your practice is running without a last step. Score honestly: a flattering score is a lie you’ll pay for later.
Answer each question 0 (no / never), 1 (informally), or 2 (yes, in writing). Your answers are scored on this page; at the end we’ll email you your rating together with the book The Trusted Machine and the free 8-tool toolkit.
Answered 0/16
Get your rating — plus the book and the toolkit.
Answer all sixteen questions. Then enter your email and we'll rate where your firm stands and send you the book together with the free 8-tool toolkit.
We'll email your rating, the book, and the free 8-tool toolkit to remediate any issues — no sequence, no drip, no sharing your address, unsubscribe in one click.
0/32
—
This outranks your total
Want a second pair of eyes on this?
We'll walk through your scorecard with you — where you're exposed, and what to do in what order. No charge, and no obligation.
No account, no email, no tricks: these are the exact questions the scorecard asks. Share them with a partner, or walk the office through them at your next staff meeting. The interactive version above scores them and tells you what to fix first.
Section A · Data & confidentiality
We have a written rule about what client data may and may not be entered into AI tools.
Staff use approved AI tools with data protections (paid/enterprise or zero-retention), not personal free accounts.
We know every AI tool touching client data — including browser extensions, meeting note-takers, and connectors that link AI to our systems.
Section B · Fraud & deepfakes
A zero anywhere in this section outranks your total.
Money movement and data-release requests require out-of-band verification (a call-back on a known number), not just an email or a video call.
We use a codeword or dual authorization for high-value transfers.
Staff have been told, in the last 12 months, that voices and videos can be faked.
Section C · Reliability & verification
Nothing AI-generated reaches a client without a human review step.
We verify AI factual claims (citations, tax rules, figures) against a trusted source before they go out.
We ground AI in our real numbers rather than asking it to recall or estimate them.
Section D · Security posture
We run vulnerability scans / penetration tests on a schedule — not just once.
We have a written information security plan (a WISP) reviewed in the last 12 months.
Staff receive ongoing security education, not a one-time onboarding session.
Section E · Agency & action control
These four ask what your AI can DO, not what you paste into it. A zero here outranks your total.
We know exactly which AI tools can take an action (send an email, move money, place a call, post publicly, write to a ledger) rather than only produce text.
No AI can move money, send externally, or change a client record without a human approving that specific action.
Every AI-taken action is logged, with a trail we could produce for an auditor, a client, or an insurer.
If a client asked, “prove your AI didn’t send this,” we could — because AI-originated messages are identifiable.
How it’s scored
Each question scores 0 (no / never), 1 (informally), or 2 (yes, in writing), for a maximum of 32. Ratings: Exposed (0–10), Partial (11–21), Governed (22–29), Trusted Machine (30–32). A zero on any critical question in Fraud & deepfakes or Agency & action control outranks your total — those are the two places where a gap is not a weakness but an open door.
These questions come from The Trusted Machine by Mark Kennedy. Read about the book →
The suite is the fix, built in.
Everything the scorecard checks for — human approval on every action, a daily security watch, an audit trail — is how the WOW AI Suite works out of the box. WOW Sentinel checks your AI stack daily.