Self-assessmentTwelve questionsSheet 19

Where are you, actually.

A mirror, not a score.

Twelve questions across the four layers of the MESA Framework, scored against the published five-level maturity model. You get a profile per layer, not a single grade, because a single grade is what lets a strong regulatory posture conceal a substrate that cannot hold it up.

The result appears on this page the moment you finish. There is no form in front of it, and the scoring never leaves your browser.

§ 01How to score it

The instrument only works if you are willing to lose.

Your maturity level is not a score. It is a mirror showing your institutional capacity for truth. An institution that scores against its policy documents produces an aspirational profile and a roadmap that addresses gaps it does not have, while the real ones stay where they are. Three rules govern the correct use of this instrument.

Rule 01
Score operating reality
Not policy claims. The question is what happens on an ordinary Tuesday, not what the document says should happen.
Rule 02
Score down at boundaries
When you sit between two levels, take the lower one. The conservative score is the one you can defend under examination.
Rule 03
Score by triangulation
Have each layer answered by the layer owner and by an independent reviewer. Where the two disagree, the lower score wins.

Twelve questions follow, three for each layer. They are drawn from the sixteen representative questions published in Chapter 4 of the Enterprise Playbook. One of them, on Sharia validation, applies only to Islamic finance institutions and can be marked not applicable; it is then excluded from that layer's average rather than counted against you.

§ 02The instrument

Twelve questions, four layers.

Layer
1

The Regulatory Floor

What are we required to do, in which jurisdictions, under which authorities?

Q01Do you maintain a current, written mapping of every AI system to the jurisdictions and supervisory authorities it is subject to?
Q02For Islamic finance institutions: how is Sharia validation integrated into AI model governance?
Q03How is cross-border handling of AI data governed?
Layer
2

The Strategic Compass

What do we choose to do, given what we are required to do?

Q04Does the board approve a written AI risk appetite statement at least annually?
Q05Is your AI roadmap mapped to the national AI strategies of the jurisdictions you operate in?
Q06Is AI governance treated as a competitive capability or as a compliance cost?
Layer
3

The Operational Machinery

How do we govern the AI systems we have decided to build?

Q07What share of production AI models have current independent validation reports on file?
Q08What share of third-party AI vendors have completed risk classification and due diligence?
Q09Have you rehearsed an AI incident response in the past twelve months?
Layer
4

The Technical Substrate

How do we engineer the systems so the governance is real, not aspirational?

Q10What share of production AI models have active drift monitoring?
Q11Are high-risk models tested against adversarial inputs?
Q12Can you produce a complete decision audit trail, meaning input data, model version, output and explainability artifact, for any production AI decision within twenty-four hours?
0 of 12 answered
§ 03Your profile

Four layers, four readings.

Per-layer scoring averages the question scores within each layer and rounds to the nearest level. The output is a four-element vector, and the vector is the point: the lowest layer is read first, because the layers beneath cap what the layers above can sustain.

Have the interpretation written up

The profile above tells you where you sit. It does not tell you what to do about it in what order, which depends on which layers are lagging and by how much. Give me an address and I will send back a written reading of your profile and a remediation sequence: what to fix first, what it unlocks, and the failure mode to watch for on your next transition. Written by me, not generated.

On its way

Thank you, there. Your profile has reached me and I will send the written reading and the remediation sequence to the address you gave.

If you would rather talk it through, the fit call is thirty minutes and free.

§ 04What this is not

What this page cannot do.

A framework used without knowing its limits is faith rather than diagnosis. The same applies to an instrument, and more sharply to a short one.

It is twelve questions, and the instrument is fifty

These twelve are the representative questions published in Chapter 4, three per layer. The working instrument runs fifty, twelve to thirteen per layer, and it reaches pillars this page does not touch at all: AI data governance under the enterprise classification and lineage controls, closure rates on material validation findings, per-decision explainability for customer-facing systems, residency honoured by architecture rather than by policy. The scoring rubrics and the severity model are not published, and they are what the examination runs on. A short instrument can locate you. It cannot examine you.

It scores your claim, not your evidence

You answered these questions about yourself, which means the profile above is a self-report. That is the honest limit of every self-assessment, and it is why the three rules at the top matter more than the questions do. The examination inverts the burden: every finding traces to a source, and a claim without an artifact behind it does not become a finding. That difference is the whole distance between a profile you can act on privately and a record a board or a supervisor can rely on.

§ 05Questions

What people ask about the assessment.

Is this the fifty-question MESA instrument?

No. This is twelve of the sixteen representative questions published in Chapter 4 of the Enterprise Playbook, three per layer. The full instrument is fifty questions, twelve to thirteen per layer, and it lives in Appendix F. Its scoring rubrics and its severity model are not published, and they are what the Teardown runs on. Treat this page as a way to locate yourself, not as an examination.

Why is maturity scored per layer instead of as one overall grade?

Because institutions rarely climb the four layers in lockstep, and an average across them hides the thing that matters. A Level 1 Technical Substrate caps the Operational Machinery the institution can actually sustain, no matter what the policies say, because the substrate determines what the machinery can enforce. One overall grade would let a strong Regulatory Floor conceal a substrate that cannot support it.

Do you keep my answers?

No. The scoring runs entirely in your browser and no answer is transmitted anywhere. If you ask for the written interpretation, what is sent is your name, your email address, your organisation if you choose to give it, and the four-level profile already displayed on the page. The individual answers are never sent.

What if a question does not apply to us?

One question, on Sharia validation, applies only to Islamic finance institutions and carries a not-applicable option that is excluded from the layer average rather than scored as zero. Every other question is jurisdiction-neutral. If your institution is outside the Middle East, populate the Regulatory Floor with your own supervisory regime, such as OSFI Guideline E-23 for federally regulated Canadian institutions.

What should I do with the result?

Read the lowest layer first. The improvement plan addresses the lowest layers ahead of the highest, because the layers beneath cap what the layers above can sustain. Then check the failure mode named for your next transition, because most institutions that stall at a level stall on the failure mode they did not recognise they were vulnerable to.

How accurate is a self-assessment?

It is as accurate as the honesty you bring to it, which is the point rather than a caveat. Score against operating reality rather than policy claims, score conservatively at boundaries, and have each layer answered by at least two parties with the lower score winning where they disagree. What a self-assessment cannot produce is an evidence-traced record that a board or a supervisor can rely on. That is what the examination is for.

§ 06Next

When locating yourself is not enough.

A profile is useful the moment a board asks where the institution stands and someone can answer without guessing. It stops being enough the moment the answer has to hold up under examination, because at that point the question is no longer where you think you are. It is what you can prove.

The AI Governance Teardown is the examination version: two weeks, fixed scope, fifty questions across the four layers, every finding traced to a source, delivered board-ready with a remediation roadmap. It starts with a free thirty-minute fit call that qualifies the work in both directions.

Fin · Readiness
Start the assessment →