AI Governance Assessment

AI Governance
Readiness Assessment.

Score your organization against the SafeSpace AI Governance Assessment Model: eight domains, control-level maturity, and one weighted AI Governance Score out of 100.

The eight domains

  • Shadow AI18%
  • Policy Enforcement18%
  • Privacy15%
  • Transparency14%
  • Security13%
  • Governance10%
  • Human Adoption6%
  • Agent Readiness6%

Choose from one of two assessments below — a light Quick Scan for a fast indicative score, or a full-weight assessment for a complete, evidence-ready governance review.

Quick Scan

16 controls · ~5 minutes

One or two controls per domain. An indicative AI Governance Score you can produce in a single sitting, without gathering evidence first.

Full Assessment

44 controls · ~20 minutes

Every control in the model, across all eight domains, with per-domain confidence ratings. The version to run with your security, privacy, and compliance leads.

See the platform instead
Sample Report— Illustrative example, fictional company
What your report looks like

A preview of the report you’ll receive.

Below is a fully rendered Full Assessment for a fictional mid-size EU financial services firm — Meridian Trust Financial (~1,400 employees · EU financial services · fictional). Your own report uses the same structure, populated from your actual answers. Both sample PDFs below are built from the same organisation, so you can compare what each mode delivers.

Sample result

AI Governance Score

33 / 100

Higher is better

Maturity band

Emerging

Awareness exists and some controls are being drafted, but coverage is thin and enforcement still depends on individual behaviour rather than technical controls.

Priority domain · Shadow AI

Domain maturity

Each domain is the average maturity of its controls, expressed as a percentage of the 0–5 scale. Higher is better. Confidence reflects the evidence quality implied by your answers.

Shadow AISHA · 18% weightpriority domain10·0.5/5·Low confidence
Policy EnforcementPOL · 18% weight20·1/5·Low confidence
PrivacyPRI · 15% weight48·2.4/5·Medium confidence
TransparencyTR · 14% weight37·1.8/5·Low confidence
SecuritySEC · 13% weight50·2.5/5·Medium confidence
GovernanceGOV · 10% weight60·3/5·Medium confidence
Human AdoptionHUM · 6% weight40·2/5·Medium confidence
Agent ReadinessAGT · 6% weight13·0.7/5·Low confidence
Recommended actions

One tailored next step per governance domain, weakest first. Directional guidance only — see the disclaimer under “How is this scored?”.

  1. 01

    Shadow AI

    10/100·Ad-hoc

    Unmanaged AI usage is happening faster than you can see it. Shadow AI Discovery builds a complete inventory of AI tools in use — including personal-account and direct API usage — within 48 hours, and keeps rediscovering continuously.

    Shadow AI Discovery
  2. 02

    Agent Readiness

    13/100·Ad-hoc

    Autonomous agents will inherit every gap above and act on them at machine speed. Register agents with distinct identities, scope their permissions and time-bound them, and require human approval for consequential actions before agent use scales.

    Agent Governance
  3. 03

    Policy Enforcement

    20/100·Ad-hoc

    Policy exists on paper but is not enforced at the network layer. A self-hosted tokenization proxy inspects outbound prompts and applies allow/deny, redaction, and tokenization rules before anything reaches an external model.

    Tokenization Proxy
  4. 04

    Transparency

    37/100·Emerging

    You cannot currently show what AI is in use, by whom, or produce Article 50 disclosure evidence. A hash-chained audit log records every AI interaction automatically and turns transparency into a queryable record.

    Audit Log
  5. 05

    Human Adoption

    40/100·Emerging

    Employees are adopting AI faster than the organization is teaching them how to do it safely. Deliver role-appropriate AI awareness training and give staff an approved tool for each common use case — bans without alternatives drive usage underground.

  6. 06

    Privacy

    48/100·Defined

    Personal and confidential data is likely leaving through AI prompts, which conventional DLP does not inspect. Stateless tokenization replaces PII, source code, and contract content with reversible tokens before the prompt leaves your tenant.

    Tokenization Proxy
  7. 07

    Security

    50/100·Defined

    AI systems are not yet protected to the standard of the rest of your estate. Prioritise MFA on every AI workspace, centrally issued and rotated API credentials, and tamper-evident logging of AI interactions.

