Know whether AI governance can scale without losing visibility, accountability or trust.
Ten business days to separate policies from operating reality and show leadership what is visible, what is trusted, what is unproven and what must change first.
Know whether AI governance can scale without losing visibility, accountability or trust.
The Rapid Review remains a ten-business-day, 49-criterion independent diagnosis. The update keeps the bounded review but broadens what counts as governance evidence, so management cannot score well merely because policies and committees exist.
The question the review answers: If AI adoption doubled, would the organisation know what exists, who owns the decisions, which systems can be trusted, what evidence is missing and what should stop or reopen?
Know whether AI is creating governed value.
Tests strategic intent, business outcome, value evidence, portfolio visibility, success metrics, appetite and scale/stop decisions.
Know whether the organisation can see and own the AI that matters.
Tests inventory completeness, embedded/shadow AI, classification, ownership, authority, escalation and change reclassification.
Know whether the technical position can support the business claim.
Tests data rights/quality, architecture, cyber risk, suppliers, concentration, portability, fallback and resilience.
Know whether human judgement remains real.
Tests decision boundaries, override capability, workload, automation bias, competence, literacy and workforce transition.
Know what evidence demonstrates that AI behaves acceptably.
Tests validation, performance, fairness, robustness, explainability, GenAI/agent evidence and specialist assurance coverage.
Know whether obligations and new evidence reopen the position.
Tests applicability, records, monitoring, incident handling, provider/model change, drift thresholds and notification.
Know whether leadership can rely on the governance position.
Tests assurance mapping, evidence confidence, reliance, Board information, challenge, closure evidence and review triggers.
A strong policy cannot compensate for weak operating evidence.
Management's AI register is reconciled to independent discovery sources.
The review records what population was checked, what remains unknown and whether embedded or shadow AI sits outside governance.
High-impact use cases must show evidence appropriate to the technology.
The review does not perform every quantitative test, but it identifies the missing validation, fairness, robustness, hallucination, security or agent evidence.
Human oversight is tested as an operating control.
The review asks whether the named human can understand, challenge, override or stop the AI in time.
AI literacy is not treated as generic training completion.
The review tests whether roles whose judgement or accountability changed have proportionate competence and operating support.
Approval has an expiry logic.
The review records what incident, drift, supplier, data, model, autonomy, or regulatory change must reopen the decision.
The Board's own AI use enters scope.
Where relevant, the review tests Board-paper AI, confidentiality, verification, director literacy and Committee allocation.
Start with one material use case and the governance around it.
The review remains deliberately bounded. Where it identifies a need for a quantitative model, fairness, robustness, adversarial, or other specialist testing, it makes that requirement explicit rather than hiding it inside a governance score.