Governance & ethics
The risk framework, EU AI Act readiness, model oversight processes, and ethical guardrails in place.
What we ask
The four questions in this dimension, with the four ordinal options and their fixed scores. Identical wording to what you will see in the assessment.
1. Have you classified your AI use cases against the EU AI Act risk categories?
Categories: prohibited, high-risk, limited-risk (transparency obligations), minimal. Classification is a regulatory requirement from August 2026 for high-risk systems.
| Option | Response | Score |
|---|---|---|
| a | All AI uses inventoried and classified; reviewed quarterly | 100 |
| b | Major systems classified; long-tail tools not yet | 67 |
| c | Aware of categories; classification not done | 33 |
| d | Not familiar with the EU AI Act risk framework | 0 |
2. Do your AI systems disclose to users when they are interacting with AI?
EU AI Act Article 50 requires this for chatbots, content generation, and similar interactions from August 2026.
| Option | Response | Score |
|---|---|---|
| a | Yes — clear, persistent disclosure across all AI interactions | 100 |
| b | Disclosed in major systems; smaller tools inconsistent | 67 |
| c | Discussed; not yet implemented | 33 |
| d | No disclosure | 0 |
3. How are AI model decisions logged for audit purposes?
For high-risk AI under EU AI Act, automatic logging of events is mandatory (Article 12). Even for non-high-risk, audit trails are best practice.
| Option | Response | Score |
|---|---|---|
| a | Automatic logging with retention policy and tamper-evident storage | 100 |
| b | Logged in critical systems; ad-hoc elsewhere | 67 |
| c | Some logging, no retention or audit policy | 33 |
| d | No model decision logging | 0 |
4. Do you have a documented process to challenge or override an AI-driven decision?
For decisions affecting people (employment, credit, access to services), human-in-the-loop with explicit override authority is required.
| Option | Response | Score |
|---|---|---|
| a | Documented override process with named owner, SLA, and audit log | 100 |
| b | Override possible but not formally documented | 67 |
| c | Theoretically yes; never tested | 33 |
| d | No override mechanism | 0 |
Ready to see your full score?
Take the full assessment to see your score across all six dimensions, your peer benchmark, and your three highest-leverage moves.
Take the assessment →