    Audit Log
  8. 08

    Governance

    60/100·Defined

    Governance structures are working. Tie them to evidence: link policy statements to the enforcement and audit records that prove they are being applied.

    Audit Log
Your approach

Tools or vendors considered

Currently evaluating a mix of native data-loss prevention controls and third-party AI gateway proxies. Piloted an enterprise assistant with a small team; no organisation-wide decision yet.

Approaches selected

  • Middle security layer
  • Blocking all AI tools and providing our own LLM
Your answers

The full record of what was assessed. Your own report includes the same section, populated from your responses.

  1. 01
    TR-001
    AI Inventory

    Does the organization maintain a centralized, current inventory of every AI system and tool in use?

    Partially implemented — some coverage, inconsistent2/5
  2. 02
    TR-002
    AI Inventory

    Is a named business owner assigned and recorded for each AI system in use?

    Operational — documented and running in production3/5
  3. 03
    TR-004
    Usage Visibility

    Can you report on who is using which AI tools, how often, and for what purpose?

    Initial awareness — recognised, nothing in place yet1/5
  4. 04
    TR-006
    Usage Visibility

    Do executives receive regular reporting on enterprise AI adoption and associated risk?

    Partially implemented — some coverage, inconsistent2/5
  5. 05
    TR-009
    Explainability

    Can you trace an individual AI interaction — prompt, model, and data used — after the fact?

    Initial awareness — recognised, nothing in place yet1/5
  6. 06
    TR-011
    Explainability

    Do AI systems that interact with people disclose that they are AI, as EU AI Act Article 50 requires?

    Partially implemented — some coverage, inconsistent2/5
  7. 07
    SEC-001
    Identity Security

    Is multi-factor authentication enforced for every corporate AI platform and workspace?

    Managed and measured — monitored with defined owners4/5
  8. 08
    SEC-004
    API Security

    Are AI API keys and service credentials centrally issued, rotated, and scoped to least privilege?

    Operational — documented and running in production3/5
  9. 09
    SEC-007
    Access Control

    Is access to AI systems granted by role, reviewed periodically, and revoked on leaver events?

    Operational — documented and running in production3/5
  10. 10
    SEC-009
    Infrastructure Security

    Do you have controls that detect or block prompt injection and model-abuse attempts?

    Initial awareness — recognised, nothing in place yet1/5
  11. 11
    SEC-012
    Monitoring

    Are AI interactions logged in a tamper-evident way and retained for audit purposes?

    Partially implemented — some coverage, inconsistent2/5
  12. 12
    SEC-015
    Incident Response

    Does your incident response plan explicitly cover AI and Shadow AI related incidents?

    Partially implemented — some coverage, inconsistent2/5
  13. 13
    PRI-001
    Data Classification

    Can you detect when personal or confidential data is sent to an AI system?

    Partially implemented — some coverage, inconsistent2/5
  14. 14
    PRI-004
    Regulatory Compliance

    Are GDPR obligations — lawful basis, DPIAs, data subject rights — applied to AI processing?

    Managed and measured — monitored with defined owners4/5
  15. 15
    PRI-006
    Data Protection

    Do you control and evidence where data processed by AI systems is stored and processed?

    Operational — documented and running in production3/5
  16. 16
    PRI-009
    Privacy Governance

    Are retention and deletion rules defined and enforced for AI prompts, outputs, and logs?

    Partially implemented — some coverage, inconsistent2/5
  17. 17
    PRI-011
    Data Protection

    Are source code, contracts, and strategic documents protected from being pasted into external AI tools?

    Initial awareness — recognised, nothing in place yet1/5
  18. 18
    GOV-001
    Leadership

    Is there a named executive accountable for AI governance across the organization?

    Managed and measured — monitored with defined owners4/5
  19. 19
    GOV-003
    Leadership

    Does a cross-functional AI governance committee meet on a defined cadence?

    Operational — documented and running in production3/5
  20. 20
    GOV-007
    Policy Management

    Is there an enterprise AI usage policy that is documented, communicated, and kept current?

