ASanctumBoardsassessments
Sample report. ACME Ltd is a fictional aged-care provider — this is the exact format, depth and traceability a real assessment delivers, populated with illustrative answers.

Professional AI Governance Assessment

ACME Ltd

14 July 2026 · powered by the SanctumBoard Assessment Engine

Residential aged-care provider · Victoria, Australia · assessed with input from the Chair, three non-executive directors, the Company Secretary, the CEO and the CFO

Executive summary

ACME Ltd assessed at 52/100 — Developing. The structures are forming; consistency and evidence are the work now. The assessment identified 3 priority gaps, of which the most consequential is personal information (Data & Privacy). The roadmap below sequences the response over 30 days, 90 days and 12 months, and each recommendation is traced to the instrument that motivates it.

52

overall / 100

Oversight &AccountabilityStrategy &Risk AppetitePolicy &ControlsData &PrivacyVendors &ModelsCulture &Capability

Findings

Oversight & Accountability

47/100

Has the board explicitly assigned accountability for AI oversight (to the board, a committee, or a named director)?

Developing

Evidence noted: Clinical Governance Committee charter amendment drafted March 2026; adoption scheduled for the August board meeting.

Does the board receive a current inventory of where AI is used across the organisation (including embedded AI in vendor products)?

Ad hoc

Evidence noted: IT began a spreadsheet inventory; rostering, clinical-notes summarisation and the falls-prediction module in the nurse-call system are not yet captured.

Commission an AI inventory within 60 days: every system using AI (built, bought or embedded), its owner, purpose, data touched and criticality. Refresh it quarterly to the board.

Does management report to the board on AI initiatives, incidents and risks on a regular cadence?

Developing

Evidence noted: CEO report mentions AI projects ad hoc; no standing section or incident view yet.

Strategy & Risk Appetite

40/100

Has the board set an explicit risk appetite for AI (where AI may and may not be used, and at what level of autonomy)?

Ad hoc

Evidence noted: Verbal position only: 'no AI in clinical decisions without a nurse in the loop' — nothing adopted in writing.

Draft a one-page AI risk-appetite statement: prohibited uses, uses requiring board sign-off, and delegated uses with guardrails. Adopt it by resolution.

Is AI adoption tied to the organisation's strategy with measurable objectives, rather than experiments accumulating bottom-up?

Developing

Evidence noted: Rostering-efficiency pilot has KPIs; other initiatives arrived through vendors without board-visible objectives.

Policy & Controls

52/100

Is there a board-endorsed AI policy governing acceptable use, procurement, development and human oversight of AI?

Developing

Evidence noted: Draft acceptable-use policy with legal for review; procurement and incident-response chapters incomplete.

Are there defined points of human review for consequential AI-influenced decisions (people, money, care, legal rights)?

Managed

Evidence noted: Clinical guardrail operating: RN review required before any AI-suggested care-plan change; overrides logged in the clinical system.

Do AI failures (wrong outputs, bias events, data leaks via AI tools) have a defined incident path that reaches the board when material?

Ad hoc

Evidence noted: General incident procedure exists; AI failure modes and board materiality thresholds not addressed.

Extend the incident procedure to AI failure modes with materiality thresholds for board escalation, and test it with one tabletop scenario this year.

Data & Privacy

38/100

Do you know — and control — what personal information flows into AI tools (including staff use of public chatbots)?

Ad hoc

Evidence noted: Survey found care staff drafting family updates in a public chatbot — resident names included. Interim memo issued; no technical controls yet.

Issue an approved-AI-tools list with clear rules on personal and confidential information, and verify controls (or contractual terms) for each approved tool.

Are people told when AI is used in ways that materially affect them (customers, clients, employees)?

Developing

Evidence noted: Privacy policy updated for the website chatbot; clinical and rostering uses not yet disclosed to residents' families or staff.

