Digital sovereignty self-assessment

# Where do you stand on digital sovereignty?

A ten-minute, 16-question self-check across 8 dimensions, scored 0 to 4. It takes its cue from the EU Cloud Sovereignty Framework and adapts the same idea into a broader question of how much governed, provable control you hold over your data and workflows, wherever they run.

 **Private by design.** Everything runs in your browser. Nothing is stored, sent, or saved anywhere.

 Organization (optional)  

 Role (optional)  

 

 Start 

  This assessment scores your answers in your browser, which is how it avoids sending them anywhere. That needs JavaScript. All 16 questions are listed below, so you can still read and answer them on paper.

 ## The scale

  0 No control. The capability sits entirely outside your organization, with no visibility and no recourse. 

 1 Contractual only. Control exists on paper through vendor terms, but not in your own hands. 

 2 Partial and inconsistent. Some control exists, but it is uneven across teams and hard to prove. 

 3 Governed and repeatable. Control is deliberate, consistent, documented, and inspectable. 

 4 Owned and portable. Full operational control, evidenced, with the freedom to switch or exit without breaking critical operations. 

  

 

 

Question 1 of 16

 



 

  For your most critical systems, do you know exactly where data is stored and which jurisdictions can legally compel access to it?   We do not have a clear picture of where critical data physically resides.    We know the region because a contract states it, but have not verified it.    We know residency for some systems, but it is inconsistent across the estate.    We have verified residency and jurisdictional exposure for most critical systems.    We have full, evidenced residency mapping and have addressed extraterritorial access risk.  

   If a jurisdictional or regulatory rule changed tomorrow, could you move or isolate the affected data without breaking operations?   We would have no practical way to respond.    We would depend entirely on a vendor to act for us.    We could respond for some systems, with significant disruption.    We have a tested plan for most critical data.    Data is structured and portable enough to relocate or isolate with minimal disruption.  

   If your primary vendor or cloud provider became unavailable, could your team maintain and recover critical systems without them?   We could not operate or recover without the provider.    Recovery depends on provider support we cannot guarantee.    We could recover some systems, slowly and partially.    We can maintain and recover most critical systems independently.    Full operational independence with tested recovery across critical systems.  

   Do you have visibility into how your critical environments are operated, configured, and accessed?   Operations are an opaque box we do not see into.    We rely on vendor reporting we cannot independently verify.    We have partial visibility for some environments.    We have consistent, inspectable visibility across most environments.    Full, evidenced operational visibility and access control across the estate.  

   How dependent are your critical workflows on proprietary formats, APIs, or services that would be hard to replace?   Critical workflows are deeply tied to one vendor and effectively unmovable.    We are locked in, and exit cost is high but theoretically possible.    Some systems are portable, others are tightly coupled.    Most critical systems use open or portable standards.    Architecture is deliberately portable, with exit paths validated.  

   When you choose a new platform or tool, do you assess exit cost and portability as part of the decision?   We do not consider exit or portability when choosing tools.    We consider it informally, after the fact.    We consider it for major decisions only.    Portability is a standard part of our selection process.    Exit cost and portability are required, documented criteria for every critical choice.  

   Do you control which AI models can access your data, where those models run, and what they are permitted to do with the data?   We have no control or visibility over AI access to our data.    Control exists only through a provider's terms.    We control this for some use cases, inconsistently.    We govern model access, location, and permitted use for most AI use cases.    Full, evidenced control over model execution, data access, and inference governance.  

   If a model provider changed access, pricing, terms, or availability, could your critical AI-enabled workflows continue?   A provider change would halt critical workflows.    We depend on a single provider with no fallback.    We have alternatives for some workflows.    Most critical AI workflows have governed fallback options.    AI workflows are model-agnostic and resilient to provider change.  

   Is your critical data and content structured, governed, and clean enough to be safely used by AI and automated systems?   Data is messy, duplicated, and ungoverned.    Some governance exists on paper but is not enforced.    Pockets of the estate are well governed, most are not.    Most critical data is structured, governed, and reusable.    Data and content are fully governed, structured, and AI-ready across the estate.  

