Assessment

How mature is your organisation's AI governance?

Seven areas. 38 questions. About fifteen minutes. No sign-up.

AI governance is the set of practices by which an organisation knows what AI it is using, decides what is acceptable, controls what actually runs, watches what happens in production and can demonstrate all of this to someone outside the organisation. Most organisations have some of these practices and few have all of them. The gaps are rarely where people expect.

How it works

This assessment measures those practices across seven areas. It asks 38 questions. Each question offers five descriptions of what the practice looks like at increasing levels of maturity, plus a "don't know" option. You choose the description that most closely matches how your organisation actually operates today, not how it is documented or how it is intended to operate.

It takes about fifteen minutes. There are no right answers and the result is not a grade. It is a picture of where your governance is strong, where it is thin and what the next level looks like in each area.

Answer for the organisation as a whole, or for the part of it you can speak for. If you are unsure whether something exists, "don't know" is a valid and useful answer. Not knowing is itself a finding.

The seven areas

  • Accountability and oversight. Who owns AI outcomes, whether the board sees them, and whether decisions about AI are made by a defined body and recorded.
  • Policy and people. Whether the rules for AI use are written, usable and current, and whether the people bound by them have actually been trained.
  • Inventory and discovery. Whether the organisation knows what AI it uses, including tools staff have adopted on their own, AI embedded in purchased software and agents acting on its behalf.
  • Risk assessment. Whether each AI system is assessed against a defined method, whether the assessment covers the people it affects and whether AI risk sits inside the organisation's normal risk management.
  • Controls and enforcement. Whether the controls that govern AI operate as mechanisms in the path of live traffic, or exist only as documents and good intentions.
  • Monitoring and incident response. Whether the organisation can see how its AI is behaving in production, notice when something changes and handle an incident through to closure.
  • Evidence and assurance. Whether the organisation can show an outside party what it did and when, without reconstructing the story afterwards, and whether that evidence can be verified without taking the organisation's word for it.

How it is scored

Each answer maps to a maturity level from 1 (Absent) to 5 (Optimised). "Don't know" scores 0. Each area receives the average of its questions. The overall result is a weighted average of the seven areas. Three areas carry more weight because everything else depends on them. Inventory, because you cannot govern what you have not found. Enforcement, because this is where harm is prevented or not. Evidence, because this is what an outside party asks for. The scoring method is set out at the foot of the results page.

These six labels are used for every question. Each question's options are written as concrete descriptions of what that level looks like for that specific practice, so the labels are a guide rather than the answer itself.

ScoreLevelWhat it means in general
0Don't knowYou are not aware whether this practice exists or who would know.
1AbsentThe practice does not exist. Nothing is written, nothing is done, nobody owns it.
2Ad hocSomething exists but it depends on individuals. It was done once, or is done inconsistently, and there is no owner or cadence.
3DefinedThe practice is documented, owned and followed. There is a written method, a named person and a repeatable process.
4ManagedThe practice is operating, measured and maintained. It runs on a cadence, produces records and someone checks that it is working.
5OptimisedThe practice is embedded in how the organisation works, largely mechanised, continuously reconciled against reality and improving from what it observes.

Before you begin

The assessment is self-reported. It measures practice, not outcomes, and it cannot tell whether a control you describe as operating is actually operating. Treat the result as a structured conversation with yourself rather than a verdict.