AI Governance
Readiness Assessment.
Score your organization against the SafeSpace AI Governance Assessment Model: eight domains, control-level maturity, and one weighted AI Governance Score out of 100.
The eight domains
- Shadow AI18%
- Policy Enforcement18%
- Privacy15%
- Transparency14%
- Security13%
- Governance10%
- Human Adoption6%
- Agent Readiness6%
Choose from one of two assessments below — a light Quick Scan for a fast indicative score, or a full-weight assessment for a complete, evidence-ready governance review.
Quick Scan
16 controls · ~5 minutes
One or two controls per domain. An indicative AI Governance Score you can produce in a single sitting, without gathering evidence first.
Full Assessment
44 controls · ~20 minutes
Every control in the model, across all eight domains, with per-domain confidence ratings. The version to run with your security, privacy, and compliance leads.
A preview of the report you’ll receive.
Below is a fully rendered Full Assessment for a fictional mid-size EU financial services firm — Meridian Trust Financial (~1,400 employees · EU financial services · fictional). Your own report uses the same structure, populated from your actual answers. Both sample PDFs below are built from the same organisation, so you can compare what each mode delivers.
AI Governance Score
33 / 100
Higher is better
Maturity band
Emerging
Awareness exists and some controls are being drafted, but coverage is thin and enforcement still depends on individual behaviour rather than technical controls.
Priority domain · Shadow AI
Each domain is the average maturity of its controls, expressed as a percentage of the 0–5 scale. Higher is better. Confidence reflects the evidence quality implied by your answers.
One tailored next step per governance domain, weakest first. Directional guidance only — see the disclaimer under “How is this scored?”.
- 01
Shadow AI
10/100·Ad-hocUnmanaged AI usage is happening faster than you can see it. Shadow AI Discovery builds a complete inventory of AI tools in use — including personal-account and direct API usage — within 48 hours, and keeps rediscovering continuously.
Shadow AI Discovery - 02
Agent Readiness
13/100·Ad-hocAutonomous agents will inherit every gap above and act on them at machine speed. Register agents with distinct identities, scope their permissions and time-bound them, and require human approval for consequential actions before agent use scales.
Agent Governance - 03
Policy Enforcement
20/100·Ad-hocPolicy exists on paper but is not enforced at the network layer. A self-hosted tokenization proxy inspects outbound prompts and applies allow/deny, redaction, and tokenization rules before anything reaches an external model.
Tokenization Proxy - 04
Transparency
37/100·EmergingYou cannot currently show what AI is in use, by whom, or produce Article 50 disclosure evidence. A hash-chained audit log records every AI interaction automatically and turns transparency into a queryable record.
Audit Log - 05
Human Adoption
40/100·EmergingEmployees are adopting AI faster than the organization is teaching them how to do it safely. Deliver role-appropriate AI awareness training and give staff an approved tool for each common use case — bans without alternatives drive usage underground.
- 06
Privacy
48/100·DefinedPersonal and confidential data is likely leaving through AI prompts, which conventional DLP does not inspect. Stateless tokenization replaces PII, source code, and contract content with reversible tokens before the prompt leaves your tenant.
Tokenization Proxy - 07
Security
50/100·DefinedAI systems are not yet protected to the standard of the rest of your estate. Prioritise MFA on every AI workspace, centrally issued and rotated API credentials, and tamper-evident logging of AI interactions.
Audit Log - 08
Governance
60/100·DefinedGovernance structures are working. Tie them to evidence: link policy statements to the enforcement and audit records that prove they are being applied.
Audit Log
Tools or vendors considered
Currently evaluating a mix of native data-loss prevention controls and third-party AI gateway proxies. Piloted an enterprise assistant with a small team; no organisation-wide decision yet.
Approaches selected
- Middle security layer
- Blocking all AI tools and providing our own LLM
The full record of what was assessed. Your own report includes the same section, populated from your responses.
- 01TR-001AI Inventory
Does the organization maintain a centralized, current inventory of every AI system and tool in use?
Partially implemented — some coverage, inconsistent2/5 - 02TR-002AI Inventory
Is a named business owner assigned and recorded for each AI system in use?
Operational — documented and running in production3/5 - 03TR-004Usage Visibility
Can you report on who is using which AI tools, how often, and for what purpose?
Initial awareness — recognised, nothing in place yet1/5 - 04TR-006Usage Visibility
Do executives receive regular reporting on enterprise AI adoption and associated risk?
Partially implemented — some coverage, inconsistent2/5 - 05TR-009Explainability
Can you trace an individual AI interaction — prompt, model, and data used — after the fact?
Initial awareness — recognised, nothing in place yet1/5 - 06TR-011Explainability
Do AI systems that interact with people disclose that they are AI, as EU AI Act Article 50 requires?
Partially implemented — some coverage, inconsistent2/5 - 07SEC-001Identity Security
Is multi-factor authentication enforced for every corporate AI platform and workspace?
Managed and measured — monitored with defined owners4/5 - 08SEC-004API Security
Are AI API keys and service credentials centrally issued, rotated, and scoped to least privilege?
Operational — documented and running in production3/5 - 09SEC-007Access Control
Is access to AI systems granted by role, reviewed periodically, and revoked on leaver events?
