Priority Governance
Example only — not a real organization

Sample QuickScan Result

This is a clearly labeled example so you can see the output before you start. Your own result is generated instantly from your answers — free, on screen, and without submitting sensitive operational data.

Start your own QuickScan →See the Starter Kit & Workshop
Your Readiness Level
Developing
Readiness score: 33 / 100 (secondary to the level)

Some useful practices exist, but they remain informal or inconsistent. Documenting a handful of essentials will move you quickly.

Readiness Level is directional and based on self-reported information — it supports discussion and prioritization, not certification or compliance determination.

Seven-Pillar Snapshot

InventoryFoundational · 50/100
Data BoundariesEarly Stage · 17/100
Risk ClassificationFoundational · 50/100
Human AccountabilityEarly Stage · 17/100
Security & Abuse ControlsFoundational · 50/100
Monitoring, Evidence & AuditabilityEarly Stage · 0/100
1 “Not sure” answer — flagged as an unknown to discuss
Governed AccelerationFoundational · 50/100

Top Gaps

1
Monitoring, Evidence & Auditability
Readiness sub-score 0/100
2
Data Boundaries
Readiness sub-score 17/100
3
Human Accountability
Readiness sub-score 17/100

14 of 21 questions answered in this example.

Policy Starter Outline (Discussion Draft)

Discussion Draft — not a finalized or compliant policy

Discussion Draft — not a finalized or compliant policy. This is a starting point to refine internally and with your own legal, security, and compliance advisors. It is not legal advice, not a security assessment, and not a compliance certification.

# AI Acceptable Use — Policy Starter Outline (Discussion Draft)

> **Discussion Draft — not a finalized or compliant policy. This is a starting point to refine internally and with your own legal, security, and compliance advisors. It is not legal advice, not a security assessment, and not a compliance certification.**

**Organization:** Northwind Systems (example)
**Industry:** Software / SaaS  ·  **Size:** 51–200
**Buyer context:** We sell into large enterprises; We respond to RFPs or security questionnaires
**Readiness Level:** Developing (33/100, directional)

---

## 1. Purpose (draft)

Northwind Systems (example) uses AI tools to do useful work. This starter outline is a discussion draft to help Northwind Systems (example) agree on a few practical, plain-English rules for using AI responsibly. It is a starting point for internal conversation — not a finalized or compliant policy, and not legal advice.

## 2. Scope (draft)

This outline is intended to cover employees and contractors of Northwind Systems (example) who use AI tools (for example: general-purpose chat assistants, coding assistants, and AI features inside other software) for work.

## 3. Where you stand today (from your QuickScan)

Your self-reported readiness snapshot, by pillar:

- **Inventory:** emerging (Readiness sub-score 50/100)
- **Data Boundaries:** not yet established (Readiness sub-score 17/100)
- **Risk Classification:** emerging (Readiness sub-score 50/100)
- **Human Accountability:** not yet established (Readiness sub-score 17/100)
- **Security & Abuse Controls:** emerging (Readiness sub-score 50/100)
- **Monitoring, Evidence & Auditability:** not yet established (Readiness sub-score 0/100)
- **Governed Acceleration:** emerging (Readiness sub-score 50/100)

**Top areas to discuss first:** Monitoring, Evidence & Auditability, Data Boundaries, Human Accountability.

*These figures are directional and based on self-reported information. They support discussion and prioritization — not certification or compliance determination.*

## 4. Data boundaries — a starting point to agree

A useful rule of thumb is **describe, don't paste.** As a draft starting point, keep the following out of AI tools unless a specific, approved arrangement exists:

- Customer or client records and personal data
- Employee records
- Credentials, secrets, or access tokens
- Confidential contracts or sensitive legal documents
- Financial records
- Source code or production logs containing sensitive data

*Treat this as a draft to confirm and refine with your own legal, security, and privacy advisors.*

## 5. Sections to develop together

A workable AI acceptable-use policy usually covers the areas below. For each, the useful step here is agreeing the decision — not filling in a form. The complete, editable policy starter, worked examples, and step-by-step templates are part of the AI Governance Starter Kit.

- **Approved tools & inventory** — Which AI tools and AI-enabled features are in use, which are sanctioned versus ad hoc, and who keeps that list current?
- **Risk & review** — How will you sort AI uses into simple risk levels, and which uses need a second review before going live (especially customer-facing or people-affecting uses)?
- **Human accountability** — Who owns AI governance, who approves new uses, and who handles problems or escalations?
- **Security & abuse guardrails** — Which approved tools and settings will you publish, and how will people report a mistake or near-miss? (Practical guardrails, not a security assessment.)
- **Evidence & records** — What will you keep — this outline, approvals, inventory — so you can answer a customer or leader quickly?
- **Governed acceleration** — What lightweight path lets teams request or propose a new AI use without going around the rules?

## 6. Where to go from here

1. Review this draft with the relevant people at Northwind Systems (example) and agree the decisions above.
2. Take open questions to your leadership, legal, security, and compliance contacts.
3. When you’re ready to turn these decisions into working documents, the AI Governance Starter Kit provides the editable policy, templates, and a 30-day implementation plan.

---

*Discussion Draft — not a finalized or compliant policy. This is a starting point to refine internally and with your own legal, security, and compliance advisors. It is not legal advice, not a security assessment, and not a compliance certification.*

Example figures are illustrative and directional. The QuickScan is a practical starting point — not legal advice, not a security assessment, and not a compliance certification.