AI Governance Readiness Assessment | JHarris Advisory
AI Governance · Readiness Assessment
AI Governance Readiness Self-Assessment
Do you actually know every AI system running in your organization?
28 questions6 domains15 to 20 minutesScored against NIST AI RMF-aligned governance practice
0
/ 56
02035465256
No score yet
Complete the assessment below
What you get, and what it costs. Your maturity score, level, and weakest domain appear immediately, free. Enter your email at the end for the full domain breakdown, per-domain remediation actions, your flagged priorities, and an engagement plan.
Twenty-eight questions across six governance domains. Score your current state, not your intent. This assessment is framework-neutral: it scores governance practices that hold up under the NIST AI Risk Management Framework, the EU AI Act's governance expectations, and the state AI statutes now coming into force. It does not tell you which specific laws apply to you, because that depends on your industry, where you operate, and what your systems actually do. Domain 5 asks whether you have answered that question.
0 = not in place · 1 = partially implemented or informal · 2 = fully implemented and documented. Use the Notes column to record evidence; notes stay in your browser and are never transmitted.
Organization Information
Optional
Domain 1 · Use Case Intake & Inventory
0 / 10
Q#
Assessment Question
Score 0 · 1 · 2
Notes / Evidence
Priority
1.1
The organization maintains a formal process to identify and document all AI/ML use cases before deployment.
1.2
Intake documentation captures the use case purpose, data inputs, intended outputs, and affected populations.
1.3
AI use cases are logged in a centralized inventory that is reviewed and updated at least quarterly.
1.4
Shadow AI and unapproved tools are surfaced through active discovery, not just self-reporting (vendor contract review, expense review, employee survey).
1.5
A named business owner is assigned and accountable for each active AI use case in the inventory.
Domain 2 · Risk Tiering & Classification
0 / 10
Q#
Assessment Question
Score 0 · 1 · 2
Notes / Evidence
Priority
2.1
A documented risk tiering rubric assigns High, Medium, or Low classifications to AI use cases based on defined criteria.
2.2
Tier assignment accounts for data sensitivity, whether the system informs consequential decisions, regulatory exposure, and the level of human oversight.
2.3
High-risk use cases require additional review, documentation, or approval before deployment.
2.4
Classifications are re-reviewed when material changes occur: new data sources, new outputs, or new affected populations.
2.5
Classification decisions are documented with written rationale and retained so the decision can be reconstructed later.
Domain 3 · Controls & Oversight
0 / 10
Q#
Assessment Question
Score 0 · 1 · 2
Notes / Evidence
Priority
3.1
Required controls are mapped to each AI use case based on its risk tier, so the control set follows from the classification.
3.2
Human review or override mechanisms are available for consequential AI-assisted decisions, and reviewers have the authority and information to actually overrule the system.
3.3
Access to AI tools and their outputs is restricted to authorized personnel with defined roles.
3.4
Audit logging is enabled for material AI decisions, with a defined retention period.
3.5
AI failure modes are addressed in the existing incident response plan, not treated as a separate untested process.
Domain 4 · AI Vendor Risk Management
0 / 8
Q#
Assessment Question
Score 0 · 1 · 2
Notes / Evidence
Priority
4.1
Vendor and third-party AI tools go through formal intake and risk review before deployment, including AI features added to tools you already use.
4.2
Contracts with AI vendors address data use and training rights, model transparency, and liability allocation.
4.3
AI vendor risk reviews occur at least annually, with an off-cycle trigger when a vendor materially changes its model or data practices.
4.4
A vendor AI portfolio list is maintained and reported alongside internal use cases, so leadership sees one picture rather than two.
Domain 5 · Regulatory Posture & Compliance
0 / 8
Q#
Assessment Question
Score 0 · 1 · 2
Notes / Evidence
Priority
5.1
The organization has determined which AI laws and frameworks apply to it, based on industry, the jurisdictions where it operates, and what its systems actually do.
5.2
An obligation calendar tracks deadlines, required disclosures, and compliance milestones, with a named owner for each.
5.3
Required disclosures or notices about AI and automated decision-making are in place where they apply.
5.4
Counsel or qualified advisors are engaged on AI regulatory posture at least annually, and before deploying AI in a high-exposure area such as employment, lending, housing, insurance, or health.
Domain 6 · Governance Structure & Accountability
0 / 10
Q#
Assessment Question
Score 0 · 1 · 2
Notes / Evidence
Priority
6.1
A written AI governance policy or charter has been adopted and approved by leadership.
6.2
Roles and responsibilities are clearly assigned: who owns the program, who owns the data, who owns privacy, and who sponsors it at the executive level.
6.3
AI governance is reported to executive leadership or the board on a regular cycle.
6.4
Staff who develop, deploy, or manage AI systems have received relevant training within the last 12 months.
6.5
A scheduled process exists to review and update AI governance policies as regulations and technology change.
AI Governance Readiness Results
—
Where You Stand
Your Weakest Domain
Get your full report
You have your maturity level and your weakest domain. The full report shows every domain scored, the specific remediation actions behind each gap, your flagged priorities, and a recommended engagement path.
All six domains scored with gap severity
Specific remediation actions per domain, not just a score
Your flagged priority items compiled into one list
Maturity ladder showing what the next level requires
Printable report for your governance file
JHarris Advisory LLC provides consulting services, not legal services. It is not a law firm, and submitting this form does not create an attorney-client relationship. Your assessment answers and notes stay in your browser; only what you type above is sent. Do not enter confidential or personal data anywhere on this page.
Build this into your AI governance program
This assessment shows you where the gaps are. The AI Governance Starter Bundle gives you the policy templates, use case intake forms, risk tiering rubric, and vendor review checklists to start closing them.