JHarris Advisory LLC · JHA-AIGOV-BD-03 · Pairs with JHA-BRF-10-01
AI Governance Readiness Self-Assessment
Score each item 0 = Not in place · 1 = Partially implemented · 2 = Fully implemented
0
/ 56
0
20
35
46
52
56
No score yet
Complete the assessment below
Organization Information
Assessment ContextDomain 1 · Use Case Intake & Inventory
Q#
Assessment Question
Score 0 · 1 · 2
Notes / Evidence
Priority
1.1
The organization maintains a formal process to identify and document all AI/ML use cases before deployment.
1.2
Intake forms or equivalent documentation capture the use case purpose, data inputs, intended outputs, and affected populations.
1.3
AI use cases are logged in a centralized inventory that is reviewed and updated at least quarterly.
1.4
Shadow AI or unapproved tools are identified through discovery processes (e.g., vendor reviews, employee surveys).
1.5
Business owners are assigned and accountable for each active AI use case in the inventory.
Domain 2 · Risk Tiering & Classification
Q#
Assessment Question
Score 0 · 1 · 2
Notes / Evidence
Priority
2.1
A documented risk tiering rubric assigns High, Medium, or Low risk classifications to AI use cases based on defined criteria.
2.2
Risk tier assignment considers: data sensitivity, consequential decision-making, regulatory exposure, and human oversight level.
2.3
High-risk use cases require additional review, documentation, or approval before deployment.
2.4
Risk tier classifications are reviewed and updated when material changes occur (new data, new outputs, new affected populations).
2.5
Risk classification decisions are documented with rationale and retained for audit purposes.
Domain 3 · Controls & Oversight
Q#
Assessment Question
Score 0 · 1 · 2
Notes / Evidence
Priority
3.1
Required controls are mapped to each AI use case based on its risk tier.
3.2
Human review or override mechanisms are available for consequential AI-assisted decisions.
3.3
Access to AI tools and outputs is restricted to authorized personnel with defined roles.
3.4
Audit logging is enabled for material AI decisions, and logs are retained per policy.
3.5
AI systems are integrated with the organization's incident response procedures for AI-related failures.
Domain 4 · AI Vendor Risk Management
Q#
Assessment Question
Score 0 · 1 · 2
Notes / Evidence
Priority
4.1
Vendor or third-party AI tools are subject to formal intake and risk review before deployment.
4.2
Contracts with AI vendors include provisions addressing data use, model transparency, and liability allocation.
4.3
AI vendor risk reviews occur at least annually, or upon material changes to the vendor's model or data practices.
4.4
A vendor AI portfolio list is maintained and reviewed as part of AI governance reporting.
Domain 5 · Regulatory Posture & Compliance
Q#
Assessment Question
Score 0 · 1 · 2
Notes / Evidence
Priority
5.1
The organization has identified which AI regulations and frameworks apply based on its industry, geography, and AI use cases.
5.2
A regulatory obligation calendar tracks key deadlines, required disclosures, and compliance milestones.
5.3
Required disclosures or consumer notices related to AI/automated decision-making are in place where applicable.
5.4
Legal counsel or qualified advisors are engaged on AI regulatory compliance at least annually.
Domain 6 · Governance Structure & Accountability
Q#
Assessment Question
Score 0 · 1 · 2
Notes / Evidence
Priority
6.1
A written AI governance policy or charter has been adopted and approved by leadership.
6.2
Roles and responsibilities for AI governance are clearly defined (e.g., AI Lead, Data Steward, Privacy Officer, Executive Sponsor).
6.3
AI governance is reported to executive leadership or the board on a regular cycle (quarterly or annually).
6.4
Staff who develop, deploy, or manage AI systems have received relevant training within the last 12 months.
6.5
A formal process exists to review and update AI governance policies as regulations and technology evolve.
Assessment Results
Complete scoring aboveD1 · Intake & Inventory
0/ 10
D2 · Risk Tiering
0/ 10
D3 · Controls & Oversight
0/ 10
D4 · Vendor Risk
0/ 8
D5 · Regulatory Posture
0/ 8
D6 · Governance Structure
0/ 10
| Score Range | Maturity Level | JHA Recommendation |
|---|---|---|
| 0 – 20 | Ad Hoc / Unmanaged | Immediate engagement recommended. Foundational program build required across all domains. |
| 21 – 35 | Developing | Significant gaps exist. Targeted remediation and policy development needed within 90 days. |
| 36 – 46 | Defined | Core framework in place. Focus on consistency, controls completion, and governance reporting. |
| 47 – 52 | Managed | Strong program. Optimize vendor risk, regulatory tracking, and board-level reporting cadence. |
| 53 – 56 | Optimized | Mature program. Focus on continuous improvement, model audits, and regulatory horizon scanning. |
⚑ Priority Action Items
No priority items flagged yet. Check the "Flag" box on any question to add it here.
Signatures
Completed By
Reviewed By (JHA Consultant)
Assessment complete — see your engagement plan and service recommendations
Build this into your AI governance program
This assessment shows you where the gaps are. The AI Governance Starter Bundle gives you the policy templates, use-case intake forms, risk-tiering rubric, and vendor review checklists to start closing them.