AI Governance Readiness Report
This is an example of the free report you receive on completing the assessment. Figures are illustrative and informational only.
Domain scores
Top strengths
- Named owner assigned for AI governance
- SSO/MFA enforced for AI admin tooling
- AI-specific risk review during vendor onboarding
Top gaps
- No formal AI intake or approval workflow
- Weak access controls before content enters the RAG index
- Low evidence coverage behind stated controls
Priority recommendations
- P00–30 daysCreate and maintain an AI system inventory
Stand up a single inventory of AI systems, copilots, agents, and AI-enabled workflows, each linked to an owner and intended purpose.
- P130–60 daysEnforce access control before indexing RAG content
Apply access controls and scoping before content enters the retriever/index, and add a process to remove stale or sensitive content.
- P130–60 daysDefine human review and override for material AI outputs
Document where human review, intervention, or override applies when AI outputs could materially affect a person or business process.
Detailed gaps, framework mapping & remediation roadmap
The full report adds control-by-control gap analysis, NIST AI RMF / ISO 42001 / EU AI Act mapping, a prioritized remediation roadmap, and benchmark context. A verified assessment adds analyst review and sampled evidence validation.
This report is illustrative and informational only. It is not a legal, security, compliance, audit, or certification determination.