Vendors & Models

60/100

Does procurement due diligence ask AI-specific questions (training data, accuracy, data use, incident history) before adopting AI-powered products?

Managed

Evidence noted: AI schedule added to the procurement checklist in February 2026; applied to the new rostering vendor and nurse-call upgrade.

If your systems or services touch people in the EU, have you assessed exposure under the EU AI Act's risk categories?

Not applicable

Evidence noted: No EU residents, services or data flows.

Culture & Capability

72/100

Has the board invested in its own AI literacy (briefings, education, or an advisor) sufficient to ask informed questions?

Managed

Evidence noted: Two board education sessions delivered (AICD facilitator, May 2026); AI added to the skills matrix for the next appointment round.

Are staff trained on safe AI use — what's approved, what's prohibited, and how to raise concerns?

Managed

Evidence noted: Role-based module in the LMS since April; 84% completion; AI added to the speak-up policy examples.

Is AI governance reviewed on a cycle (at least annually) against current regulation, incidents and the changing AI landscape?

Developing

Evidence noted: Intent minuted for an annual review; not yet on the board work plan with an owner.

Applicable legislation, standards & guidance

A Director's Guide to AI Governance (AICD/HTI)AICD / Human Technology Institute (2024)
Voluntary AI Safety Standard (Australia)Voluntary AI Safety Standard (DISR, 2024)
ISO/IEC 42001 — AI management systemsISO/IEC 42001:2023
NIST AI Risk Management FrameworkNIST AI RMF 1.0
Board oversight duty (Caremark, applied to AI)In re Caremark / Delaware case law

Roadmap

30 days

Personal information: Issue an approved-AI-tools list with clear rules on personal and confidential information, and verify controls (or contractual terms) for each approved tool.

90 days

Visibility: Commission an AI inventory within 60 days: every system using AI (built, bought or embedded), its owner, purpose, data touched and criticality. Refresh it quarterly to the board.

Risk appetite: Draft a one-page AI risk-appetite statement: prohibited uses, uses requiring board sign-off, and delegated uses with guardrails. Adopt it by resolution.

Incident response: Extend the incident procedure to AI failure modes with materiality thresholds for board escalation, and test it with one tabletop scenario this year.

12 months

Continuous review: Put AI governance on the annual work plan with a defined owner — or move to continuous monitoring so regulation changes come to you instead of waiting for the review.

Suggested board agenda items

  1. Receive and consider: Personal information in AI tools — current state "Ad hoc", proposed response and owner
  2. Receive and consider: AI inventory — current state "Ad hoc", proposed response and owner
  3. Receive and consider: AI risk-appetite statement — current state "Ad hoc", proposed adoption by resolution
  4. Receive and consider: AI incident response — current state "Ad hoc", proposed response and owner
  5. Adopt: Clinical Governance Committee charter amendment assigning AI oversight

Suggested management actions

  • Issue an approved-AI-tools list with clear rules on personal and confidential information, and verify controls (or contractual terms) for each approved tool.
  • Commission an AI inventory within 60 days: every system using AI (built, bought or embedded), its owner, purpose, data touched and criticality. Refresh it quarterly to the board.
  • Draft a one-page AI risk-appetite statement: prohibited uses, uses requiring board sign-off, and delegated uses with guardrails. Adopt it by resolution.
  • Extend the incident procedure to AI failure modes with materiality thresholds for board escalation, and test it with one tabletop scenario this year.
  • Add a standing AI section to the CEO's board report: new uses, incidents and near-misses, model changes, emerging regulation.

This is what your organisation receives — tailored to you.

Your own report is built from your answers, your jurisdiction and your industry — with your evidence notes kept against each finding, a copy emailed to you, and (for SanctumBoard subscribers) the recommendations delivered as draft actions into your board's approval queue.

This assessment is educational and directional, based on self-reported answers at a point in time. It is not legal advice and not a compliance determination. Citations identify the instruments motivating each recommendation. ACME Ltd and all names herein are fictional.