The full instrument. Fifty questions, twelve to thirteen per layer, each with the five-level rubric it is scored against. The shorter twelve-question readiness assessment locates you; this one examines the estate.
It is not a quiz. It is a structured honesty instrument, and three rules matter more than the questions. Score against operating reality, not policy claims. Score conservatively at boundaries, meaning the level you could defend under examination rather than the one you could describe in a leadership memo. And score by triangulation: each layer answered by the layer owner and an independent reviewer, and where they disagree the lower score wins, because the disagreement is the finding.
Scoring runs entirely in your browser. Nothing is transmitted, nothing is stored, and there is no sign-up, so there is nothing to unsubscribe from later.
L1 Regulatory Floor · L2 Strategic Compass · L3 Operational Machinery · L4 Technical Substrate
The Self-Assessment produces three artifacts: a per-question score, a per-layer score, and a four-element profile vector. The methodology is deliberately simple because the discipline lives in the three rules, not in the arithmetic.
Each question is scored Level 1 through Level 5 against the rubric provided. The score is the lowest level the institution can defend under examination by the rules above. Where the institution sits between two levels (the policy describes Level 4 behavior, the operating reality reflects Level 3), the lower level is recorded. Where others see a scoring rubric, I see a contract the institution writes with itself about which version of its own story it is willing to defend.
Per-layer scores are the arithmetic mean of the question scores within that layer, rounded to the nearest integer. Half-points round down rather than up. This rounding rule is deliberate. The institution that earns a 3.5 has not yet earned Level 4. It has reached the boundary where Level 4 becomes achievable with sustained discipline. The rounding pulls the institution back to the level it can presently defend.
The four per-layer scores form a profile vector of the form (L1, L2, L3, L4). A typical pattern observed across MENA financial-services institutions in the 2024 through 2026 period is (L1: 3, L2: 2, L3: 2, L4: 1). The vector is the institution's MESA fingerprint. It identifies which layer is the binding constraint and therefore which chapter discipline the institution must build first.
Each layer's questions are answered by at least two parties. The layer owner produces a first draft. An independent reviewer drawn from internal audit, risk, or an external assessor produces a second. Where the two parties agree, the score is the agreed score. Where they disagree, the lower score wins and the disagreement is recorded as a finding for the AI Governance Committee. The disagreement is the most valuable output of the Self-Assessment. It surfaces the conversations the institution had been avoiding.
At each level boundary, the conservative reading wins. Level 3 requires the discipline to be operational and reviewed. Level 4 requires it to be measured. The institution that has dashboards but does not act on the readings is at Level 3, not Level 4. The institution that has policies but does not follow them is at Level 1, not Level 2.
The full Self-Assessment is re-administered annually. Layer 3 questions are re-administered quarterly because Layer 3 is the layer that moves fastest. Layer 1 questions are re-administered at any material regulatory event (new framework, amended guidance, jurisdictional expansion). The annual re-assessment produces a year-over-year delta the board reads as the program's signal.
The profile vector maps directly to a chapter reading prioritization. The lowest layer is read first because the lowest layer caps everything above it. Within Layer 3, the lowest pillar is read first because the pillars depend on each other in a documented order: data governance is the substrate, MRM the discipline, vendor risk the perimeter, incident response the recovery mechanism, the operating model the cadence, the governance office the staffing.
The reading list is generated by the following logic.
A Level 1 in Layer 4 directs the reader to Chapters 9 (data architecture) and 12 (MRM technical substrate) first, because Layer 4 is the substrate every other layer rests on. A Level 1 in Layer 3 directs the reader to Chapters 12 (MRM) and 13 (data governance) first, because these are the upstream pillars. A Level 1 in Layer 1 directs the reader to Chapters 5 through 8 (the jurisdictional chapters) first, because the regulatory perimeter is the perimeter against which everything else is judged.
The recurring profile vectors map to recurring reading lists.
The regulator-driven profile (3, 2, 2, 1) has Layer 1 strongest because supervisors have been asking direct questions, and the other layers lag because they are not yet under examination pressure. The reading priority is Chapters 9 and 12 first to address Layer 4, then Chapters 13 through 15 to lift Layer 3, then Chapter 10 to integrate the operating model, then Chapter 4 to anchor the program at Layer 2.
The vendor-driven profile (2, 2, 3, 2) has stronger Layer 3 vendor risk because the institution moved through a major vendor transformation. The other Layer 3 pillars lag. The reading priority is Chapters 12 and 13 to strengthen the upstream pillars vendor risk depends on, then Chapter 15 to complete the incident response perimeter, then Chapters 5 through 8 to firm up Layer 1, then Chapter 4 to re-anchor at Layer 2.
The fintech profile (2, 3, 1, 3) has strong Layer 2 (AI is the business model) and strong Layer 4 (the technical substrate is the business) but a weak Layer 3 (the operational machinery has not been built at scale). The reading priority is Chapters 10 and 11 to build the operating model and governance office, then Chapters 12 through 15 to install the Layer 3 disciplines, then Chapters 5 through 8 to confirm jurisdictional coverage.
The reading list is not a syllabus. It is a sequenced intervention. Reading Chapter 4 before reading Chapter 12 produces a strategic frame without operational substance. Reading Chapter 12 before reading Chapter 13 produces an MRM function operating on ungoverned data. The sequence matters because the dependencies matter.
The output the Self-Assessment generates for each institution is a single page with three elements: the profile vector, the prioritized chapter reading list with target completion dates, and the recommended 18-to-24-month MESA roadmap calibrated to the institution's profile per Chapter 4's phase definitions. The page is the institution's working document for the next twelve months. It is reviewed quarterly at the AI Governance Committee and re-baselined annually at the full re-assessment.
This companion appendix is licensed CC BY-NC-ND 4.0, Attribution-NonCommercial-NoDerivatives: share it with credit to the author, but not for commercial use and not as a modified version. The book itself and the named frameworks (the MESA Framework, the Five-Gate Deployment Model, the AI Incident Response Protocol and the others) are © 2026 Nabeel Khan, all rights reserved.
The lowest layer is the one that caps the rest.