AI Agents & AutomationFree Interactive Tool

AI Governance Maturity Assessment: Score Your Controls Before an Auditor Does

This free AI governance maturity assessment scores your organization across the ten controls that regulators, auditors, and enterprise customers now ask about. It is built for CIOs, compliance leaders, and risk officers at manufacturers and defense contractors where AI is spreading faster than the policy covering it. Ten questions examine policy, system inventory, use case approval, risk tiering, data handling enforcement, vendor diligence, output evaluation, incident response, regulatory alignment, and executive reporting. You get a percentage score, a maturity band, and five prioritized recommendations. The most common finding is not weak policy but policy with no enforcement mechanism behind it.

0 of 10 answered0%

1. Do you have a written, approved AI use policy?

2. Do you maintain an inventory of AI systems in use across the business?

Shadow AI usage through personal accounts is the most commonly missed category in a first inventory.

3. Is there an approval process before a new AI use case goes live?

4. Do you classify AI use cases by risk level?

Risk tiering lets you apply proportionate controls instead of blocking everything or nothing.

5. Are there enforced rules about what data may be sent to AI systems?

6. How do you conduct due diligence on AI vendors and models?

7. Is AI output quality evaluated before release and monitored afterwards?

8. Are AI incidents defined, reportable, and rehearsed?

An AI incident includes wrong output that caused a business decision, not only a security breach.

9. How well aligned are you to applicable regulation and standards?

Consider NIST AI RMF, ISO 42001, EU AI Act obligations, and sector rules such as ITAR, EAR, or CMMC.

10. Does leadership receive regular reporting on AI risk and value?

How maturity is scored

Each question offers four options worth zero to three points across ten questions, giving a maximum of thirty. The percentage places you in one of four bands: ungoverned below 40%, emerging from 40 to 64%, managed from 65 to 84%, and optimized at 85% and above. Questions are weighted equally on purpose. In practice the binding constraint is rarely the sophistication of your best control; it is the weakest link that an auditor or an incident finds first. An organization with an excellent policy and no system inventory has no idea what its policy applies to, which is functionally the same as having no policy.

The frameworks these questions map to

The ten controls are drawn from the frameworks that enterprise buyers, auditors, and regulators actually reference, translated into plain questions you can answer without a compliance dictionary open beside you. If you need formal mapping for a customer questionnaire or an internal audit, each area corresponds to recognizable control families in the published standards below.

  • NIST AI Risk Management Framework: the govern, map, measure, and manage functions underpin questions one through eight.
  • ISO/IEC 42001: AI management system requirements align to policy, inventory, and leadership reporting.
  • EU AI Act: risk classification and post-market monitoring obligations map to the tiering and monitoring questions.
  • CMMC, ITAR, and EAR: data handling enforcement and vendor residency diligence carry extra weight for defense suppliers.

Interpreting your band without over-correcting

The failure mode at low maturity is exposure; the failure mode at high maturity is friction. If you score in the lower bands, resist the instinct to ban AI outright, because blanket bans reliably push usage into personal accounts where you have no visibility at all. Publish a clear rule about what data may never leave the boundary, provide a sanctioned tool that is genuinely good, and make the approved path the easy path. If you score in the upper bands, start measuring how long your own approval process takes. A governance program that adds six weeks to every low-risk request will be routed around, and you will be back to shadow AI with better paperwork.

How Netray builds governance that survives contact with delivery

Netray implements AI governance for manufacturers and defense contractors as part of delivering working systems, not as a separate documentation exercise. We build the inventory, define proportionate risk tiers, and wire enforcement into the platform so data classification rules are technical controls rather than reminders. For clients under ITAR, EAR, or CMMC, we deploy models on-prem or air-gapped so the governance question about data residency has a simple structural answer. We also automate evidence collection from the platform itself, which means your next audit draws on logs your systems already produce instead of a scramble for screenshots.

Frequently Asked Questions

Where should an organization with no AI governance start?

Start with discovery, not policy. Spend two weeks finding what AI is already in use, including personal accounts and features quietly embedded in software you already own. Almost every organization is surprised. Then publish one short readable rule about what data may never be entered into external tools, and provide a sanctioned alternative that is actually good. Inventory plus a usable sanctioned path removes more risk in a month than a comprehensive policy document does in a year.

Does the EU AI Act apply to a US manufacturer?

It can. The obligations follow where the output is used, so a US manufacturer whose AI-assisted products or services reach the EU market may fall in scope, as may one supplying an EU customer who is in scope. The practical response is the same either way: classify your use cases by risk, document the high-risk ones, and keep post-market monitoring records. That work also satisfies most of NIST AI RMF and ISO 42001, so it is rarely wasted effort.

How is governing AI agents different from governing chatbots?

Agents take actions, so governance must cover consequences rather than just content. That means action-level authorization, spend and quantity limits, human confirmation for high-impact operations, and audit logs tying every tool call to an initiating user. Risk tiering also needs an extra dimension: a low-risk topic becomes high risk the moment the system can write to your ERP. Most governance frameworks written for generative text need explicit extension before they cover agentic deployments.

Get an evidenced AI governance gap analysis from Netray, mapped to the frameworks your customers and auditors actually cite.