Fifteen questions, about five minutes, two scores. Who in your service currently has nobody to ask? And if something answered them, could you show a regulator, an auditor or a client what it was told and what it said?
Your score appears before we ask you for anything. Answer honestly. Nobody is watching, and a flattering score tells you nothing.
You get two scores because they answer two different questions, and they move independently. Strong on one says nothing about the other.
Who in your service currently has nobody to ask. A social worker whose week overruns, a carer with a question at nine on a Sunday night, a young person who wants to read what has been written about them. And what the record you keep now will be worth to that child later.
If AI did that work, could you say where your information went, who processed it, in which country, under whose law? And could you show exactly what the tool was told and what it answered? That is what a regulator, auditor or client would ask for.
Your two scores place you in one of four positions. Each one has a clear next step.
{{ quadBlurb }}
Neither of these changes your score. They decide which half of the read-out is worth your time.
Inside: your three next actions in order, a score for where your information goes, the eight questions a regulator would ask you, and an honest note on what this scorecard cannot tell you.
{{ confirmNote }}
Opportunity {{ oppPct }} · Defensibility {{ defPct }} · Data control {{ dcPct }} · {{ quadName }}
Written so you could put it in front of a board or a management meeting without translating it first.
You built the controls, and nobody is better served than they were. The social worker, the carer and the child are where they started. The hard half is already done.
People who would be better served, and the records to prove what happened. The strongest position and the rarest one. Your question is how fast to scale, not whether you are allowed.
Not much AI happening, not much exposure. Comfortable, and easy to stay in too long. The moment people start using AI, the record needs to already be there.
People across your service need answers, and there is no record of what AI is already telling them. They reach for it anyway, in browser tabs, unrecorded. The most common position, and the most expensive one to ignore.
Answer these two in your head and you will know whether the other thirteen are worth five minutes.
Where does the processing physically happen when your people use AI, and under whose law?
How long does it take someone to find the answer to a policy or case question that is already somewhere in your own documents?
No trick questions and no points for optimism. The uncomfortable answers are the useful ones.
Every vendor assessment has limits. Most bury them. Here are ours, before you start rather than after.
We sell control over information, so here is how this page handles yours, plainly.
Your answers stay in your browser while you take the scorecard. The score is worked out on your device. If you close the tab before asking for the read-out, nothing has reached us at all.
When you ask for the full read-out, we receive your answers along with the name, work email and organisation you give us. Your read-out downloads straight away. We also email that address a link to confirm it is yours; only if you click it do we email your read-out and, if you ticked the box, add you to occasional updates. If you never confirm, we keep nothing. One click unsubscribes. We do not sell or pass your details to anyone, and we do not enrich them from third party data.
If we ever publish anything from the results, it will be aggregate only, with the sample size stated, and never attributed to an organisation. Read the privacy notice.
Full details, including your rights, are in the privacy notice.
Anyone accountable for how information is handled in a regulated organisation. It was written first for social care, where the material is about children and vulnerable adults and the recording burden is heaviest, and it applies without translation to legal, healthcare, education and professional services.
It is aimed at the person who would have to answer if somebody asked. A director or a registered manager. A DPO or information governance lead. A COO or an operations director. A partner or a practice manager. If AI use in your organisation would land on your desk when it went wrong, this is written for you.
Anyone comfortable with cloud AI inside their existing boundary who needs no evidence of how it was used. That is a legitimate position and it does not need a scorecard.
About five minutes. Fifteen questions, one screen each, four options each. There are two more at the end that do not affect your score and take a few seconds.
No. Your scores, your position and the five detail bars all appear before any form. The email is only for the full read-out: the actions, the eight questions, and the score for where your information goes.
The read-out ends with a page about Chrysalis, because we made it and we are not pretending otherwise. Everything before that is written to be useful whether or not you ever speak to us. Two of the four positions have next steps that involve no supplier at all.
Yes. The questions are about how AI processes your information and what record survives, and that applies inside Microsoft 365 just as much as anywhere else.
Yes. Answer for whatever unit you can honestly answer for, and say so when we speak. A directorate and a whole council will produce very different scores, and both are worth having.
That is what it is for. The read-out prints cleanly, and you can save it as a PDF from your browser.
Most are, on the defensibility side. It is a new category and almost nobody has this straight yet. The scorecard is more useful as a map of what to fix in what order than as a grade.