Where are you, actually.
A free AI governance readiness assessment: twelve questions across the four layers of the MESA Framework, scored against the published five-level maturity model. You get a profile per layer, not a single grade, because a single grade is what lets a strong regulatory posture conceal a substrate that cannot hold it up.
It is free, and free without the usual conditions. No sign-up, no email, no demo booking. The result appears on this page the moment you finish, there is no form in front of it, and the scoring never leaves your browser.
The instrument only works if you are willing to lose.
Your maturity level is not a score. It is a mirror showing your institutional capacity for truth. An institution that scores against its policy documents produces an aspirational profile and a roadmap that addresses gaps it does not have, while the real ones stay where they are. Three rules govern the correct use of this instrument.
Twelve questions follow, three for each layer. They are drawn from the sixteen representative questions published in Chapter 4 of the Enterprise Playbook. One of them, on Sharia validation, applies only to Islamic finance institutions and can be marked not applicable; it is then excluded from that layer's average rather than counted against you.
Twelve questions, four layers.
Four layers, four readings.
Per-layer scoring averages the question scores within each layer and rounds to the nearest level. The output is a four-element vector, and the vector is the point: the lowest layer is read first, because the layers beneath cap what the layers above can sustain.
On its way
Thank you, there. Your profile has reached me and I will send the written reading and the remediation sequence to the address you gave.
If you would rather talk it through, the fit call is thirty minutes and free.
What this page cannot do.
A framework used without knowing its limits is faith rather than diagnosis. The same applies to an instrument, and more sharply to a short one.
It is twelve questions, and the instrument is fifty
These twelve are the representative questions published in Chapter 4, three per layer. The working instrument runs fifty, twelve to thirteen per layer, and it reaches pillars this page does not touch at all: AI data governance under the enterprise classification and lineage controls, closure rates on material validation findings, per-decision explainability for customer-facing systems, residency honoured by architecture rather than by policy. All fifty are published at the companion portal, each with its five-level scoring rubric. What stays unpublished is the severity model, the weighting that turns fifty individual scores into a ranked remediation sequence, and that is what the examination runs on. A short instrument can locate you. It cannot examine you.
It scores your claim, not your evidence
You answered these questions about yourself, which means the profile above is a self-report. That is the honest limit of every self-assessment, and it is why the three rules at the top matter more than the questions do. The examination inverts the burden: every finding traces to a source, and a claim without an artifact behind it does not become a finding. That difference is the whole distance between a profile you can act on privately and a record a board or a supervisor can rely on.
What people ask about the assessment.
Is this AI governance readiness assessment really free?
Yes, and free without the usual conditions. There is no sign-up, no email requirement, no demo booking and no trial that expires. The twelve questions are scored in your browser and the per-layer profile appears on the page the moment you finish, so nothing is transmitted and there is nothing to unsubscribe from later. The only optional step is asking for a written interpretation, which needs an email address because a reply has to go somewhere. The reason it is free is that a self-assessment is a self-locating aid rather than an engagement: it tells an institution roughly where it stands, and whether a proper examination is worth commissioning.
Is this the fifty-question MESA instrument?
No. This is twelve of the sixteen representative questions published in Chapter 4 of the Enterprise Playbook, three per layer. The full instrument is fifty questions, and every one of them now carries its five-level scoring rubric at the companion portal. What stays unpublished is the severity model, the weighting that turns fifty individual scores into a ranked remediation sequence. That is what the Teardown runs on. Treat this page as a way to locate yourself, not as an examination.
Why is maturity scored per layer instead of as one overall grade?
Because institutions rarely climb the four layers in lockstep, and an average across them hides the thing that matters. A Level 1 Technical Substrate caps the Operational Machinery the institution can actually sustain, no matter what the policies say, because the substrate determines what the machinery can enforce. One overall grade would let a strong Regulatory Floor conceal a substrate that cannot support it.
Do you keep my answers?
No. The scoring runs entirely in your browser and no answer is transmitted anywhere. If you ask for the written interpretation, what is sent is your name, your email address, your organisation if you choose to give it, and the four-level profile already displayed on the page. The individual answers are never sent.
What if a question does not apply to us?
One question, on Sharia validation, applies only to Islamic finance institutions and carries a not-applicable option that is excluded from the layer average rather than scored as zero. Every other question is jurisdiction-neutral. If your institution is outside the Middle East, populate the Regulatory Floor with your own supervisory regime, such as OSFI Guideline E-23 for federally regulated Canadian institutions.
What should I do with the result?
Read the lowest layer first. The improvement plan addresses the lowest layers ahead of the highest, because the layers beneath cap what the layers above can sustain. Then check the failure mode named for your next transition, because most institutions that stall at a level stall on the failure mode they did not recognise they were vulnerable to.
How accurate is a self-assessment?
It is as accurate as the honesty you bring to it, which is the point rather than a caveat. Score against operating reality rather than policy claims, score conservatively at boundaries, and have each layer answered by at least two parties with the lower score winning where they disagree. What a self-assessment cannot produce is an evidence-traced record that a board or a supervisor can rely on. That is what the examination is for.
When locating yourself is not enough.
A profile is useful the moment a board asks where the institution stands and someone can answer without guessing. It stops being enough the moment the answer has to hold up under examination, because at that point the question is no longer where you think you are. It is what you can prove.
The AI Governance Teardown is the examination version: two weeks, fixed scope, fifty questions across the four layers, every finding traced to a source, delivered board-ready with a remediation roadmap. It starts with a free thirty-minute fit call that qualifies the work in both directions.
Ask your AI assistant instead.
This page is a snapshot, accurate at the release it cites. The same corpus is callable, publicly and without a key, so an assistant can query it live and return an answer carrying the source it came from. For this page that is start_assessment and score_assessment, which run the same 50-question MESA self-assessment this page describes, and return a scored result with the weakest layer named. The output states in its own text that it is a self-assessment and not an audit.
claude mcp add --transport http concylium https://mcp.nabeelkhan.com/api/mcp
Claude Desktop, ChatGPT, Cursor, VS Code and Gemini CLI take the endpoint on its own: https://mcp.nabeelkhan.com/api/mcp. No key, no account, nothing to sign. Setup for every client.
“Run the MESA self-assessment from Concylium against my organisation. Ask me the questions one layer at a time, then score it and tell me the weakest control.”
Fifty published questions, each with its five-level rubric. The score is preliminary and says so in its own output.