Answered before you apply, not after

Common questions

What the diagnostic is, what it is not, and what happens with what you tell us.

What is an AI governance readiness diagnostic?

A structured 30-minute assessment of how AI is currently controlled in your organisation. It covers ten governance domains — ownership, inventory, access, approval, agent autonomy, risk classification, security and privacy, monitoring and audit, policy, and third-party AI — and produces a readiness score plus your three highest-priority gaps.

Do I need to prepare anything beforehand?

No. There is no questionnaire to complete and no documentation to gather. The session works from a conversation about what you actually have running. Bringing someone who knows how the tools are used day to day helps, but is not required.

Which frameworks does the assessment map to?

ISO/IEC 42001 and the NIST AI Risk Management Framework, with reference to ASEAN and regional AI-governance guidance and emerging practice for agentic AI. Mapping the output to recognised frameworks means it can be reused in board papers, audit responses and certification planning.

Is this an audit or a certification?

No. It is a diagnostic, intended to show you where you stand and what to fix first. It is guidance only — not legal advice, regulatory certification or ISO certification — and it does not replace a formal audit or a certification body.

Why is it free, and what is the catch?

Sessions are free while the framework is being validated with organisations adopting enterprise AI. Places are limited and each application is reviewed individually, so we can keep the sessions focused on organisations already running AI in production.

What happens to the information we share?

Application details are used only to review fit and arrange the session. Nothing discussed is published or attributed, and the examples shown on this site are composites, not client quotes.

Who should attend from our side?

One or two people is ideal. Someone accountable for the AI programme or for risk, plus someone who knows how the tools are used in practice. More than three tends to slow the session down without improving the result.

What do we actually receive afterwards?

A readiness score across the domains assessed, your three priority gaps ranked by exposure, and a practical action plan for each — not a hundred-page policy document.

Something not covered here? Mention it in the application and we’ll answer before the session.

Still the fastest way to find out

Thirty minutes will tell you more than another round of internal questions.