This is an example report using representative data. Your actual score will be different.
Your report · Completed 29 Apr 2026
Example Organisation · Standard track · EU-27 · ID demo · 29 Apr 2026
Overall maturity
2.4 /5.0
L2 · EmergingYou are emerging — approaching the threshold for sustainable AI governance. Three high-leverage actions get you to Defined.
Dimensions at/above L3
1/8
Questions answered
16/16
Regulatory gaps
11
Actions queued
8
WHERE YOU'RE EXPOSED
You're exposed in these areas. 11 regulatory gaps · 8 prioritised actions.
Your AI literacy programme and cultural foundations represent a genuine compliance strength under Art. 4.
Your vendor risk management shows supply-chain awareness that goes beyond the average for your peer group.
Run a full shadow-AI census. Target L3 in 4–6 weeks.
Classify all AI against Annex III. Target L3 in 6–8 weeks.
AI incident response playbook. Target L3 in 3–5 weeks.
Calibrated to current resourcing. Reorder, defer, or assign.
Phase 1 — 0–3 months
| Phase | Action | Detail | Effort | Owner |
|---|---|---|---|---|
| P1 | Deploy AI and SaaS discovery tooling | Implement automated discovery via SSO logs, browser extension, or network monitoring to identify all AI tools in use. | Medium | IT Director / CISO |
| P1 | Classify all AI systems by EU AI Act risk tier | Review each AI system against Annex III categories. Document classification decisions. Prioritise high-risk systems for Art. 9 risk management. | Medium | DPO / Legal |
| P1 | Document an AI incident response playbook | Define escalation paths, notification timelines (NIS2: 24h early warning; DORA: 4h initial notification), and responsible parties. | Medium | CISO |
Phase 2 — 3–6 months
| Phase | Action | Detail | Effort | Owner |
|---|---|---|---|---|
| P2 | Formalise the AI governance policy | Establish a formal, board-endorsed AI governance policy with a named accountable owner and cross-functional authority. | Low | CEO / Board |
| P2 | Update RoPA to include all AI processing activities | Add all AI data processing to your Art. 30 record. Include data sources, transfer mechanisms, retention periods, and legal basis. | Low | DPO |
Phase 3 — 6–12 months · Sustain & optimise
| Phase | Action | Detail | Effort | Owner |
|---|---|---|---|---|
| P3 | Sustain AI literacy programme with refresher training✓ At target | Annual refresher modules for all staff. Track completion rates. | Low | HR / L&D |