tioga.ai — sample artifact
AI Governance Readiness Assessment — Executive Summary
The summary-page format delivered at the end of the 3–4 week AI Governance Readiness Assessment engagement.
SAMPLE — client name and findings below are fictional and illustrative of format only, not a real assessment.
01 — Scope
| Client | Cascade Logistics (illustrative) |
| Systems assessed | 3 production AI systems (procurement-matching agent, support-triage classifier, internal copilot) |
| Frameworks | NIST AI RMF, ISO 42001, EU AI Act (applicability check) |
| Assessment window | 3.5 weeks |
02 — Readiness by framework function
Pattern typical of pre-launch AI programs: governance intent exists (Govern), but system inventory and ongoing monitoring lag behind (Map/Measure) — the gap this assessment exists to find.
03 — Top findings
| Severity | Finding | Recommendation |
| High | No documented system inventory — 3 production AI systems, 1 undocumented | Stand up a living system inventory as the Map function's foundation |
| High | No post-deployment monitoring for the procurement-matching agent | Instrument decision logging before next model update |
| Medium | EU AI Act applicability not yet assessed for the support-triage classifier | Run a risk-tier classification against Annex III |
| Low | Incident-response runbook exists but hasn't been tested | Tabletop exercise within the next quarter |
04 — Remediation roadmap (excerpt)
| Phase | Focus | Duration |
| 1 | System inventory + monitoring instrumentation | 2–3 weeks |
| 2 | EU AI Act risk-tier classification + evidence package | 2 weeks |
| 3 | Incident-response tabletop + runbook update | 1 week |