Assessment methodology

AI/LLM Security & Compliance Readiness: methodology and sources

This page explains how questions are structured, how the score is calculated, how critical gaps affect the result, and how the assessment should be interpreted.

Version 1.0Last reviewed: 2026-08-2315 questions

Purpose and boundaries

This is an awareness and decision-support assessment. It is not an audit, certification, legal opinion, or formal compliance determination. The score is designed to help leadership identify where deeper review, evidence, or remediation is warranted.

Scoring model

  1. Each question is scored from 0–4. The highest score represents a formalized, implemented, tested, and evidenced state.
  2. Questions are assigned to governance domains. Each domain score is the ratio of earned points to available points in that domain.
  3. Domain scores are combined into the overall score using the domain weights shown below.
  4. “Not sure” answers are treated as an uncertainty signal and may apply a modest uncertainty adjustment.
  5. Some foundational questions have critical rules. If a critical foundation is absent, the overall score can be capped so a high average does not hide material risk.

Domain weights

AI governance18%

Ownership, policy, approvals, and accountability.

AI inventory12%

Known tools, use cases, data access, and owners.

Data protection16%

Sensitive data handling, vendor terms, and privacy checks.

LLM security22%

Prompt injection, output handling, RAG, agents, and OWASP LLM exposure.

Model risk and oversight14%

Human review, monitoring, bias, misinformation, and fallback.

Compliance evidence18%

AI documentation, audit trail, EU AI Act exposure, and ISO 42001 readiness.

Critical score rules

  • No AI inventory creates shadow AI risk. (maximum score: 65)
  • No AI owner limits accountability and governance. (maximum score: 70)
  • Sensitive data in unapproved AI tools creates data leakage risk. (maximum score: 55)
  • Customer-facing LLM use without prompt injection testing is a major security gap. (maximum score: 60)
  • LLM tools, agents, or RAG without least privilege can create excessive agency risk. (maximum score: 60)

How to use the result

Review the three lowest domains, critical flags, and evidence checklist together. The objective is not to generate a high score; it is to make missing decisions, owners, and evidence visible. When a major customer, audit, regulatory, or incident deadline exists, the self-assessment should be followed by independent validation.

Reference sources