ASSESSMENT

AI & Data Governance

16 questions  ·  ~5 minutes

A 16-question diagnostic covering data governance, AI model governance, privacy & compliance, responsible AI, third-party AI risk, and EU AI Act readiness. Produces a scored report with prioritised recommendations and a pre-implementation checklist.

Progress0 of 16 answered
Save your progress

Governance Structure

1There is a named data owner or data governance lead who is accountable for data policy, standards, and compliance across the organisation.

2We have a documented data governance framework - covering data ownership, classification, quality standards, and acceptable use - that is actively reviewed and enforced.

Data Quality & Lineage

3Data quality is defined, measured, and reported regularly - we know how complete, accurate, and timely our critical datasets are.

4We can trace the origin, transformation, and movement of our critical datasets - data lineage is documented and kept current.

Data Privacy & Compliance

5We have a documented and enforced data retention and deletion policy - personal data is removed or anonymised when it reaches the end of its retention window.

6Privacy Impact Assessments (PIAs or DPIAs) are conducted before new AI initiatives, data products, or significant changes to how personal data is processed.

AI Model Governance

7AI models go through a documented review and approval process before deployment - covering purpose, training data, performance benchmarks, known limitations, and a named accountable owner.

8AI models in production are continuously monitored for performance degradation, output drift, and business outcome metrics - with clear triggers for retraining or decommissioning.

Responsible AI & Ethics

9We have published AI ethics principles or a responsible AI policy that guides how AI is developed, procured, deployed, and monitored across the organisation.

10AI models are assessed for bias before deployment, and where AI decisions affect individuals, we have explainability mechanisms so that outcomes can be understood, audited, and challenged.

Third-Party & Vendor AI Risk

11We maintain an inventory of third-party suppliers that embed AI in products or services affecting our data or operations, and we assess them against our governance standards before onboarding.

12Our contracts with AI vendors include provisions for transparency, audit rights, data handling obligations, and the right to exit if the system causes harm or regulatory non-compliance.

Training Data Management

13Training datasets are documented - including source, date range, known gaps or biases, and preparation steps - and this documentation is maintained whenever datasets are updated.

14All data used to train or fine-tune AI models has a documented legal basis - consent, licensing, or legitimate interest - and this is reviewed whenever the training dataset changes.

High-Risk AI Compliance (EU AI Act)

15We have assessed whether any AI systems we develop or deploy fall under the EU AI Act's high-risk or general-purpose AI categories, and have documented this classification with justification. Select 'Not applicable' if your organisation does not develop or deploy AI systems.

16For any high-risk AI systems, we have implemented the required EU AI Act controls: technical documentation, conformity assessment, human oversight measures, transparency obligations, and registration with the relevant authority. Select 'Not applicable' if you have no high-risk AI systems.

Overall comments

Add any overall notes or context about your responses.

You can submit with unanswered questions - they will be counted as gaps.