The MESA Self-Assessment
The full instrument. Fifty questions, twelve to thirteen per layer, each with the five-level rubric it is scored against. The shorter twelve-question readiness assessment locates you; this one examines the estate.
It is not a quiz. It is a structured honesty instrument, and three rules matter more than the questions. Score against operating reality, not policy claims. Score conservatively at boundaries, meaning the level you could defend under examination rather than the one you could describe in a leadership memo. And score by triangulation: each layer answered by the layer owner and an independent reviewer, and where they disagree the lower score wins, because the disagreement is the finding.
Scoring runs entirely in your browser. Nothing is transmitted, nothing is stored, and there is no sign-up, so there is nothing to unsubscribe from later.
Fifty questions, four layers.
Your MESA profile vector
L1 Regulatory Floor · L2 Strategic Compass · L3 Operational Machinery · L4 Technical Substrate
How the score is produced.
Scoring Methodology
The Self-Assessment produces three artifacts: a per-question score, a per-layer score, and a four-element profile vector. The methodology is deliberately simple because the discipline lives in the three rules, not in the arithmetic.
Per-Question Scoring
Each question is scored Level 1 through Level 5 against the rubric provided. The score is the lowest level the institution can defend under examination by the rules above. Where the institution sits between two levels (the policy describes Level 4 behavior, the operating reality reflects Level 3), the lower level is recorded. Where others see a scoring rubric, I see a contract the institution writes with itself about which version of its own story it is willing to defend.
Per-Layer Scoring
Per-layer scores are the arithmetic mean of the question scores within that layer, rounded to the nearest integer. Half-points round down rather than up. This rounding rule is deliberate. The institution that earns a 3.5 has not yet earned Level 4. It has reached the boundary where Level 4 becomes achievable with sustained discipline. The rounding pulls the institution back to the level it can presently defend.
The Profile Vector
The four per-layer scores form a profile vector of the form (L1, L2, L3, L4). A typical pattern observed across MENA financial-services institutions in the 2024 through 2026 period is (L1: 3, L2: 2, L3: 2, L4: 1). The vector is the institution's MESA fingerprint. It identifies which layer is the binding constraint and therefore which chapter discipline the institution must build first.
Triangulation and Independent Review
Each layer's questions are answered by at least two parties. The layer owner produces a first draft. An independent reviewer drawn from internal audit, risk, or an external assessor produces a second. Where the two parties agree, the score is the agreed score. Where they disagree, the lower score wins and the disagreement is recorded as a finding for the AI Governance Committee. The disagreement is the most valuable output of the Self-Assessment. It surfaces the conversations the institution had been avoiding.
Boundary Discipline
At each level boundary, the conservative reading wins. Level 3 requires the discipline to be operational and reviewed. Level 4 requires it to be measured. The institution that has dashboards but does not act on the readings is at Level 3, not Level 4. The institution that has policies but does not follow them is at Level 1, not Level 2.
Re-Assessment Cadence
The full Self-Assessment is re-administered annually. Layer 3 questions are re-administered quarterly because Layer 3 is the layer that moves fastest. Layer 1 questions are re-administered at any material regulatory event (new framework, amended guidance, jurisdictional expansion). The annual re-assessment produces a year-over-year delta the board reads as the program's signal.
Profile-to-Reading-List Output
The profile vector maps directly to a chapter reading prioritization. The lowest layer is read first because the lowest layer caps everything above it. Within Layer 3, the lowest pillar is read first because the pillars depend on each other in a documented order: data governance is the substrate, MRM the discipline, vendor risk the perimeter, incident response the recovery mechanism, the operating model the cadence, the governance office the staffing.
The reading list is generated by the following logic.
A Level 1 in Layer 4 directs the reader to Chapters 9 (data architecture) and 12 (MRM technical substrate) first, because Layer 4 is the substrate every other layer rests on. A Level 1 in Layer 3 directs the reader to Chapters 12 (MRM) and 13 (data governance) first, because these are the upstream pillars. A Level 1 in Layer 1 directs the reader to Chapters 5 through 8 (the jurisdictional chapters) first, because the regulatory perimeter is the perimeter against which everything else is judged.
The recurring profile vectors map to recurring reading lists.
