How to Use This Tool

Purpose: This tool is a self-assessment instrument for boards and directors of multinational organisations. It enables the board to assess the maturity of the organisation's AI governance practices against internationally recognised frameworks for board oversight of artificial intelligence.

Who should complete this assessment: This checklist is designed for completion by the board as a collective exercise, facilitated by the company secretary or chair. Alternatively, individual directors may complete it independently and compare scores as part of a board discussion on AI governance.

Scoring: For each of the 30 questions, select one of three responses: Yes - In Place (2 points): the board is satisfied this is comprehensively in place. Partially / In Progress (1 point): some activity exists but material gaps remain. No - Not in Place (0 points): this is not in place or the board cannot confirm it.

Interpreting "Yes": A Yes response should reflect the board's own confident assessment, not management's assertion to the board. If the board cannot independently verify a practice is in place and functioning, the honest response is Partially or No.

After completing the assessment: Review your maturity level and domain scores. Use low domain scores to prioritise the board's AI governance agenda. Once your governance baseline is set, see the strategy counterpart: the AI Strategy Readiness Assessment. For an independent, expert-facilitated evaluation, consider a formal BoardEvaluator™ AI Governance Status Assessment.

Progress: Your progress saves automatically as you work. To return to a partially completed assessment, simply reopen this file - your responses will be restored. Use Save Progress to manually save at any point. Use Reset to start a new assessment (this clears all saved responses).

Reference Frameworks - Verified as at 13 August 2026
Framework Version / Status Custodian Effective Date
OECD Principles on AI2019, updated 2024OECDIn force
NIST AI Risk Management Framework (AI RMF 1.0)January 2023US NISTIn force
ISO/IEC 42001:2023 - AI Management System2023ISO / IECIn force
ISO/IEC 38507:2022 - Governance implications of AI2022ISO / IECIn force
ISO/IEC 23894:2023 - AI Risk Management2023ISO / IECIn force
EU AI Act2024 (phased)European UnionPhasing in from 2025
Note: AI regulation varies by jurisdiction and is evolving quickly. This tool is grounded in internationally recognised frameworks for board oversight of AI rather than any single country's law. Boards should track the AI regulations applicable in each market where the organisation operates, including the EU AI Act and sector-specific rules. For jurisdiction-specific governance codes (for example King V in South Africa), a local edition is available on request.
Important Notice - Please Read Before Using This Tool

What this tool is: T-BG-GL001 is a self-assessment instrument designed to help boards and directors of multinational organisations evaluate the maturity of their board's AI governance practices. It is provided by Celagenix as an educational and governance-development tool.

What this tool is not: This tool is not a legal opinion, regulatory opinion, or formal governance evaluation. Completing it does not confirm compliance with any law, code or regulatory requirement. Scores are based on the board's own self-assessment and have not been independently verified. This tool does not constitute advice of any kind - legal, governance, technical or otherwise.

Framework basis: This tool draws on internationally recognised frameworks for board oversight of AI, including the OECD AI Principles, the NIST AI Risk Management Framework, ISO/IEC 42001 and 38507, ISO/IEC 23894, and the EU AI Act. It is sector-agnostic and multi-jurisdiction; it is not specific to any single country's law.

Local governance codes and law: National corporate-governance codes and data-protection laws (for example King V and POPIA in South Africa, the UK Corporate Governance Code, or the GDPR) impose additional, jurisdiction-specific obligations that this international edition does not address in detail. Boards should obtain advice on the codes and laws applicable in each market where the organisation operates. Jurisdiction-specific editions of this tool are available on request.

Strategy counterpart: Governance is one side of the coin; strategy is the other. For the strategy side, use the companion AI Strategy Readiness Assessment.

Professional advice: Celagenix recommends that boards supplement this self-assessment with formal, expert-facilitated evaluation. For an independently assessed AI governance evaluation producing a consolidated board report and benchmarked recommendations, visit the BoardEvaluator™ AI Governance Status Assessment.

References-verified date: All framework references were verified as at 13 August 2026. This tool should be reviewed by August 2027, or earlier if material regulatory changes occur. Scope: Global · Enterprise · Multi-jurisdiction.

Governance Maturity Assessment - Score Dashboard
0% Maturity
Not Yet Started
Complete the checklist below to assess your board's AI governance maturity. Answer all 30 questions across 6 domains to receive your full score and recommendations.

Your AI governance gap requires urgent board attention.

Your score indicates that the board's AI governance practices are at the Ad Hoc or Developing stage - a position of material risk against the board's duty of care and internationally recognised AI oversight expectations. A self-assessment is the right starting point, but it is not sufficient on its own to address a governance gap of this magnitude.

