Priority Governance
Illustrative sample — not a real organization

Sample QuickScan Result

This is an illustrative sample so you can see the output before you start. Harborview Advisory Group is an invented professional-services firm — it is not a real organization, not a client, and its answers and figures were made up for this page. Your own result is generated instantly from your answers — free, on screen, and without submitting sensitive operational data.

Take the Free QuickScan →See the Starter Kit & Workshop
Your Readiness Level
Developing
Readiness score: 33 / 100 (secondary to the level)

Some useful practices exist, but they remain informal or inconsistent. Documenting a handful of essentials will move you quickly.

Readiness Level is directional and based on self-reported information — it supports discussion and prioritization, not certification or compliance determination.

Seven-Pillar Snapshot

Each bar is a sub-score out of 100, shown with its level.

InventoryDeveloping · 33/100
Access & DataDeveloping · 44/100
Use ControlsDeveloping · 44/100
Risk & ComplianceDeveloping · 33/100
Vendor & ProcurementEarly Stage · 11/100
1 “Not sure” answer — flagged as an unknown to discuss
Model & Output ControlsDeveloping · 33/100
Oversight & AccountabilityDeveloping · 33/100

21 of 21 questions answered in this sample, including 1 “Not sure” answer flagged as an unknown to clarify with the team.

Strongest Areas

In this example these came out ahead of the rest. They are often the easiest to describe to a board or a customer.

Access & Data
Readiness sub-score 44/100
Use Controls
Readiness sub-score 44/100

Top Gaps

In this example these areas may benefit from attention first. Listed weakest first — this is where a focused plan usually starts.

Gap 1: Vendor & Procurement
Readiness sub-score 11/100 · 1 unknown to confirm
Gap 2: Inventory
Readiness sub-score 33/100
Gap 3: Model & Output Controls
Readiness sub-score 33/100

Policy Starter Outline (Discussion Draft)

Discussion Draft — not a finalized or compliant policy

Discussion Draft — not a finalized or compliant policy. This is a starting point to refine internally and with your own legal, security, and compliance advisors. It is not legal advice, not a security assessment, and not a compliance certification.

# AI Acceptable Use — Policy Starter Outline (Discussion Draft)

> **Discussion Draft — not a finalized or compliant policy. This is a starting point to refine internally and with your own legal, security, and compliance advisors. It is not legal advice, not a security assessment, and not a compliance certification.**

**Organization:** Harborview Advisory Group (example)
**Industry:** Professional services / consulting  ·  **Size:** 51–200
**Buyer context:** We sell into regulated industries; We respond to RFPs or security questionnaires
**Readiness Level:** Developing (33/100, directional)

---

## 1. Purpose (Draft)

Harborview Advisory Group (example) uses AI tools to do useful work. This starter outline is a discussion draft to help Harborview Advisory Group (example) agree on a few practical, plain-English rules for using AI responsibly. It is a starting point for internal conversation — not a finalized or compliant policy, and not legal advice. Organizations differ, and the wording that fits Harborview Advisory Group (example) will not be the wording that fits everyone; edit this draft rather than adopting it as written.

## 2. Scope (Draft)

This outline is intended to cover employees and contractors of Harborview Advisory Group (example) who use AI tools (for example: general-purpose chat assistants, coding assistants, and AI features inside other software) for work.

## 3. Where You Stand Today (From Your QuickScan)

Your self-reported readiness snapshot, by pillar:

- **Inventory:** informal / inconsistent (Readiness sub-score 33/100)
- **Access & Data:** informal / inconsistent (Readiness sub-score 44/100)
- **Use Controls:** informal / inconsistent (Readiness sub-score 44/100)
- **Risk & Compliance:** informal / inconsistent (Readiness sub-score 33/100)
- **Vendor & Procurement:** not yet established (Readiness sub-score 11/100)
- **Model & Output Controls:** informal / inconsistent (Readiness sub-score 33/100)
- **Oversight & Accountability:** informal / inconsistent (Readiness sub-score 33/100)

**Top areas to discuss first:** Vendor & Procurement, Inventory, Model & Output Controls.

*These figures are directional and based on self-reported information. They support discussion and prioritization — not certification or compliance determination.*

## 4. Access & Data — A Starting Point to Agree

A useful rule of thumb is **describe, don't paste.** As a draft starting point, keep the following out of AI tools unless a specific, approved arrangement exists:

- Customer or client records and personal data
- Employee records
- Credentials, secrets, or access tokens
- Confidential contracts or sensitive legal documents
- Financial records
- Source code or production logs containing sensitive data

*Treat this as a draft to confirm and refine with your own legal, security, and privacy advisors.*

## 5. Policy Topics to Develop

These are the sections a written AI use policy usually needs. They are named for the same seven pillars you were just assessed against, in the same order — one framework, not a second one. The question under each is what that section of a policy has to settle for Harborview Advisory Group (example).

For each topic, the useful step here is agreeing the decision — not filling in a form. The complete, editable policy starter, worked examples, and step-by-step templates are part of the AI Governance Starter Kit.

- **Inventory** — Which AI tools and AI-enabled features are in use, which are approved versus unofficial, and who keeps that list current?
- **Access & Data** — What information may and may not go into AI tools, and who should be able to reach the tools that hold sensitive or confidential information?
- **Use Controls** — Which AI uses are allowed outright, which need approval first, and how does someone ask for a new tool or a new use?
- **Risk & Compliance** — How will you sort AI uses into simple risk levels, which uses get an extra review before going ahead, and what obligations to customers, funders, insurers, or a regulator apply?
- **Vendor & Procurement** — Who reads what a vendor’s terms say about your data — handling, retention, and training — before you rely on the tool, and who looks when a vendor adds AI features to software you already use?
- **Model & Output Controls** — When must AI output be checked by a person before it is shared or relied on, and when should AI involvement be disclosed?
- **Oversight & Accountability** — Who coordinates AI governance, who decides and handles escalations, and what records will you keep so you can answer a customer or leader quickly?

## 6. Where to Go From Here

1. Review this draft with the relevant people at Harborview Advisory Group (example) and agree the decisions above.
2. Take open questions to your leadership, legal, security, and compliance contacts.
3. When you’re ready to turn these decisions into working documents, the AI Governance Starter Kit provides the editable policy, templates, and a 30-day implementation plan.

---

*Discussion Draft — not a finalized or compliant policy. This is a starting point to refine internally and with your own legal, security, and compliance advisors. It is not legal advice, not a security assessment, and not a compliance certification.*

Every figure on this page belongs to an invented example organization and is illustrative and directional. The QuickScan is a practical starting point — not legal advice, not a security assessment, and not a compliance certification.