Skip to content

Where does your organization stand on AI risk today?

That is the question printed on the back of the book, and this is the assessment that answers it. Twenty questions across the four Culture AIR-MAP™ phases, about 10 minutes, free. You get a stage placement, a reading on each phase, and three actions to start on Monday.

Everything here is Lite Culture AIR-MAP™ Self-Assessment, reproduced from Gears Don’t Guess, Appendix A (canonical PDF, Tribe Copy).

Before you start

This assessment places your organization on the Culture AIR-MAP™ maturity scale and points to your next move. It is the Lite version. You leave with a four-stage placement, three Monday-morning actions, and a one-page scorecard you can take to your management team or your board.

How long
About 10 minutes on your own.
What it asks
20 questions, plus three over-control signals per phase.
What you get
A stage placement, a per-phase reading, and three actions.

How to score

Each question scores 0, 1, or 2. Sum the five questions per phase for a phase score from 0 to 10. Sum the four phase scores for a total from 0 to 40.

  • 0No. You don’t do this. Or you used to and stopped. Or you’ve talked about it but no one owns it.
  • 1Partial. You do this informally, inconsistently, or in pockets. It happens often enough to be visible but not often enough to be reliable.
  • 2Yes. You do this, you’ve documented it, and it operates on a known cadence. Someone owns it.

If you can’t answer a question without checking with someone first, that’s information too. Score it 0 for now and move on. The goal of the Lite assessment is a placement, not a perfect score. The uncertain answers are part of your next move.

Phase 1. Discovery and Inventory

Maps to Part 2 (Chapters 3 through 6).

Discovery and Inventory is where you map every AI tool, workflow, and integration in use today. The phase answers one question: what’s actually running?

Question 1.1. AI tool inventory. Have you completed a current inventory of AI tools, including paid subscriptions, free tools, and tools employees use without IT’s knowledge?
Question 1.2. Financial-records sweep. Have you reviewed corporate card transactions, accounts payable records, and expense reports in the last 90 days for AI vendors no one told you about?
Question 1.3. Data classification. Have you classified the data each AI tool can access as Public, Confidential, or Restricted, with Restricted data restricted to a local LLM?
Question 1.4. Approved tools list. Do you publish a current approved AI tools list sorted into Tier 1, Tier 2, and Tier 3?
Question 1.5. Exception process. Do you have a written exception process that requires business justification, compensating controls, and an expiration date on every exception?
Over-control signals for Discovery and Inventory

These are not scored. Check any that describe this phase. If even one fires, the phase is over-controlled no matter what the questions added up to.

Phase 2. Measure and Score

Maps to Part 3 (Chapters 7 through 9).

Measure and Score is where you assess your governance maturity against an honest standard. The phase answers: where does our program stand, and can we show it?

Question 2.1. Program owner. Is the AI governance program owned by a line-of-business person with formal authority and informal trust, rather than the CISO, CIO, or head of IT?
Question 2.2. Written specifications. Do your high-stakes AI workflows have a written specification of what a correct output looks like before anyone prompts the AI?
Question 2.3. Specification metric tracked. Do you track at least one specification metric, such as “AI outputs rejected after review this month,” on a recurring cadence?
Question 2.4. One-page board update. Do you produce a one-page board AI update that covers exposure, incidents, program performance, and budget?
Question 2.5. Total AI spend known. Can you state your total AI spend this quarter across IT, marketing, operations, legal, and finance within an hour?
Over-control signals for Measure and Score

These are not scored. Check any that describe this phase. If even one fires, the phase is over-controlled no matter what the questions added up to.

Phase 3. Mitigation and Innovation

Maps to Part 4 plus the start of Part 5 (Chapters 10 through 13).

Mitigation and Innovation is where you close the gaps the assessment revealed and adjust the controls that have drifted into over-control. The phase answers: are we lowering risk in a way that still lets people do useful work?