The BoardEvaluator™ AI Governance Status Assessment provides:

  • Independent, expert-facilitated evaluation across all six AI governance domains
  • A confidential, board-ready assessment report with scored findings and specific recommendations
  • Benchmarking against comparable multinational organisations
  • A prioritised remediation roadmap that the board can act on immediately
Commission a BoardEvaluator™ Assessment →

Strong foundations. Specific gaps remain.

Your score confirms that the board has established a credible AI governance framework that broadly meets internationally recognised expectations. The domain-level breakdown reveals where specific gaps remain. Closing those gaps efficiently and with confidence requires more than a checklist.

The BoardEvaluator™ AI Governance Status Assessment provides:

  • A formal, expert-evaluated assessment that validates your self-assessment scores and identifies blind spots
  • Targeted recommendations for each domain gap, with practical implementation guidance
  • A consolidated board report suitable for presenting to the board, its committees and key stakeholders
  • Benchmarking data to contextualise your score against peer multinational organisations
Request a BoardEvaluator™ Assessment →

Governance excellence, well evidenced.

Your score indicates that the board is operating at an Advanced level of AI governance maturity, consistent with international leading practice. Achieving this is significant. Sustaining it - as AI technology evolves, AI regulation develops across jurisdictions, and stakeholder scrutiny intensifies - requires ongoing discipline and independent validation.

The BoardEvaluator™ AI Governance Status Assessment provides:

  • Periodic independent validation of governance excellence, producing externally credible evidence of the board's AI oversight rigour
  • An updated benchmarking analysis as the global AI governance landscape evolves
  • A board-ready assessment report that supports the organisation's disclosure obligations
  • Early identification of emerging governance gaps before they become material risks
Schedule a BoardEvaluator™ Assessment →
0 - 25% · 0-15 pts
Ad Hoc
No formal AI governance structure. Immediate board action required.
26 - 50% · 16-30 pts
Developing
Some awareness but governance is informal and incomplete. Key gaps remain.
51 - 75% · 31-45 pts
Defined
Structured approach broadly in place. Specific domains require strengthening.
76 - 100% · 46-60 pts
Advanced
Robust, integrated AI governance consistent with international leading practice.
Yes - In Place = 2 points
Partially / In Progress = 1 point
No - Not in Place = 0 points
01
Board AI Mandate & Strategic Direction
0/10
AI governance starts with the board: approving the framework, setting the risk appetite, and ensuring AI activity is integrated into - not isolated from - the organisation's strategy. This domain assesses whether the board has established a clear mandate and strategic direction for AI, consistent with the OECD AI Principles and NIST AI RMF (Govern).
T-BG-GL001.1.1
Has the board approved a formal AI governance framework or policy that defines the organisation's approach to the acquisition, development, use and distribution of artificial intelligence?
OECD AI Principles; NIST AI RMF (Govern); ISO/IEC 38507: A board-approved AI governance framework is the foundation of oversight and the anchor of the board's duty of care for AI.
T-BG-GL001.1.2
Does the board have sufficient collective understanding of how artificial intelligence is currently being used - or is proposed to be used - within the organisation and its material third-party relationships to fulfil its oversight obligations?
ISO/IEC 38507; NIST AI RMF (Map): Boards can only oversee what they understand. Sufficient collective knowledge of where and how AI is used is a precondition for effective oversight.
T-BG-GL001.1.3
Is the board's AI governance framework explicitly integrated into the organisation's overall strategy and business model - rather than treated as a standalone technology policy?
OECD AI Principles; NIST AI RMF (Govern): AI governance must be integrated with strategy and the business model, not treated as a standalone technology policy.
T-BG-GL001.1.4
Has the board approved a defined AI risk appetite statement that sets the boundaries within which management may develop, deploy or procure AI systems - and is this statement reviewed at least annually?
ISO/IEC 23894; NIST AI RMF (Manage): A defined AI risk appetite sets the boundaries within which management may build, deploy or procure AI, and should be reviewed at least annually.
T-BG-GL001.1.5
Does the board receive at least one dedicated briefing per year on artificial intelligence developments - including new AI deployments, material risks, regulatory updates and industry trends - to maintain the competence required for effective AI oversight?
ISO/IEC 38507: Directors must maintain the competence to oversee AI. A dedicated annual briefing keeps the board current on deployments, risks and regulatory change.
02
AI Risk Oversight & Assurance Framework
0/10
03
Responsible AI & Ethical Governance
0/10
04
AI Data Governance & Cyber Risk
0/10
05
AI Acquisition, Oversight & Performance
0/10
06
AI Transparency & Stakeholder Reporting
0/10