The regulator-driven profile (3, 2, 2, 1) has Layer 1 strongest because supervisors have been asking direct questions, and the other layers lag because they are not yet under examination pressure. The reading priority is Chapters 9 and 12 first to address Layer 4, then Chapters 13 through 15 to lift Layer 3, then Chapter 10 to integrate the operating model, then Chapter 4 to anchor the program at Layer 2.
The vendor-driven profile (2, 2, 3, 2) has stronger Layer 3 vendor risk because the institution moved through a major vendor transformation. The other Layer 3 pillars lag. The reading priority is Chapters 12 and 13 to strengthen the upstream pillars vendor risk depends on, then Chapter 15 to complete the incident response perimeter, then Chapters 5 through 8 to firm up Layer 1, then Chapter 4 to re-anchor at Layer 2.
The fintech profile (2, 3, 1, 3) has strong Layer 2 (AI is the business model) and strong Layer 4 (the technical substrate is the business) but a weak Layer 3 (the operational machinery has not been built at scale). The reading priority is Chapters 10 and 11 to build the operating model and governance office, then Chapters 12 through 15 to install the Layer 3 disciplines, then Chapters 5 through 8 to confirm jurisdictional coverage.
The reading list is not a syllabus. It is a sequenced intervention. Reading Chapter 4 before reading Chapter 12 produces a strategic frame without operational substance. Reading Chapter 12 before reading Chapter 13 produces an MRM function operating on ungoverned data. The sequence matters because the dependencies matter.
The output the Self-Assessment generates for each institution is a single page with three elements: the profile vector, the prioritized chapter reading list with target completion dates, and the recommended 18-to-24-month MESA roadmap calibrated to the institution's profile per Chapter 4's phase definitions. The page is the institution's working document for the next twelve months. It is reviewed quarterly at the AI Governance Committee and re-baselined annually at the full re-assessment.
This companion appendix is licensed CC BY-NC-ND 4.0, Attribution-NonCommercial-NoDerivatives: share it with credit to the author, but not for commercial use and not as a modified version. The book itself and the named frameworks (the MESA Framework, the Five-Gate Deployment Model, the AI Incident Response Protocol and the others) are © 2026 Nabeel Khan, all rights reserved. The editable working files are different. Anything on this page you are meant to complete rather than read carries the Companion Working Files Licence 1.0 instead: use it, adapt it and complete it inside your own organisation, including commercially. NoDerivatives does not apply to it, because a completed template is a modified version and forbidding that would forbid the point.
What this self-assessment does not claim.
Read this before you rely on it
- It is a self-report. You answered these questions about your own institution, which is the honest limit of every self-assessment and the reason the three rules matter more than the questions do.
- A profile is a locating aid. It is not an examination, and it is not a record a board or a supervisor can rely on, because nothing here traces a claim to an artifact.
- Per-layer scores are arithmetic means with half-points rounded down. That rounding is deliberate and conservative, and it means a strong layer average can still sit a level below where a charitable reading would put it.
- The Sharia validation question is excluded from its layer average when marked not applicable, rather than counted against a conventional institution.
- Scoring is client-side. Nothing is transmitted and nothing is stored, which also means nothing is saved when you close the tab.
- This is reference material and advisory practice. It is not legal advice, and it does not substitute for your counsel or your regulator relationship.
The lowest layer is the one that caps the rest.
Ask your AI assistant instead.
This page is a snapshot, accurate at the release it cites. The same corpus is callable, publicly and without a key, so an assistant can query it live and return an answer carrying the source it came from. For this page that is start_assessment and score_assessment, which run the same 50-question MESA self-assessment this page describes, and return a scored result with the weakest layer named. The output states in its own text that it is a self-assessment and not an audit.
claude mcp add --transport http concylium https://mcp.nabeelkhan.com/api/mcp
Claude Desktop, ChatGPT, Cursor, VS Code and Gemini CLI take the endpoint on its own: https://mcp.nabeelkhan.com/api/mcp. No key, no account, nothing to sign. Setup for every client.
“Run the MESA self-assessment from Concylium against my organisation. Ask me the questions one layer at a time, then score it and tell me the weakest control.”
Fifty published questions, each with its five-level rubric. The score is preliminary and says so in its own output.