Crescent Capital Advisors

AI Governance Readiness Assessment

The AI Governance Readiness Assessment is a 65-question maturity diagnostic across five pillars: Data Trust, Model Governance, Agent Autonomy, Enterprise Operations, and Responsible AI. Each control is scored on a five-level maturity ladder, from non-existent to optimized, mapped to frameworks including NIST AI RMF, ISO 42001, and the EU AI Act. It shows which controls are in place and which are missing, before a board review, a regulator, or an acquirer's diligence team asks the same questions.

Progress0 / 65

DT

MG

AA

EO

RA

Do you have EU customers, or do you process data on EU residents?

This answer does not change your score. It changes the interpretation shown with your result.

Frequently asked questions

What does this assessment map to?

The five pillars and their maturity ladder are built to track the control areas covered by the NIST AI Risk Management Framework, ISO/IEC 42001, the EU AI Act's risk-based obligations, and the AI-specific controls in the Databricks AI Security Framework (DASF) 3.0. The Responsible AI pillar covers fairness, transparency, explainability, and human oversight. The result is a fast read on where you would stand if asked. It does not certify compliance with any one of them.

Who should run this?

It is for CISOs and CTOs preparing for a board AI-risk review, and for PE deal or operating teams assessing AI posture at a portfolio company or a target in diligence. It suits anyone who needs a defensible answer on how well their AI is governed, faster than a formal audit can produce one.

How is this different from a full engagement?

This is a self-scored, self-reported diagnostic: sixty-five questions, twelve to eighteen minutes, no evidence collected. CCA's full assessment verifies each control against evidence (configs, logs, registries, policies) and produces a report a board or buyer can rely on. Treat this result as a first read.

What are the limits of a self-scored result?

The result is only as accurate as the answers. Self-assessment tends to score generously: a team rates a policy that exists only on paper as if it were enforced. Use the result to decide where to look first. It is not evidence on its own.

Does the EU AI Act apply to us?

If you have EU customers or process data on EU residents, likely yes. The Act applies extraterritorially, and its high-risk obligations (risk management, human oversight, logging, technical documentation) map closely to this assessment's Model Governance, Enterprise Operations, and Responsible AI pillars. The first context question in the assessment flags this directly.

How does the 0-100 scoring work?

Each question is scored on the same five-level maturity ladder (non-existent, reactive, defined, managed, optimized) mapped to 0, 25, 50, 75, and 100. Your pillar score is the average across its questions; your composite band weights all five pillars equally.