Assessment Methodology
Transparent, rule-based scoring with full auditability.
Governance dimensions
The assessment evaluates nine dimensions aligned with established expectations for responsible AI: accountability, human oversight, data governance, fairness, transparency, security, risk management, lifecycle management, and accountability to affected people.
Scoring approach
Each question is scored on a maturity scale from not implemented (0) to fully implemented (4). Not applicable responses are excluded from category calculations. Category scores are normalized to a 0 to 100 scale and combined using fixed weights totaling 100 percent.
Readiness levels
- 0 to 39: Initial. Fundamental controls require attention.
- 40 to 59: Developing. Material gaps remain.
- 60 to 74: Established. Core practices in place.
- 75 to 89: Advanced. Mature practices with limited gaps.
- 90 to 100: Leading. Highly developed governance capability.
Readiness and system risk
Governance readiness measures organizational preparedness. AI system risk reflects the potential consequence of the system based on its data use and impact profile. These are reported separately. A mature organization may still operate a high-risk AI system.
Risk matrix
Identified risks are plotted on a 5 by 5 matrix using likelihood and impact ratings. Risk score equals likelihood multiplied by impact. Scores of 1 to 4 are low, 5 to 9 moderate, 10 to 16 high, and 17 to 25 critical.
Limitations
Results are based on self-reported responses and do not certify compliance, safety, or legal approval. All outputs should be validated by qualified professionals. Numerical scores are calculated by deterministic rules, not by a language model.