Question 3.1. Architectural constraints for destructive AI actions. For AI actions with permanent consequences (an AI agent deleting an ERP record, wiping a backup, sending a payment), is the safeguard built into the system itself (delayed delete, two-step approval, out-of-band confirmation) rather than a rule written into the AI’s instructions?
Question 3.2. Data boundary controls. Do AI agents access only the data and operations they need for one task (rather than a single master credential that opens everything), and are backups stored on different storage than primary data?
Question 3.3. AI vendor diligence. Do you run a four-question AI vendor diligence before approving new AI vendors: does it learn from your data, what’s the model lineage (which underlying AI models it sits on top of), what can it do without a human, who are its vendors?
Question 3.4. Over-control identified and being unlocked. Have you identified at least one area where AI controls are blocking the innovation you intended to enable, and are you actively adjusting it?
Question 3.5. Written 90-day roadmap. Do you have a written 90-day AI governance roadmap with named owners and target dates, instead of reacting incident by incident?
Over-control signals for Mitigation and Innovation

These are not scored. Check any that describe this phase. If even one fires, the phase is over-controlled no matter what the questions added up to.

Phase 4. Maintenance

Maps to the rest of Part 5 plus Part 6 (Chapters 14 through 17).

Maintenance is the ongoing operating discipline that keeps the program working as AI vendors, tools, and use cases keep changing. The phase answers: will this program survive the next twelve months without falling apart?

Question 4.1. Role-based training. Have you trained supervisors first (the enforcement layer), then executives, then individual employees, on your AI policy?
Question 4.2. Cultural signal check. Can three randomly chosen employees name the approved tools, describe the exception process, and tell you they own the output of any AI tool they use?
Question 4.3. Incident response readiness. Do you have a calibrated internal-message template, a pre-assigned triage owner, and a severity triage card in place before the next incident?
Question 4.4. Risk-register cadence. Is AI risk reviewed on your standard risk-register cadence, including additions, severity changes, and closures, instead of being treated as a separate annual exercise?
Question 4.5. Failure-pattern review. Do you run a quarterly or annual review of AI failure patterns (your own incidents plus published cases) and apply lessons to your controls?
Over-control signals for Maintenance

These are not scored. Check any that describe this phase. If even one fires, the phase is over-controlled no matter what the questions added up to.

The scale, in full

Everything the assessment scores against, straight from Appendix A. Read it before you answer or after you see a result. It does not change either way.

Phase scoring: the innovation-balance scale

Phase scoreZoneWhat it means
0 to 2No governanceHigh risk. The phase is essentially unmanaged.
3 to 5Basic controlsModerate risk. The phase exists in pockets but isn’t reliable.
6 to 10Balanced governanceOptimal. The phase reduces risk without blocking useful work.
Any score, if a signal below firesOver-controlledInnovation blocked. Failure mode on the same scale as 0 to 2.

Over-control is rare to self-diagnose, because most management teams don’t recognize it in their own organization. So apply this cue. If any of the three signals below describe a phase, mark that phase over-controlled no matter what the questions added up to and follow the over-control next-move guidance in the stage table.

How to spot over-control in a phase:

  • The cycle time for approving a new AI tool exceeds 12 weeks from request to answer.
  • Employees route their work around the approved path because the path is slower than the work.
  • Tools sit on the approved tools list with zero usage three months after approval.

If you see any one of those, you have an over-control problem in that phase even when your other answers look strong. Over-control kills programs the same way no controls do, just more quietly.

Total interpretation: organizational maturity

Total scoreStageWhat the organization usually looks like
0 to 12FormingNo inventory, no classification, no tiers, no exception process. AI risk is unmanaged. Shadow AI is in use; no one is tracking it. The conversation is still “should we ban it.”
13 to 22BuildingInventory exists. Classification card published. Approved tools list under construction or freshly published. Program owner named, but the role is still defining itself. Specification work hasn’t started.
23 to 31OperatingProgram owner active and respected. Specifications written for high-stakes workflows. At least one specification metric tracked. Board update produced quarterly. Vendor diligence run on new AI vendors.
32 to 40LeadingAll four phases score in the 6 to 10 zone with no over-control signal firing. Maintenance cadence has run at least one full cycle. Over-control is monitored on the same scale as under-control. AI risk is a standing category on the risk register.

