A working diagnostic template for scoping an organization's AI risk exposure across the six AIMA business-function layers, producing a risk heat map and a sequenced remediation roadmap. Pair this with AIMA-01 for the scoring model it's built on.
For each of the six layers, score current maturity 1–5 using the AIMA levels. Score against evidence, not intent — a documented policy nobody follows scores as Ad hoc, not Defined.
No consistent process. Activities are reactive and undocumented.
Processes are documented and repeatable across the organization.
Processes are actively managed, measured, and controlled.
Quantitative metrics drive continuous improvement decisions.
Best-in-class, continuously evolving and benchmarked externally.
Each layer represents a distinct domain of AI governance accountability. All six must be scored independently to produce a complete risk picture.
Board-level accountability, AI policy frameworks, and executive ownership of AI risk.
Identification, assessment, and treatment of AI-specific risks across the enterprise.
Data quality, lineage, privacy controls, and governance for AI training and inference.
Model lifecycle controls, bias testing, validation gates, and documentation standards.
Production controls, drift detection, incident response, and performance monitoring.
Due diligence, contractual controls, and ongoing oversight of external AI providers.
For each layer, set a target score based on regulatory exposure and business criticality. Target scores are not aspirational maximums — they are calibrated minimums based on the risk profile of each layer.
A layer touching high-risk EU AI Act use cases should target at least Managed (3). These are layers where regulatory non-compliance carries material legal and reputational consequences.
A layer touching only internal productivity tools may reasonably target Defined (2). Over-engineering governance for low-risk applications wastes resources and creates compliance fatigue.
Gap = target score minus current score, per layer. Plot each layer on a heat map: gap size on one axis, business impact (regulatory exposure, data sensitivity, decision consequence) on the other. Layers landing in the high-gap, high-impact quadrant are the priority.
Visualizing gap size against business impact reveals which layers demand immediate remediation investment. The upper-right quadrant — high gap, high impact — is where governance failures become regulatory and reputational events.

Layers in the upper-right quadrant — Governance & Oversight and Third-Party & Vendor AI — carry both the largest gaps and the highest regulatory exposure, making them the unambiguous starting point for remediation.
Sequence remediation by priority score, not by ease of implementation — the temptation is always to fix the easy gaps first. For each priority layer, define four elements that will govern the remediation effort.
Define the exact control, policy, or process change that will close the identified gap. Vague remediation actions produce vague results.
Assign a named individual — not a team or department — who is accountable for delivering the remediation by the target date.
Set a specific quarter for completion. Open-ended timelines are the primary reason remediation roadmaps stall after the first review cycle.
Define in advance what evidence will demonstrate the new maturity level once implemented — audit logs, test results, approved policies, or third-party attestations.
The roadmap below illustrates how priority-sequenced remediation translates into a phased delivery plan. Each phase builds governance infrastructure that subsequent phases depend on.
Governance & Oversight
Establish AI governance committee, assign executive AI owner, publish AI policy framework. Evidence: Board-approved AI policy document.
Third-Party & Vendor AI
Deploy vendor AI due diligence questionnaire, update procurement contracts with AI clauses. Evidence: Completed vendor assessments on file.
Data Management
Implement data lineage tracking for AI training sets, complete data sensitivity classification. Evidence: Data inventory with lineage records.
Model Development & Validation
Introduce formal model validation gates and bias testing checkpoints. Evidence: Validation reports for all production models.
Deployment & Monitoring + Risk Management
Deploy model drift monitoring dashboards and integrate AI risk into enterprise risk register. Evidence: Live monitoring dashboards and updated risk register.
Re-run this assessment on a fixed cadence — quarterly for high-priority layers, semi-annually for the rest — rather than only after an incident or audit finding prompts it. Maturity that isn't re-measured tends to be assumed rather than known.
Apply to all layers currently rated as high priority — those in the high-gap, high-impact quadrant. Quarterly cadence ensures remediation actions are delivering measurable maturity improvement and allows course correction before the next audit cycle.
Apply to all remaining layers once they have exited the high-priority quadrant. Semi-annual cadence maintains visibility without creating assessment fatigue for teams managing lower-risk domains.
If you're not confident your current-state scores reflect reality, run the AIMA-03 question bank first — it's designed to surface the evidence gaps a self-reported score usually hides before you commit numbers to this template.
Self-reported maturity scores are systematically optimistic. Teams score against intent and documentation rather than against operational evidence. AIMA-03 is specifically designed to challenge this bias by requiring respondents to cite specific evidence for each score claimed.
The AIMA-03 question bank surfaces evidence gaps — the delta between what an organization believes its maturity level is and what the documentary and operational record actually supports. Running AIMA-03 before completing this template produces more defensible scores and a more accurate heat map.
Run AIMA-03 → complete this template with evidence-backed scores → produce the heat map → sequence the remediation roadmap. Skipping AIMA-03 is acceptable for a first-pass diagnostic, but scores should be treated as provisional until validated against the question bank.
Scoring model foundation — defines the 1–5 maturity levels this template is built on.
This template — gap assessment, heat map, and remediation roadmap.
Question bank — evidence validation before committing scores to AIMA-02.
AI Governance Gap & Risk Assessment Template