Step 3 of 3: 0 of 25 answered

Section 1 of 6

Governance & accountability

0 / 7 answered

Answer Key

In place:Defined + implemented + used in practice
Partially in place:Implemented in some areas or inconsistent
Planned:Committed and expected within 6 months
Not in place:Not defined or not implemented
N/A:Not applicable (excluded from scoring)
1

Do you have a named accountable owner (or committee) for AI risk and compliance, with documented responsibilities and escalation routes?

2

Is an AI risk assessment required before production release and before any material change (new model, new data, new decision context)?

3

Do you have a written AI acceptable-use and secure AI engineering standard that is communicated and enforced (including contractors)?

4

Is your AI risk register reviewed on a defined cadence by governance stakeholders (security, privacy, legal/compliance, product/engineering)?

5

Do executives/board receive periodic AI risk reporting (KPIs, top risks, incidents, audit results, remediation status)?

6

Is there periodic independent assurance (internal audit/second line or equivalent) over AI controls and risk management?

7

Do you publish (or provide to customers) a clear statement of your responsible AI / AI governance commitments and how you operationalise them?