The AI Governance Gut Check

A C-Level View

If you’re reading this, some part of you already senses your AI governance isn’t quite where it should be. That’s not a red flag — it’s the normal state for almost every organization moving at this pace. This tool won’t tell you that you’re failing. It’ll tell you specifically where the gaps are, so you know exactly what to fix first, instead of carrying a vague unease about it.

This is a fast way to find out which of the eight you actually have — versus which ones you assume you have because they sound like things a mature organization would do.


1. Documentation

Can you produce, right now, a model card, decision log, data lineage record, and approval trail for every AI system currently in production — not reconstructed from memory, but already written down?

If the honest answer involves someone saying “give me a week to pull that together,” you don’t have this. You have the intention to have it.


2. An embedded partner

Is there a named person with real governance/risk expertise sitting inside each product team, with standing in product meetings — not a shared function teams file a ticket to?

If risk/security only shows up when invited to a review, that’s a shared function, not an embedded one. Different thing.


3. Reusable templates

When a new team needs a risk assessment or a vendor questionnaire, do they pull from an existing library — or does someone start from a blank page?

If every team’s governance documents look different in structure and depth, there’s no shared template. There’s tribal knowledge.


4. Shared tooling and vendor risk

Do you know, for every third-party model or LLM currently wired into a workflow, exactly what data reaches it and where that data goes after?

If the answer is “the vendor has a security page, I assume it’s fine,” that’s not a risk assessment. That’s trust without verification.


5. Design-stage review

Is security and governance in the room before the system is built — or do they see it for the first time at a pre-launch review, when the architecture is already locked in?

If the first governance conversation happens close to launch, it’s a checkpoint, not a design partner. The expensive mistakes were already made by then.


6. Demos, not just documents

Has anyone outside the build team actually watched the system run — live, unscripted — in the last quarter? Or has the model card been the only thing anyone’s reviewed?

Paper compliance and a working system are not the same claim. If nobody’s seen it work, nobody’s actually validated it.


7. Decision rights

If product, risk, legal, and engineering disagree on an AI decision, is there a known place and cadence where that gets resolved — or does it get argued over email until someone senior gets tired of it?

If escalation is “whoever emails loudest gets an answer eventually,” there’s no real decision-rights structure, regardless of what the org chart says.


8. AI-specific literacy

If your risk or security partner sat in on a design review tomorrow, would they actually recognize a prompt injection risk, a data poisoning vector, or an adversarial manipulation attempt — or would they be reviewing it with a pre-AI security lens?

If the honest answer is “I’m not sure,” that’s not a hiring gap alone — it’s a training gap, and it’s not the risk partner’s job to close by themselves. Security and governance are shared responsibility across the whole product team, not something outsourced to one specialist while everyone else stays uninvolved.


Reading your results

  • 6–8 real yeses: you’re ahead of most organizations moving at this pace — the priority now is spreading this consistently across every product team, not just the ones that happen to have a strong lead.
  • 3–5 real yeses: you have the instinct, not yet the operating model. Start with documentation, an embedded partner, and the design-stage review — those three cost the least and unlock the rest.
  • 0–2 real yeses: the ambition to adopt AI is ahead of the ability to govern it. That gap is exactly where the expensive mistakes happen — not from bad intentions, from missing structure.

Regulatory guidance in most jurisdictions is still catching up to AI-specific risk. That’s not a reason to wait — it’s the reason the bar has to come from inside the organization first, because no one else has set it yet.

Wherever you landed, the point isn’t the score — it’s knowing which of these eight is real in your organization today, versus assumed.