Ten questions. Six dimensions. An instant picture of what your AI governance is missing - and what to address first.
Select an answer to continue
We help organisations identify and close AI governance gaps before they become incidents, audit findings, or lost contracts.
Most organisations that have started thinking about AI governance have made progress in some areas and left others untouched. The difficulty is knowing which is which. Self-assessment is unreliable – the gaps that matter most are often the ones that feel least urgent until they surface in an audit, an incident, or a conversation with a customer who has started asking governance questions.
This assessment maps your governance position across six dimensions: visibility of what AI tools are in use and what data they process; policy and the approval process around new tool adoption; supplier governance and data handling terms; accountability structures and board oversight; monitoring and review cadence; and incident readiness.
Each dimension is scored independently so you can see where the real gaps are rather than receiving a single number that obscures them.
This tool is designed for IT leaders, security and risk professionals, compliance functions, and senior management teams responsible for how their organisation uses and governs AI. It does not require technical knowledge of AI systems.
It is particularly relevant for organisations that have taken some governance steps but are uncertain whether they have covered the right ground, those facing procurement questions about AI governance from enterprise or public sector customers, and those that have experienced an AI-related issue and want to understand what governance gaps allowed it to happen.
The AI Governance Maturity Scorecard asks how mature your overall governance programme is. This assessment asks something more specific: what is missing, and where. The two tools are designed to work together – the scorecard gives you the overall picture, the gap assessment tells you where to focus first.
Our AI Gap Assessment tooling identifies common gaps in AI adoption, in the following categories.
Visibility addresses whether the organisation has an accurate, current picture of what AI tools are in use – including tools adopted informally by staff, AI features embedded in existing platforms, and supplier-side AI processing. It is the foundation on which all other governance depends.
Supplier governance examines whether the data handling and retention terms of AI tool suppliers have been reviewed, whether data processing agreements are in place where required, and whether supplier term changes are monitored.
Policy and governance covers whether the rules around AI usage reflect how people actually work, and whether the process for getting new tools approved is fast and clear enough to be used rather than bypassed.
Accountability addresses whether there is named, active ownership of AI governance and whether leadership receives reliable, evidenced reporting on governance rather than broad assurance.
Monitoring and review covers whether the governance programme is reviewed on a defined cadence against current operational reality, or whether it was built once and left.
Incident readiness examines whether the organisation has a specific, owned AI incident response capability – including an understanding of the regulatory notification timelines that apply when personal data is involved.
Identifying gaps in your AI adoption and governance is the first step to the secure use of AI technologies.
Black Chili is an independent security architecture and AI assurance consultancy. We help UK organisations understand their actual AI governance position, close the gaps that matter, and build the independent oversight that keeps governance current as AI usage evolves.
If your results have surfaced gaps you want to address, or if you want an independent assessment of your governance position rather than a self-assessment, get in touch at blackchili.co.uk/contact