Professional AI Governance Assessment
ACME Ltd
14 July 2026 · powered by the SanctumBoard Assessment Engine
Residential aged-care provider · Victoria, Australia · assessed with input from the Chair, three non-executive directors, the Company Secretary, the CEO and the CFO
Executive summary
ACME Ltd assessed at 52/100 — Developing. The structures are forming; consistency and evidence are the work now. The assessment identified 3 priority gaps, of which the most consequential is personal information (Data & Privacy). The roadmap below sequences the response over 30 days, 90 days and 12 months, and each recommendation is traced to the instrument that motivates it.
52
overall / 100
Findings
Oversight & Accountability
47/100Has the board explicitly assigned accountability for AI oversight (to the board, a committee, or a named director)?
DevelopingEvidence noted: Clinical Governance Committee charter amendment drafted March 2026; adoption scheduled for the August board meeting.
Does the board receive a current inventory of where AI is used across the organisation (including embedded AI in vendor products)?
Ad hocEvidence noted: IT began a spreadsheet inventory; rostering, clinical-notes summarisation and the falls-prediction module in the nurse-call system are not yet captured.
→ Commission an AI inventory within 60 days: every system using AI (built, bought or embedded), its owner, purpose, data touched and criticality. Refresh it quarterly to the board.
Does management report to the board on AI initiatives, incidents and risks on a regular cadence?
DevelopingEvidence noted: CEO report mentions AI projects ad hoc; no standing section or incident view yet.
Strategy & Risk Appetite
40/100Has the board set an explicit risk appetite for AI (where AI may and may not be used, and at what level of autonomy)?
Ad hocEvidence noted: Verbal position only: 'no AI in clinical decisions without a nurse in the loop' — nothing adopted in writing.
→ Draft a one-page AI risk-appetite statement: prohibited uses, uses requiring board sign-off, and delegated uses with guardrails. Adopt it by resolution.
Is AI adoption tied to the organisation's strategy with measurable objectives, rather than experiments accumulating bottom-up?
DevelopingEvidence noted: Rostering-efficiency pilot has KPIs; other initiatives arrived through vendors without board-visible objectives.
Policy & Controls
52/100Is there a board-endorsed AI policy governing acceptable use, procurement, development and human oversight of AI?
DevelopingEvidence noted: Draft acceptable-use policy with legal for review; procurement and incident-response chapters incomplete.
Are there defined points of human review for consequential AI-influenced decisions (people, money, care, legal rights)?
ManagedEvidence noted: Clinical guardrail operating: RN review required before any AI-suggested care-plan change; overrides logged in the clinical system.
Do AI failures (wrong outputs, bias events, data leaks via AI tools) have a defined incident path that reaches the board when material?
Ad hocEvidence noted: General incident procedure exists; AI failure modes and board materiality thresholds not addressed.
→ Extend the incident procedure to AI failure modes with materiality thresholds for board escalation, and test it with one tabletop scenario this year.
Data & Privacy
38/100Do you know — and control — what personal information flows into AI tools (including staff use of public chatbots)?
Ad hocEvidence noted: Survey found care staff drafting family updates in a public chatbot — resident names included. Interim memo issued; no technical controls yet.
→ Issue an approved-AI-tools list with clear rules on personal and confidential information, and verify controls (or contractual terms) for each approved tool.
Are people told when AI is used in ways that materially affect them (customers, clients, employees)?
DevelopingEvidence noted: Privacy policy updated for the website chatbot; clinical and rostering uses not yet disclosed to residents' families or staff.
Vendors & Models
60/100Does procurement due diligence ask AI-specific questions (training data, accuracy, data use, incident history) before adopting AI-powered products?
ManagedEvidence noted: AI schedule added to the procurement checklist in February 2026; applied to the new rostering vendor and nurse-call upgrade.
If your systems or services touch people in the EU, have you assessed exposure under the EU AI Act's risk categories?
Not applicableEvidence noted: No EU residents, services or data flows.
Culture & Capability
72/100Has the board invested in its own AI literacy (briefings, education, or an advisor) sufficient to ask informed questions?
ManagedEvidence noted: Two board education sessions delivered (AICD facilitator, May 2026); AI added to the skills matrix for the next appointment round.
Are staff trained on safe AI use — what's approved, what's prohibited, and how to raise concerns?
ManagedEvidence noted: Role-based module in the LMS since April; 84% completion; AI added to the speak-up policy examples.
Is AI governance reviewed on a cycle (at least annually) against current regulation, incidents and the changing AI landscape?
DevelopingEvidence noted: Intent minuted for an annual review; not yet on the board work plan with an owner.
Applicable legislation, standards & guidance
Roadmap
30 days
Personal information: Issue an approved-AI-tools list with clear rules on personal and confidential information, and verify controls (or contractual terms) for each approved tool.
90 days
Visibility: Commission an AI inventory within 60 days: every system using AI (built, bought or embedded), its owner, purpose, data touched and criticality. Refresh it quarterly to the board.
Risk appetite: Draft a one-page AI risk-appetite statement: prohibited uses, uses requiring board sign-off, and delegated uses with guardrails. Adopt it by resolution.
Incident response: Extend the incident procedure to AI failure modes with materiality thresholds for board escalation, and test it with one tabletop scenario this year.
12 months
Continuous review: Put AI governance on the annual work plan with a defined owner — or move to continuous monitoring so regulation changes come to you instead of waiting for the review.
Suggested board agenda items
- Receive and consider: Personal information in AI tools — current state "Ad hoc", proposed response and owner
- Receive and consider: AI inventory — current state "Ad hoc", proposed response and owner
- Receive and consider: AI risk-appetite statement — current state "Ad hoc", proposed adoption by resolution
- Receive and consider: AI incident response — current state "Ad hoc", proposed response and owner
- Adopt: Clinical Governance Committee charter amendment assigning AI oversight
Suggested management actions
- Issue an approved-AI-tools list with clear rules on personal and confidential information, and verify controls (or contractual terms) for each approved tool.
- Commission an AI inventory within 60 days: every system using AI (built, bought or embedded), its owner, purpose, data touched and criticality. Refresh it quarterly to the board.
- Draft a one-page AI risk-appetite statement: prohibited uses, uses requiring board sign-off, and delegated uses with guardrails. Adopt it by resolution.
- Extend the incident procedure to AI failure modes with materiality thresholds for board escalation, and test it with one tabletop scenario this year.
- Add a standing AI section to the CEO's board report: new uses, incidents and near-misses, model changes, emerging regulation.
This is what your organisation receives — tailored to you.
Your own report is built from your answers, your jurisdiction and your industry — with your evidence notes kept against each finding, a copy emailed to you, and (for SanctumBoard subscribers) the recommendations delivered as draft actions into your board's approval queue.
This assessment is educational and directional, based on self-reported answers at a point in time. It is not legal advice and not a compliance determination. Citations identify the instruments motivating each recommendation. ACME Ltd and all names herein are fictional.