Fifteen questions across six dimensions. No email required. You will get an honest picture of where your organisation stands - and what to tackle first.
We help organisations build AI governance that holds up under scrutiny - not just on paper. A conversation costs nothing and takes thirty minutes.
AI governance maturity is not about having a policy. It is about whether the controls your organisation has in place actually reflect how AI is being used – and whether they would hold up under scrutiny from a board, a regulator, or a significant customer.
This scorecard assesses six dimensions that together determine whether AI governance is operational or theoretical: visibility of what AI tools are in use and what data they process; policy and the approval process around new tool adoption; supplier governance and data handling terms; accountability structures and board oversight; monitoring and review cadence; and incident readiness.
Each dimension is scored independently so you can see where the real gaps are rather than receiving a single number that tells you little.
This tool is designed for IT leaders, security professionals, compliance and risk functions, and senior management teams who are responsible for how their organisation adopts and governs AI. It does not require technical knowledge of AI systems – it assesses governance structures, not technical capability.
It is particularly relevant for organisations operating in regulated sectors, those with significant enterprise or public sector customers who are beginning to ask governance questions, and any organisation that has started using AI tools without a formal programme in place to govern that usage.
Enterprise customers are beginning to include AI governance requirements in procurement processes. Regulators across financial services, healthcare, and professional services are incorporating AI oversight into their supervision frameworks. Insurers are asking what controls are in place around AI usage as part of underwriting conversations. The external pressure for demonstrable AI governance is increasing and the organisations that build it ahead of that pressure will be better positioned than those that build it in response to it.
The most significant risks most organisations face from AI are not from sophisticated attacks on AI systems. They are from data reaching suppliers under terms that were never reviewed, from staff using tools without adequate guidance, from governance structures that exist on paper and are bypassed in practice, and from the inability to answer basic questions about AI usage when those questions arrive.
Our AI governance maturity tooling helps identify opportunities to improve
Tools are in use, data is reaching AI systems, and nobody has a complete picture of either. There is no inventory, no policy, no supplier oversight, and no named accountability. Most organisations are at this level without knowing it.
Policies have been written and something exists in a shared drive. But the documents do not reflect how people actually work, the approval process is too slow to be used, and nobody is actively maintaining any of it. Paper governance provides false assurance rather than actual protection.
Controls are in place and broadly operational. The organisation can demonstrate its AI governance with evidence, not just describe it. Gaps are known, tracked, and being addressed. When a regulator, insurer, or enterprise customer asks the question, there is a real answer.
Most organisations currently sit at Level 1 or Level 2. Level 1 represents the absence of meaningful governance – tools are in use, data is reaching AI systems, but there is no inventory, no policy, no accountability, and no supplier oversight in place. Level 2 is where documentation exists but operational governance does not: policies have been written, but they do not reflect how people actually work and are not followed in any meaningful sense.
Level 3 represents functioning, managed governance – controls are in place and broadly operational, but gaps remain in monitoring, supplier oversight, or incident preparedness. Level 4 is defensible governance: the organisation can demonstrate its AI controls with evidence, not just describe them.
Black Chili is an independent security architecture and AI assurance consultancy. We help UK organisations understand their actual AI exposure, build governance that functions operationally rather than just existing on paper, and maintain the independent oversight that keeps governance current as the AI landscape evolves.
Our AI Assurance services include structured AI Exposure Reviews, AI Governance and Guardrails Design, Continuous AI Assurance, and AI Incident Review. If you want to talk through your scorecard results or understand what governance work would look like for your organisation, get in touch.
We can help improve your AI Security.