NewNew: The enterprise guide to Agentic AI — 24 min read.

Read →
Advisory assessment · 5 minutes

Would your AI estate survive an audit next quarter?

Six control areas drawn from NIST AI RMF, EU AI Act expectations and established model risk practice — scored, banded and turned into the first three fixes.

Score each dimension

Answer as your organisation operates today, not as it is described in a strategy deck. Scores update the result live.

01 · AI inventory

Is there a complete, current inventory of AI systems including embedded vendor features?

1 = no inventory · 5 = live inventory with owners, risk tier and purpose

02 · Model risk & validation

Are models validated independently before deployment, with documented limitations?

1 = the build team self-certifies · 5 = independent validation with documented limits and sign-off

03 · Data privacy & provenance

Do you know what data trains and grounds each system, and is its use lawful and documented?

1 = provenance unclear · 5 = documented lineage, lawful basis and retention per system

04 · Third-party & vendor risk

Are AI vendors assessed for data use, subprocessors, model changes and exit?

1 = standard software due diligence only · 5 = AI-specific due diligence with change notification and exit plan

05 · Monitoring & drift

Are accuracy, bias and drift monitored in production against defined thresholds?

1 = no production monitoring · 5 = threshold-based monitoring with automatic alerting

06 · Incident response

Is there a tested playbook for AI failures, harmful output and rollback?

1 = no AI-specific playbook · 5 = tested playbook with rollback and regulator notification paths

AI governance readiness
60/ 100
Controlled

Core controls operate. Close the gaps in vendor AI risk and incident rehearsal before scaling higher-risk use cases.

AI inventory3/5
Model risk & validation3/5
Data privacy & provenance3/5
Third-party & vendor risk3/5
Monitoring & drift3/5
Incident response3/5
Review this with an advisor →

Weighted average 3.00 of 5. Scores stay in the page link and the PDF — nothing is stored and no email is required.

Your prioritised next 90 days

Generated from your three weakest weighted dimensions.

  1. 01
    AI inventory — scored 3/5

    Stand up a single AI inventory covering in-house models, embedded vendor AI and shadow usage, with a named owner and risk tier per entry.

  2. 02
    Model risk & validation — scored 3/5

    Introduce independent validation gates proportionate to risk tier, with documented intended use, limitations and rejection criteria.

  3. 03
    Data privacy & provenance — scored 3/5

    Document training and retrieval data lineage per system, confirm lawful basis and retention, and block unapproved data from grounding pipelines.

Inventory, validation, monitoring and incident response carry higher weight because they are the controls examiners test first. Directional self-assessment only — not legal advice.

Common questions

Which frameworks does this reflect?
The dimensions map to NIST AI RMF functions and the documentation, monitoring and human-oversight expectations of the EU AI Act, plus the model risk practices regulated firms already run under SR 11-7.
Is this a compliance certification?
No. It is a directional self-assessment to help leaders find the weakest control before an auditor or regulator does. It does not constitute legal advice.
Who typically runs it?
Risk, compliance and security leaders together with the AI platform owner. Scoring separately and comparing answers usually surfaces the real gaps faster than a joint session.