Demo Assessment, sample organisation showing the full results experience
Sample company:
Simoda
17out of 100
At Risk

AI Governance Score

Section Breakdown

Governance17/100

Strategy, accountability, policy, and oversight of AI

Data Privacy17/100

Data handling, DPIAs, minimisation, and transparency

AI Security17/100

Protecting AI systems, credentials, and outputs

Legal Compliance & Shadow AI17/100

Regulatory compliance, IP, and shadow AI control

Operational17/100

Process embedding, quality, skills, and scaling

Your Assessment Summary

Your organisation has achieved an AI Governance Score of 17/100, indicating that AI use across your business is largely ungoverned. The good news: most of this risk can be closed with focused policies, controls, and accountability, and acting now puts you ahead of regulators, customers, and competitors demanding evidence of control.

Your strongest area is Governance (17/100), which gives you a solid foundation to build on. Operational (17/100) is your most significant gap, and your biggest opportunity for rapid risk reduction.

These five sections reinforce each other: governance sets the rules, data privacy and security enforce them, legal compliance keeps you within them, and operational maturity proves they work in practice. The organisations that demonstrate AI governance well do not fix one section in isolation, they build all five in parallel, each strengthening the others. Your prioritised roadmap below is sequenced to create exactly this effect.

Section Insights

A detailed look at each section, what it means and where the gaps are.

Governance17/100
At Risk

AI is being used across your organisation without formal oversight. Without a strategy, named accountability, or an enforced policy, AI use is unmanaged, and your exposure grows with every new tool someone adopts.

Key Gaps

  • •No documented, approved AI strategy or usage policy
  • •No named owner or committee accountable for AI oversight
  • •AI tools are deployed without review, approval, or risk assessment

If You Do Nothing

  • •UK GDPR fines reach £17.5m or 4% of turnover for data misuse, and "we didn't know" is not a defence
  • •One unvetted AI tool is all it takes for a client's confidential data to leave your control, ending contracts and triggering breach-notification duties
  • •Boards, insurers and procurement teams increasingly demand evidence of AI control: without it you lose tenders and cover, and directors carry the accountability

How This Connects

This is the root cause of every other gap: without policy and accountability there is no mandate for the data, security, and legal controls assessed below, and no one to answer for them. Fixing governance first is what makes the other sections fixable.

Data Privacy17/100
At Risk

You have limited visibility of what personal data your AI tools collect, process, and store. This creates immediate regulatory exposure under UK GDPR and undermines trust in how you handle information.

Key Gaps

  • •Data flows into AI tools are unknown or unmapped
  • •No DPIAs completed for AI processing of personal data
  • •No controls preventing sensitive data entering AI tools

If You Do Nothing

  • •UK GDPR fines reach £17.5m or 4% of global turnover, and AI data misuse is squarely in scope
  • •A personal data breach via an AI tool triggers 72-hour notification duties, client notifications, and potentially class actions
  • •Customers and partners will leave a supplier that cannot say where their data goes, and AI is now the first place they look

How This Connects

Data privacy sits at the sharp end of the other sections: weak governance means no one maps or approves data flows, and weak security means nothing technically stops sensitive data entering AI tools, together, that is exactly how a reportable GDPR breach happens.

AI Security17/100
At Risk

Your AI tools are deployed without security assessment, credentials are loosely managed, and outputs are used unchecked. This is the classic attack surface for AI-era breaches, and it is open.

Key Gaps

  • •No security assessment before deploying AI tools
  • •Credentials and API keys are not securely managed
  • •AI outputs are trusted without validation

If You Do Nothing

  • •AI credentials with broad access are a direct route into your systems, a single leaked key can expose far more than the tool itself
  • •Prompt injection and unchecked AI outputs are now a leading cause of data exfiltration and fraudulent transactions
  • •A breach through an ungoverned AI tool won't be treated as an AI problem, it will be treated as your breach

How This Connects

Security is what turns governance rules into technical reality: the policy written in your governance section is only as strong as the access controls and monitoring assessed here, and a breach here converts every compliance gap into a live incident.

Legal Compliance & Shadow AI17/100
At Risk

Shadow AI is likely in use without your knowledge, vendor contracts do not address AI risk, and your regulatory position under the EU AI Act or UK framework is unclear.

Key Gaps

  • •Shadow AI is unidentified and unmanaged
  • •Contracts do not address IP, liability, or output ownership
  • •Regulatory compliance status is unknown

If You Do Nothing

  • •EU AI Act penalties reach €35m or 7% of global turnover, and obligations are already phasing in
  • •IP and ownership disputes over AI-generated work can invalidate deliverables you have already sold to clients
  • •Unmanaged shadow AI means contracts, confidentiality and regulatory duties are being breached by staff right now, without your knowledge

How This Connects

Legal compliance is where every other gap becomes liability: ungoverned tools, unmapped data and unassessed systems each convert into contractual and regulatory exposure here, the weaknesses of the other sections are compounded, not contained, by this one.

Operational17/100
At Risk

AI use is ad-hoc: value is not measured, outputs are not reviewed, and there is no budget or ownership. Without structure, benefits will not scale, and neither will control.

Key Gaps

  • •AI use is individual, ad-hoc, and undocumented
  • •No measurement of return or business impact
  • •No budget, owners, or champions for AI activity

If You Do Nothing

  • •AI spend keeps growing while returns go unmeasured, budget that delivers nothing gets cut, taking genuine value with it
  • •Unreviewed AI outputs reach customers directly, and one high-profile error damages the brand more than years of good work can repair
  • •Without owners and champions, ad-hoc use fragments, shadow AI fills the space your structure leaves

How This Connects

Operational maturity is where governance becomes real: the policies, controls and approvals from the other sections only matter if they reach day-to-day work, where they don't, staff bypass them and shadow AI fills the gap, quietly reopening every risk the other sections closed.

Risks of Inaction

  • Doing nothing is not a neutral option: with AI use largely uncontrolled, it is a question of when, not whether, you face a reportable data breach, a regulatory investigation, or a client discovering their data went into an AI tool. UK GDPR fines alone reach £17.5m or 4% of turnover, and the reputational damage outlasts the penalty.
  • Your weakest section, Operational, is where a real-world incident is most likely to start: a data leak, a compliance breach, or an AI-driven decision that costs you a client. Gaps never stay isolated; they surface as incidents in the area you are least prepared to defend.
  • Without a maintained AI register and a mandatory approval process, shadow AI keeps spreading, and most organisations only discover unsanctioned AI use after something has gone wrong, when the fines, breach costs and lost contracts are already incurred.
  • Because the five sections reinforce each other, one unaddressed gap reopens the others: ungoverned tools bypass security, unassessed tools mishandle personal data, and both end up as legal exposure. Acting on the roadmap as a connected programme is what breaks that chain.