UK Enterprise AI Governance Benchmark

Anonymous assessment

Answer 20 governance questions across ten dimensions. Your score is calculated immediately in your browser. After completing all questions, you can voluntarily submit the answers anonymously for aggregate annual research. The benchmark form does not ask for your name, organisation, email address or phone number.

Your current maturity score

0/100

Initial

0/20 answered · self-assessment only · no UK percentile is shown until a sufficient research cohort exists.

Inventory & ownership

0/100

0/2 answered

Risk classification

0/100

0/2 answered

Data governance

0/100

0/2 answered

Evaluation & assurance

0/100

0/2 answered

Human oversight

0/100

0/2 answered

Agent & tool controls

0/100

0/2 answered

Third-party governance

0/100

0/2 answered

Change management

0/100

0/2 answered

Incident response

0/100

0/2 answered

Value & lifecycle

0/100

0/2 answered

Inventory & ownership

We maintain an inventory of material AI use cases, systems and accountable owners.

Inventory & ownership

Each material AI use has a documented purpose, users and intended business outcome.

Risk classification

AI uses are classified by consequence, autonomy and data sensitivity.

Risk classification

Higher-risk AI uses require stronger approval, testing and oversight.

Data governance

Data used by AI has documented sources, permissions and confidentiality/privacy restrictions.

Data governance

We control whether sensitive organisational data may be sent to external AI providers.

Evaluation & assurance

Material AI is evaluated against task-specific quality and failure criteria before deployment.

Evaluation & assurance

We retain evidence of evaluations and known limitations for consequential AI uses.

Human oversight

Consequential AI-supported decisions have explicit human review and escalation rules.

Human oversight

People responsible for oversight have sufficient information and authority to challenge or stop the AI-enabled process.

Agent & tool controls

AI agents/tools use least privilege and deterministic authorisation for protected actions.

Agent & tool controls

High-impact actions such as payment, deletion, publication or contractual commitment require appropriate approval.

Third-party governance

We assess material AI/model providers for security, data handling, resilience and contractual dependency.

Third-party governance

We understand material provider/model concentration and have proportionate exit or continuity plans.

Change management

Material changes to models, prompts, tools or workflows are versioned and retested.

Change management

We can identify which material AI configuration/version was operating when an important decision or incident occurred.

Incident response

AI failures, misuse, complaints and unexpected behaviour have an incident and escalation process.

Incident response

Material AI incidents generate corrective actions and lessons that feed back into governance.

Value & lifecycle

AI use cases are periodically reviewed for realised value, cost, risk and continued justification.

Value & lifecycle

We can retire or disable AI capabilities that no longer meet business, risk or performance requirements.

Optional anonymous cohort information

These broad categories help produce useful aggregate comparisons without asking for your name, organisation or contact details.

Do not enter confidential, personal or identifying information. Participation is voluntary. Optional cohort fields use broad categories. Public reporting is aggregate only, and raw organisation-level responses are not published. This diagnostic is not certification, legal advice or independent assurance.

Benchmark methodology and publication rules