AI Governance Gap & Risk Assessment Template

AIMA-02Toolkit ArtefactPresentation-readyLinked to Chapter 01

A working diagnostic template for scoping an organization's AI risk exposure across the six AIMA business-function layers, producing a risk heat map and a sequenced remediation roadmap. Pair this with AIMA-01 for the scoring model it's built on.

Step 1 — Score Current Maturity by Layer

For each of the six layers, score current maturity 1–5 using the AIMA levels. Score against evidence, not intent — a documented policy nobody follows scores as Ad hoc, not Defined.

1 — Ad hoc

No consistent process. Activities are reactive and undocumented.

2 — Defined

Processes are documented and repeatable across the organization.

3 — Managed

Processes are actively managed, measured, and controlled.

4 — Measured

Quantitative metrics drive continuous improvement decisions.

5 — Optimized

Best-in-class, continuously evolving and benchmarked externally.

The Six AIMA Business-Function Layers

Each layer represents a distinct domain of AI governance accountability. All six must be scored independently to produce a complete risk picture.

Governance & Oversight

Board-level accountability, AI policy frameworks, and executive ownership of AI risk.

Risk Management

Identification, assessment, and treatment of AI-specific risks across the enterprise.

Data Management

Data quality, lineage, privacy controls, and governance for AI training and inference.

Model Development & Validation

Model lifecycle controls, bias testing, validation gates, and documentation standards.

Deployment & Monitoring

Production controls, drift detection, incident response, and performance monitoring.

Third-Party & Vendor AI

Due diligence, contractual controls, and ongoing oversight of external AI providers.

Step 2 — Score Target Maturity by Layer

For each layer, set a target score based on regulatory exposure and business criticality. Target scores are not aspirational maximums — they are calibrated minimums based on the risk profile of each layer.

High-Risk Layers

A layer touching high-risk EU AI Act use cases should target at least Managed (3). These are layers where regulatory non-compliance carries material legal and reputational consequences.

  • Governance & Oversight
  • Third-Party & Vendor AI
  • Model Development & Validation

Lower-Risk Layers

A layer touching only internal productivity tools may reasonably target Defined (2). Over-engineering governance for low-risk applications wastes resources and creates compliance fatigue.

  • Risk Management (internal tools)
  • Deployment & Monitoring (low-stakes)
  • Data Management (non-sensitive)

Step 3 — Build the Gap & Risk Heat Map

Gap = target score minus current score, per layer. Plot each layer on a heat map: gap size on one axis, business impact (regulatory exposure, data sensitivity, decision consequence) on the other. Layers landing in the high-gap, high-impact quadrant are the priority.

Heat Map: Gap vs. Business Impact

Visualizing gap size against business impact reveals which layers demand immediate remediation investment. The upper-right quadrant — high gap, high impact — is where governance failures become regulatory and reputational events.

Layers in the upper-right quadrant — Governance & Oversight and Third-Party & Vendor AI — carry both the largest gaps and the highest regulatory exposure, making them the unambiguous starting point for remediation.

Step 4 — Sequence the Remediation Roadmap

Sequence remediation by priority score, not by ease of implementation — the temptation is always to fix the easy gaps first. For each priority layer, define four elements that will govern the remediation effort.

1

Specific Control or Process

Define the exact control, policy, or process change that will close the identified gap. Vague remediation actions produce vague results.

2

Owner

Assign a named individual — not a team or department — who is accountable for delivering the remediation by the target date.

3

Target Quarter

Set a specific quarter for completion. Open-ended timelines are the primary reason remediation roadmaps stall after the first review cycle.

4

Evidence of New Maturity

Define in advance what evidence will demonstrate the new maturity level once implemented — audit logs, test results, approved policies, or third-party attestations.

Remediation Roadmap: Sequencing by Priority

The roadmap below illustrates how priority-sequenced remediation translates into a phased delivery plan. Each phase builds governance infrastructure that subsequent phases depend on.

1

Q1 — Priority 1

Governance & Oversight
Establish AI governance committee, assign executive AI owner, publish AI policy framework. Evidence: Board-approved AI policy document.

2

Q1–Q2 — Priority 2

Third-Party & Vendor AI
Deploy vendor AI due diligence questionnaire, update procurement contracts with AI clauses. Evidence: Completed vendor assessments on file.

3

Q2 — Priority 3

Data Management
Implement data lineage tracking for AI training sets, complete data sensitivity classification. Evidence: Data inventory with lineage records.

4

Q2–Q3 — Priority 4

Model Development & Validation
Introduce formal model validation gates and bias testing checkpoints. Evidence: Validation reports for all production models.

5

Q3 — Priority 5 & 6

Deployment & Monitoring + Risk Management
Deploy model drift monitoring dashboards and integrate AI risk into enterprise risk register. Evidence: Live monitoring dashboards and updated risk register.

Step 5 — Re-Score on a Fixed Cadence

Re-run this assessment on a fixed cadence — quarterly for high-priority layers, semi-annually for the rest — rather than only after an incident or audit finding prompts it. Maturity that isn't re-measured tends to be assumed rather than known.

Quarterly Re-Assessment

Apply to all layers currently rated as high priority — those in the high-gap, high-impact quadrant. Quarterly cadence ensures remediation actions are delivering measurable maturity improvement and allows course correction before the next audit cycle.

  • Governance & Oversight
  • Third-Party & Vendor AI

Semi-Annual Re-Assessment

Apply to all remaining layers once they have exited the high-priority quadrant. Semi-annual cadence maintains visibility without creating assessment fatigue for teams managing lower-risk domains.

  • Data Management
  • Model Development & Validation
  • Deployment & Monitoring
  • Risk Management

Notes on Using This with AIMA-03

If you're not confident your current-state scores reflect reality, run the AIMA-03 question bank first — it's designed to surface the evidence gaps a self-reported score usually hides before you commit numbers to this template.

The Problem with Self-Reported Scores

Self-reported maturity scores are systematically optimistic. Teams score against intent and documentation rather than against operational evidence. AIMA-03 is specifically designed to challenge this bias by requiring respondents to cite specific evidence for each score claimed.

What AIMA-03 Surfaces

The AIMA-03 question bank surfaces evidence gaps — the delta between what an organization believes its maturity level is and what the documentary and operational record actually supports. Running AIMA-03 before completing this template produces more defensible scores and a more accurate heat map.

Recommended Sequencing

Run AIMA-03 → complete this template with evidence-backed scores → produce the heat map → sequence the remediation roadmap. Skipping AIMA-03 is acceptable for a first-pass diagnostic, but scores should be treated as provisional until validated against the question bank.

AIMA-01

Scoring model foundation — defines the 1–5 maturity levels this template is built on.

AIMA-02

This template — gap assessment, heat map, and remediation roadmap.

AIMA-03

Question bank — evidence validation before committing scores to AIMA-02.