Enterprise AI Governance Self-Assessment

Ten domains regulators and boards expect you to govern. Answer honestly — takes 2 minutes. EU AI Act transparency obligations begin August 2, 2026.

01Data Governance

Do you know what data feeds each AI system, who owns it, and where it came from?

02Model Validation

Are models tested against benchmarks and formally approved before deployment?

03Bias & Fairness

Do you test AI outputs for unfair, discriminatory, or unbalanced outcomes?

04Human Oversight

Do high-impact AI decisions require human review, with escalation and override paths?

05Regulatory Compliance

Have you mapped each AI use case to the laws that govern it (EU AI Act, GDPR, industry rules)?

06Security Controls

Are prompts and outputs protected against injection, data leakage, and misuse?

07Vendor Risk

Do you assess third-party AI tools and models, and can you switch providers without rewrites?

08Audit Logging

If an auditor asked what your AI did last quarter, could you produce the record today?

09Model & Cost Monitoring

Do you track model performance drift AND monthly AI spend per workload?

10Incident Response

Is there a playbook for when AI fails, leaks data, or behaves unexpectedly?