    Operational — documented and running in production3/5
  21. 21
    GOV-011
    Risk Management

    Are AI-related risks captured in a risk register with owners and mitigation plans?

    Partially implemented — some coverage, inconsistent2/5
  22. 22
    GOV-018
    Third-party Governance

    Do AI vendors and models go through a formal approval and due-diligence process before use?

    Operational — documented and running in production3/5
  23. 23
    HUM-001
    AI Literacy

    Do employees receive AI awareness training covering safe and unsafe use of AI tools?

    Operational — documented and running in production3/5
  24. 24
    HUM-004
    Responsible AI

    Are staff in higher-risk roles required to complete responsible-AI training or certification?

    Initial awareness — recognised, nothing in place yet1/5
  25. 25
    HUM-007
    Business Adoption

    Is AI adoption tracked by department, with approved tools offered for common use cases?

    Partially implemented — some coverage, inconsistent2/5
  26. 26
    HUM-010
    Change Management

    Is there a channel for employees to request AI tools or report AI-related concerns?

    Partially implemented — some coverage, inconsistent2/5
  27. 27
    SHA-001
    Discovery

    Can you discover AI tools accessed from managed browsers and endpoints across the organization?

    Initial awareness — recognised, nothing in place yet1/5
  28. 28
    SHA-003
    Risk Identification

    Are unauthorized AI platforms identified and risk-rated when they appear on the network?

    Initial awareness — recognised, nothing in place yet1/5
  29. 29
    SHA-007
    Usage Monitoring

    Do you know what share of AI usage happens through personal, unmanaged accounts?

    Don't know
  30. 30
    SHA-010
    Discovery

    Can you detect direct AI API usage from applications, scripts, or developer tooling?

    Not implemented0/5
  31. 31
    SHA-013
    Sensitive Prompt Detection

    Can you detect prompts that contain sensitive or regulated data before they leave your network?

    Initial awareness — recognised, nothing in place yet1/5
  32. 32
    SHA-016
    Usage Monitoring

    Is Shadow AI discovery continuous, rather than a one-off exercise?

    Not implemented0/5
  33. 33
    POL-001
    Identity Enforcement

    Are approved and blocked AI tools enforced technically, not just documented in policy?

    Partially implemented — some coverage, inconsistent2/5
  34. 34
    POL-004
    Content Protection

    Are outbound AI prompts inspected against policy before reaching an external model?

    Initial awareness — recognised, nothing in place yet1/5
  35. 35
    POL-006
    Content Protection

    Is sensitive data tokenized or pseudonymized before it is sent to an AI model?

    Not implemented0/5
  36. 36
    POL-008
    Content Protection

    Is personal or confidential content redacted automatically when policy requires it?

    Initial awareness — recognised, nothing in place yet1/5
  37. 37
    POL-010
    Monitoring

    Does your DLP tooling cover conversational AI traffic, not only email and file transfer?

    Partially implemented — some coverage, inconsistent2/5
  38. 38
    POL-013
    Remediation

    When a policy violation occurs in AI usage, is remediation automated rather than manual?

    Not implemented0/5
  39. 39
    AGT-001
    Agent Identity

    Are AI agents and autonomous workflows registered with a distinct identity before deployment?

    Initial awareness — recognised, nothing in place yet1/5
  40. 40
    AGT-003
    Human Oversight

    Do consequential agent actions require documented human approval?

    Partially implemented — some coverage, inconsistent2/5
  41. 41
    AGT-006
    Delegated Authority

    Are agent permissions scoped and time-bound rather than inherited from a human account?

    Initial awareness — recognised, nothing in place yet1/5
  42. 42
    AGT-010
    Agent Monitoring

    Is there a complete audit trail of actions taken by AI agents on your systems?

    Not implemented0/5
  43. 43
    AGT-014
    Lifecycle Management

    Are agent memory and stored context governed, reviewed, and purged under defined rules?

    Not implemented0/5
  44. 44
    AGT-018
    Multi-Agent Governance

    Are the same policies enforced when agents call other agents or external tools?

    Not implemented0/5

This is a sample using fictional data. Your own report will be generated from your actual answers when you complete the assessment.