World Model Readiness
Engraved governance instrument

For your company

Governance & Compliance

Module · Five questions on who really draws the line

The Governance Deep-Dive

The core assessment asks whether a governance owner exists. This module asks whether governance actually operates: five questions about the machinery behind the boundary between what AI decides and what a human still decides.

Question 1 of 5 · Decision inventory exists

Do you have a written inventory of the decisions AI systems influence today?

Not the systems: the decisions. Pricing overrides, lead routing, credit flags, content takedowns. If nobody can produce the list, the boundary layer is being drawn implicitly, one deployment at a time.

Question 2 of 5 · Veto exercised in practice

Has your governance owner actually blocked or reversed an AI-driven decision in the last year?

A veto that has never fired is a hypothesis, not a control. The first real block tells you whether the authority holds when it costs somebody a deadline.

Question 3 of 5 · Escalation path is named

When an AI output is wrong, does everyone know exactly where it goes?

Not a ticket queue: a named path from the person who spots the error to someone with authority to change the system, with a feedback loop back to the reporter.

Question 4 of 5 · Boundaries reviewed on schedule

Are the AI-decides versus human-decides boundaries revisited on a fixed schedule?

Boundaries set once fossilise. The system earns scope (or loses it) as evidence accumulates; without a review cadence, yesterday's caution and yesterday's recklessness both persist unexamined.

Question 5 of 5 · Incidents feed back

Are AI misfires recorded and fed back into how the system is governed?

Every organisation has AI near-misses. The question is whether they end as anecdotes in hallway conversations or as entries that change a threshold, a boundary, or a training set.

For the statistics · one click each

Three questions for the public picture

These do not affect your score. They feed the anonymised, aggregated statistics; groups under 8 respondents are never shown.

Does your company have a written AI policy?

No policy
In draft
Published, not enforced
Published and enforced

Has an AI-driven decision already caused damage in your company?

Not that we know of
A near-miss, caught in time
Yes, minor damage
Yes, significant damage

How far along is your EU AI Act preparation?

Not started
Assessing exposure
Use cases classified
Controls implemented
Outside EU scope

Your context

Used to calibrate the report. Company size and sector remain in the anonymized dataset; your email does not.

What the five levels look like

Every dimension in this assessment is scored 1 to 5. This is what the levels mean, dimension by dimension. The graded report diagnoses where your own answers land and what to do about it.

Decision inventory exists

  1. 1No list anywhere
  2. 2In heads only
  3. 3Partial, outdated
  4. 4Written, mostly current
  5. 5Living inventory, owned

At the low end: Without an inventory, every new AI feature draws the boundary silently. Start the list this week; it is a document, not a project. What good looks like: A living inventory is the rarest governance asset we see. Keep it tied to deployment reviews so it cannot age.

Veto exercised in practice

  1. 1No veto exists
  2. 2Exists, never used
  3. 3Used once, contested
  4. 4Used, held up
  5. 5Routine and respected

At the low end: An unexercised veto is untested equipment. Run a deliberate drill: pick one live AI decision and have the owner walk the block path end to end. What good looks like: A veto that holds under delivery pressure is real governance. Document the precedents; they are training data for your organisation.

Escalation path is named

  1. 1Nowhere to report
  2. 2Generic ticket queue
  3. 3Path exists, unknown
  4. 4Known, sometimes used
  5. 5Known, used, closed-loop

At the low end: Errors that have nowhere to go become silent precedents. Publish one address (a person, not a queue) and route everything through it for a quarter. What good looks like: A closed-loop escalation path is what turns individual errors into system improvements. Track the loop time; it is your governance latency.

Boundaries reviewed on schedule

  1. 1Never revisited
  2. 2Ad hoc after incidents
  3. 3Annual review
  4. 4Quarterly review
  5. 5Quarterly + evidence-based

At the low end: Unreviewed boundaries drift into folklore. Put one recurring hour per quarter in the calendar of whoever owns the veto; that is the entire cost. What good looks like: Scheduled, evidence-based boundary reviews are how the system earns scope safely. Publish the review outcomes internally; it builds trust in the programme.

Incidents feed back

  1. 1Not recorded
  2. 2Anecdotes only
  3. 3Logged, not reviewed
  4. 4Logged and reviewed
  5. 5Reviewed and acted on

At the low end: Unrecorded misfires repeat. Start the cheapest possible log: date, decision, what went wrong, one sentence. Volume matters more than form. What good looks like: A working incident loop means the governance layer learns as fast as the model does. This is the property that keeps year two from eroding.