Operational — documented and running in production3/5 - 10SEC-009Infrastructure Security
Do you have controls that detect or block prompt injection and model-abuse attempts?
Initial awareness — recognised, nothing in place yet1/5 - 11SEC-012Monitoring
Are AI interactions logged in a tamper-evident way and retained for audit purposes?
Partially implemented — some coverage, inconsistent2/5 - 12SEC-015Incident Response
Does your incident response plan explicitly cover AI and Shadow AI related incidents?
Partially implemented — some coverage, inconsistent2/5 - 13PRI-001Data Classification
Can you detect when personal or confidential data is sent to an AI system?
Partially implemented — some coverage, inconsistent2/5 - 14PRI-004Regulatory Compliance
Are GDPR obligations — lawful basis, DPIAs, data subject rights — applied to AI processing?
Managed and measured — monitored with defined owners4/5 - 15PRI-006Data Protection
Do you control and evidence where data processed by AI systems is stored and processed?
Operational — documented and running in production3/5 - 16PRI-009Privacy Governance
Are retention and deletion rules defined and enforced for AI prompts, outputs, and logs?
Partially implemented — some coverage, inconsistent2/5 - 17PRI-011Data Protection
Are source code, contracts, and strategic documents protected from being pasted into external AI tools?
Initial awareness — recognised, nothing in place yet1/5 - 18GOV-001Leadership
Is there a named executive accountable for AI governance across the organization?
Managed and measured — monitored with defined owners4/5 - 19GOV-003Leadership
Does a cross-functional AI governance committee meet on a defined cadence?
Operational — documented and running in production3/5 - 20GOV-007Policy Management
Is there an enterprise AI usage policy that is documented, communicated, and kept current?
Operational — documented and running in production3/5 - 21GOV-011Risk Management
Are AI-related risks captured in a risk register with owners and mitigation plans?
Partially implemented — some coverage, inconsistent2/5 - 22GOV-018Third-party Governance
Do AI vendors and models go through a formal approval and due-diligence process before use?
Operational — documented and running in production3/5 - 23HUM-001AI Literacy
Do employees receive AI awareness training covering safe and unsafe use of AI tools?
Operational — documented and running in production3/5 - 24HUM-004Responsible AI
Are staff in higher-risk roles required to complete responsible-AI training or certification?
Initial awareness — recognised, nothing in place yet1/5 - 25HUM-007Business Adoption
Is AI adoption tracked by department, with approved tools offered for common use cases?
Partially implemented — some coverage, inconsistent2/5 - 26HUM-010Change Management
Is there a channel for employees to request AI tools or report AI-related concerns?
Partially implemented — some coverage, inconsistent2/5 - 27SHA-001Discovery
Can you discover AI tools accessed from managed browsers and endpoints across the organization?
Initial awareness — recognised, nothing in place yet1/5 - 28SHA-003Risk Identification
Are unauthorized AI platforms identified and risk-rated when they appear on the network?
Initial awareness — recognised, nothing in place yet1/5 - 29SHA-007Usage Monitoring
Do you know what share of AI usage happens through personal, unmanaged accounts?
Don't know - 30SHA-010Discovery
Can you detect direct AI API usage from applications, scripts, or developer tooling?
Not implemented0/5 - 31SHA-013Sensitive Prompt Detection
Can you detect prompts that contain sensitive or regulated data before they leave your network?
Initial awareness — recognised, nothing in place yet1/5 - 32SHA-016Usage Monitoring
Is Shadow AI discovery continuous, rather than a one-off exercise?
Not implemented0/5 - 33POL-001Identity Enforcement
Are approved and blocked AI tools enforced technically, not just documented in policy?
Partially implemented — some coverage, inconsistent2/5 - 34POL-004Content Protection
Are outbound AI prompts inspected against policy before reaching an external model?
Initial awareness — recognised, nothing in place yet1/5 - 35POL-006Content Protection
Is sensitive data tokenized or pseudonymized before it is sent to an AI model?
Not implemented0/5 - 36POL-008Content Protection
Is personal or confidential content redacted automatically when policy requires it?
Initial awareness — recognised, nothing in place yet1/5 - 37POL-010Monitoring
Does your DLP tooling cover conversational AI traffic, not only email and file transfer?
Partially implemented — some coverage, inconsistent2/5 - 38POL-013Remediation
When a policy violation occurs in AI usage, is remediation automated rather than manual?
Not implemented0/5 - 39AGT-001Agent Identity
Are AI agents and autonomous workflows registered with a distinct identity before deployment?
Initial awareness — recognised, nothing in place yet1/5 - 40AGT-003Human Oversight
Do consequential agent actions require documented human approval?
Partially implemented — some coverage, inconsistent2/5 - 41AGT-006Delegated Authority
Are agent permissions scoped and time-bound rather than inherited from a human account?
Initial awareness — recognised, nothing in place yet1/5 - 42AGT-010Agent Monitoring
Is there a complete audit trail of actions taken by AI agents on your systems?
Not implemented0/5 - 43AGT-014Lifecycle Management
Are agent memory and stored context governed, reviewed, and purged under defined rules?
Not implemented0/5 - 44AGT-018Multi-Agent Governance
Are the same policies enforced when agents call other agents or external tools?
Not implemented0/5
This is a sample using fictional data. Your own report will be generated from your actual answers when you complete the assessment.