
For your company
Governance & Compliance
Module · Five questions on who really draws the line
The Governance Deep-Dive
The core assessment asks whether a governance owner exists. This module asks whether governance actually operates: five questions about the machinery behind the boundary between what AI decides and what a human still decides.
What the five levels look like
Every dimension in this assessment is scored 1 to 5. This is what the levels mean, dimension by dimension. The graded report diagnoses where your own answers land and what to do about it.
Decision inventory exists
- 1No list anywhere
- 2In heads only
- 3Partial, outdated
- 4Written, mostly current
- 5Living inventory, owned
At the low end: Without an inventory, every new AI feature draws the boundary silently. Start the list this week; it is a document, not a project. What good looks like: A living inventory is the rarest governance asset we see. Keep it tied to deployment reviews so it cannot age.
Veto exercised in practice
- 1No veto exists
- 2Exists, never used
- 3Used once, contested
- 4Used, held up
- 5Routine and respected
At the low end: An unexercised veto is untested equipment. Run a deliberate drill: pick one live AI decision and have the owner walk the block path end to end. What good looks like: A veto that holds under delivery pressure is real governance. Document the precedents; they are training data for your organisation.
Escalation path is named
- 1Nowhere to report
- 2Generic ticket queue
- 3Path exists, unknown
- 4Known, sometimes used
- 5Known, used, closed-loop
At the low end: Errors that have nowhere to go become silent precedents. Publish one address (a person, not a queue) and route everything through it for a quarter. What good looks like: A closed-loop escalation path is what turns individual errors into system improvements. Track the loop time; it is your governance latency.
Boundaries reviewed on schedule
- 1Never revisited
- 2Ad hoc after incidents
- 3Annual review
- 4Quarterly review
- 5Quarterly + evidence-based
At the low end: Unreviewed boundaries drift into folklore. Put one recurring hour per quarter in the calendar of whoever owns the veto; that is the entire cost. What good looks like: Scheduled, evidence-based boundary reviews are how the system earns scope safely. Publish the review outcomes internally; it builds trust in the programme.
Incidents feed back
- 1Not recorded
- 2Anecdotes only
- 3Logged, not reviewed
- 4Logged and reviewed
- 5Reviewed and acted on
At the low end: Unrecorded misfires repeat. Start the cheapest possible log: date, decision, what went wrong, one sentence. Volume matters more than form. What good looks like: A working incident loop means the governance layer learns as fast as the model does. This is the property that keeps year two from eroding.