What to do next, by stage

Three Monday-morning actions per stage. Each action names the chapter you will want to return to.

Formingtotal 0 to 12

  1. Run the financial-records sweep this week. Corporate cards, accounts payable, expense reports, last 90 days. Search for AI vendor names. You’ll find tools no one told you about. That’s the point. (Chapter 3; Chapter 13 Days 1 to 30.)
  2. Publish the data classification card. Three levels: Public, Confidential, Restricted. One page. Restricted data goes only to a local LLM. (Chapter 4.)
  3. Name the program owner. A line-of-business person with formal authority and informal trust. Not the CISO. Not the CIO. Not the head of IT. (Chapter 7.)

Buildingtotal 13 to 22

  1. Publish your approved tools list, even with three tools on it. A short visible list beats a long list that’s in progress. Your employees need a path. (Chapter 13, Days 31 to 60.)
  2. Write a specification for one high-stakes workflow this week. Pick something your team already uses AI for. Write what a correct output looks like before anyone prompts the AI again. (Chapter 8 Habit 1.)
  3. Add one specification metric to your next status meeting. The easiest place to start is “AI outputs rejected after review this month.” Track it for one quarter. If the number is zero, you’ve learned something important. (Chapter 8 Habit 5; Chapter 9.)

Operatingtotal 23 to 31

  1. Run the four-question vendor diligence on your most data-sensitive AI vendor. Does it learn from your data? What’s the model lineage? What can it do without a human? And who are its vendors? One vendor, one to three hours. (Chapter 12.)
  2. Identify one over-controlled area and unlock it. Find one place where the policy is blocking the work it was meant to enable. Adjust the control instead of adding another one. (Chapter 6; Chapter 15.)
  3. Draft the calibrated internal-message template with your General Counsel. Half a day with the General Counsel. Save it where your management team can find it on a Saturday morning. The first time you need it, you’ll spend minutes instead of hours. (Chapter 16.)

Leadingtotal 32 to 40

  1. Run a quarterly failure-pattern review. Your own incidents plus published cases. Apply at least one lesson to your controls. The pattern is the asset; isolated incidents aren’t. (Chapter 17.)
  2. Audit each phase for over-control signals. Use the three cues above. Over-control hides best in mature programs because mature programs don’t look like they’re failing. (Phase scoring overlay above.)
  3. Pressure-test the program owner role for succession. If your program owner left next week, who picks it up? If the answer is “no one” or “we’d hire,” your program isn’t durable yet. (Chapter 7.)

Over-control override

If any phase is marked over-controlled, treat that phase as your priority regardless of total score. Pick the matching action below.

  • Phase 1 over-controlled. Cut your inventory or classification process to one page and one weekly meeting. Detailed inventory you can’t keep current is worse than a one-page inventory you can.
  • Phase 2 over-controlled. Cut a measurement, dashboard, or review from your cycle. Programs over-controlled in Phase 2 die from measurement overhead, not under-measurement.
  • Phase 3 over-controlled. Apply the Operating action 2 above (identify one over-controlled area and unlock it). Set a date for the unlock.
  • Phase 4 over-controlled. Cut a recurring review meeting or cadence from your operating rhythm. If three quarterly reviews could be one annual review with the same effect, make the change.

When the Lite assessment isn’t enough

The Lite assessment places you on the maturity scale and points to your next move. It doesn’t run the program for you. Three signals tell you it’s time for a deeper engagement:

  • The score reveals work too large for your existing operations to absorb.
  • Regulators or auditors require a documented assessment.
  • An incident has just happened, and the next twelve months will be measured against your response.

If one of these describes your situation, learn more about the full Culture AIR-MAP™ engagement at air-map.io.