   Can you clearly establish who owns each critical data set, who can access it, and how that access is controlled?   Ownership and permissions are unclear or undocumented.    Ownership is assumed but not formally defined.    Ownership is clear for some data, unclear for the rest.    Ownership and access are defined and enforced for most critical data.    Full, evidenced ownership and access control across all critical data.  

   For your AI-assisted business processes, have you defined which actions can be automated, which require human review, and who can stop or change the workflow?   AI-assisted actions happen without defined controls.    We have a policy document, but it is not enforced in the workflow.    Controls exist for some workflows, inconsistently.    Most critical workflows have defined automation, review, and stop controls.    Every critical workflow has enforced, inspectable control over automation and human review.  

   If an AI-supported process produced a wrong or risky output, could you trace which sources and steps produced it, and correct the process?   We could not trace or explain how the output was produced.    We could investigate manually, with difficulty and no guarantee.    We can trace some workflows but not others.    Most critical workflows are traceable and correctable.    Full traceability and correction built into every critical workflow.  

   Is governance (security, privacy, compliance, content quality, AI usage) built into your platforms and workflows, rather than checked at the end?   Governance is manual and applied after the fact, if at all.    Governance exists as policy but lives outside the systems.    Governance is built into some systems, bolted onto others.    Governance is built into most critical platforms and workflows.    Governance is native to the platform and enforced in-workflow across the estate.  

   Could you produce audit evidence (logs, telemetry, audit trails) showing what your systems and AI tools actually did, when, and on whose authority?   We could not produce this evidence.    Evidence is partial and would need heavy manual reconstruction.    We can evidence some systems but not consistently.    We can produce reliable audit evidence for most critical systems.    Complete, continuous, inspectable audit evidence across the estate.  

   Is it clear, for your critical systems, who can do what, what needs approval, and how to roll back when something goes wrong?   Roles, approvals, and rollback paths are unclear or hidden.    They exist informally but are not documented or easy to follow.    They are clear for some systems, unclear for others.    Roles, approvals, and rollback are clear and usable for most critical systems.    Clear, enforced, easy-to-follow accountability and rollback across the estate.  

   As AI takes on more work, do your people still meaningfully shape and judge outcomes, rather than rubber-stamping machine output?   AI output is accepted with little meaningful human judgment.    Review exists but is largely symbolic.    Meaningful human judgment applies to some processes, not others.    Human judgment is built into most critical AI-assisted work.    Human judgment and accountability are designed into every critical workflow.  

  Back Next 

 

 

 # Your result

 0

 

 

 ## Eight dimensions



  ## Priority gap

  ## The two tiers

### Tier 1 · Accepted ground

 0.0 / 4

Infrastructure, residency, environment, lock-in, AI execution

 

### Tier 2 · The frontier

 0.0 / 4

Data, workflow, governance, human oversight

 

 

 Most organizations score higher on the accepted ground than on the frontier. The distance between the two is the work that defines digital sovereignty in 2026.

  

 ## Breakdown

   Your score from 0 to 4 for each of the eight dimensions, with the tier each belongs to.    \# Dimension Tier Score     1 Data residency and jurisdiction T1     0    2 Operational and environment control T1     0    3 Technology choice and lock-in T1     0    4 AI execution control T1     0    5 Data and content governance and readiness T2     0    6 Workflow sovereignty T2     0    7 Governance, evidence, and observability T2     0    8 Human accountability and oversight T2     0     

  ## What this does not tell you

This is self-scored, so it reflects how you read your own organization, and self-assessment tends to run optimistic. Treat a strong score as a prompt to verify rather than as proof. It is a snapshot of 16 questions, not an audit, and it covers the data and workflow layer by design rather than the full sovereignty picture. It will point you to where your control is thinnest. It will not, on its own, tell you how to fix it.

  Download my result as PDF Start over 

 Nothing on this page has been sent anywhere. Refresh to discard.