Professional working with digital systems in an office

AI Governance Health Check.

A practical 15-question assessment for governance, controls, and readiness.
Understand how EU AI Act obligations may still affect UK organisations with EU-facing activity.
No sign-up required. Complete in around 30 minutes.

Measure your AI governance maturity before scaling further

This health check surfaces practical gaps in model controls, policy, auditability, and deployment readiness. You receive an immediate score and category-level view so you can prioritise remediation.

15 Questions

Coverage across visibility, compliance, control, readiness, and infrastructure.

No Sign-Up

Self-serve assessment with no gated download and no required sales call.

Actionable Output

Receive a score band and category breakdown to guide practical next steps.

0 of 15 answered

V

AI Usage & Visibility

How well do you understand what AI tools your team is actually using?

Do you have a complete inventory of all AI tools currently in use across your organisation?

High impact

Are staff using personal ChatGPT, Claude, or Gemini accounts for work tasks?

High impact

Can you produce an audit trail of every AI-generated output used in client work?

Medium impact

DC

Data & Compliance

Is sensitive client data protected when AI tools process it?

Where does your client data go when processed by AI tools?

High impact

Do you have a formal AI usage policy that staff have read and acknowledged?

High impact

Can you demonstrate to your regulator that AI outputs are reviewed by a human before affecting decisions?

Medium impact

GC

Governance & Control

Who controls AI model access, and can you enforce policies consistently?

Can you control which AI models different teams are allowed to use?

High impact

If your primary AI vendor changed terms or pricing tomorrow, how quickly could you switch?

High impact

Do you have an approval workflow for deploying new AI tools or models?

Medium impact

EU

EU AI Act Readiness

How prepared are you if your business develops for, sells to, or supports AI use in EU contexts?

Have you assessed whether EU AI Act obligations may apply to your organisation through EU-facing products, clients, or usage?

High impact

If an EU client, auditor, or regulator requested evidence tomorrow, could you produce your AI governance framework quickly?

High impact

Have you mapped which use cases could be considered high-risk under the EU AI Act when used in EU settings?

Medium impact

DI

Deployment & Infrastructure

Can you deploy AI where your data and regulatory constraints require?

Can you deploy AI tools on infrastructure you fully control (private cloud or on-premises)?

High impact

How many separate AI tool subscriptions is your organisation currently paying for?

Medium impact

Do you have monitoring in place for AI model performance, cost, and unexpected outputs?

High impact

Answer all 15 questions to view your results.

0/100 Calculating

Result pending

Why this matters now

The EU AI Act does not become UK domestic law automatically, but it can still affect UK companies through EU-facing activity. Strong governance is also good operational practice regardless of jurisdiction.

EU-facing exposure is time-bound

UK organisations with EU-facing AI products, services, or outputs should assess potential scope and evidence expectations early.

Shadow AI already exists

Without inventory and controls, data can flow into unmanaged tools with no review trail.

Governance maturity compounds

Teams that establish policy and controls early scale safer and faster with fewer rework cycles.

This creates a practical baseline

Your score provides a starting point for a concrete remediation plan by category.

Turn your score into a remediation plan

We can map your results to practical next steps: governance controls, policy improvements, and deployment approach based on your risk profile.