Is Your Organisation Built to Govern AI Agents, Not Just Deploy AI?
An agent may cross process, system and departmental boundaries. No single executive, technology team or risk function can see every condition that decides whether it will create value responsibly.
Answer 92 questions across thirteen domains for an indicative readiness result on screen, with a score for each domain and a prioritised set of actions. The questions establish what is known, what is evidenced, who is accountable, and which processes should be examined next. One informed person can produce a baseline. The result is strongest when strategy, operations, technology, security, risk and HR each answer the domains they own.
Readiness is distributed across the organisation.
Executives understand purpose, appetite and investment. Process owners and front-line teams understand how work actually happens. Technology, data and security leaders understand access and dependency. Legal, compliance, risk and audit understand obligations and assurance. HR and change leaders understand whether people can exercise meaningful oversight.
The discovery is designed to expose the differences between these perspectives. An unsupported "yes", an honest "not known" and a disagreement between functions are not equivalent answers. Each one reveals a different action.
The same foundations decide value. KPMG's 2026 Global AI Pulse found the strongest outcomes were associated not with deploying more AI, but with capabilities such as accountability, governance and cost visibility. McKinsey found that organisations with explicit ownership for responsible AI reached materially higher maturity than those without a clearly accountable function.
KPMG, Global AI Pulse Q2 2026. McKinsey, State of AI Trust in 2026.
Treat a one-person result as provisional until the functions that own each domain have confirmed it.
Combine authority, expertise and operational reality.
Include both decision-makers and people close to the work. Senior leaders can define the intended operating model. Operational participants reveal the exceptions, workarounds, tacit knowledge and dependencies that safe agent behaviour depends on.
| Perspective | Typical participants | Contribution |
|---|---|---|
| Executive direction | Sponsor, COO, CIO, CTO or business-unit leader | Outcomes, funding, acceptable authority and decisions |
| Process and operations | Process owners, operational leaders, process excellence | Actual work, exceptions, dependencies and performance |
| Technology, data and AI | Architecture, IT, integration, data and AI leaders | Feasibility, information, platforms and observability |
| Security and identity | Security, IAM and resilience leaders | Non-human identity, permissions, threats and containment |
| Governance and assurance | Risk, legal, privacy, compliance and internal audit | Obligations, challenge, controls and evidence |
| People and organisation | HR, workforce, learning and change | Roles, capacity, consultation, skills and oversight |
| Commercial ecosystem | Finance, procurement and supplier management | Economics, contracts, concentration and exit |
| Front-line knowledge | Managers, subject-matter experts and users | Workarounds, tacit knowledge and real consequences |
Answer the domains you can, mark the rest not known.
Answer against the organisation as it operates today. A "not known" is a finding: it means the condition is not visible in a form the organisation can rely on. Your result appears as soon as you finish, and a copy is emailed to you.
About this assessment. This initial assessment provides indicative guidance based solely on the information supplied by the participant. It does not constitute an independently validated assessment, certification, assurance, legal advice or confirmation that an organisation, process or technology is ready for deployment. Your report will explain the apparent strengths, constraints and information gaps identified from your responses. Greater confidence may require input from other stakeholders, supporting evidence and facilitated review by IGX Solutions. The assessment and resulting report are licensed for your organisation's internal use only. The questions, assessment structure and methodology remain the intellectual property of IGX Solutions Ltd.
Loading the assessment.
How useful was this assessment?
Thank you. This goes straight into the next revision of the assessment.
Run it as a working session with the full team.
The online result is an indicative baseline. To turn it into decisions, work through the same domains with the people who own them and capture the following alongside each answer.
-
Set the scope
Agree whether the review covers the whole organisation, a business unit, a geography or a named agentic AI programme. Record the intended outcomes and the kinds of action agents may eventually perform.
-
Assign domain leads
Give each of the thirteen domains an accountable lead who can gather evidence and involve the right specialists. Accountability should not default to IT because AI is involved.
-
Gather evidence before concluding
Use current strategies, policies, process documentation, architecture, data records, risk assessments, audit findings, incident data, workforce plans and performance measures. Record "not known" where evidence does not exist.
-
Review answers together
Use the questions to surface disagreement as well as gaps. Different answers from operations, IT, risk and executives are themselves a readiness finding.
-
Convert findings into decisions
Identify missing evidence, required controls, capability gaps, accountable owners and candidate processes for screening. Prioritise by value, exposure and dependency, not by how easy a gap is to close.
-
Reassess as authority expands
Readiness changes as processes, regulation, technology and agent authority change. Repeat the review at agreed milestones and before agents take materially different actions.
Capture with every answer
- A response: yes, partly, no, not applicable or not known.
- The evidence supporting the response.
- The accountable owner.
- Confidence in the conclusion: high, medium or low.
- The required action, its priority, its dependency and a target date.
An honest "no" or "not known" is more valuable than an unsupported "mostly". The objective is not to appear ready. It is to understand what responsible progress requires.
The organisational conditions around agent action.
Each domain carries equal weight in the result. The assessment asks between six and eight questions in each, against the organisation as it operates today.
- 1
Strategy, Purpose and Value
Establish why the organisation is considering agentic AI, which outcomes matter, and how strategic choices will be governed.
- 2
Governance Operating Model and Accountability
Establish who can decide, approve, challenge, operate, suspend and retire agentic systems.
- 3
Use-Case Portfolio and Risk Classification
Select agentic use cases deliberately and apply controls proportionate to consequence.
- 4
Process and Operating-Model Readiness
Understand the work agents may enter and avoid scaling unclear or ineffective processes.
- 5
Data, Knowledge, Context and Memory
Ensure agents receive appropriate information and do not create uncontrolled information risks.
- 6
Technology Architecture and Integration
Provide a supportable architecture matched to agent workload, impact and dependency.
- 7
Security, Agent Identity and Access
Control agents as non-human actors capable of using tools and delegated permissions.
- 8
Agent Design, Authority and Human Sovereignty
Define what agents may pursue and do, where people retain authority, and how delegation stays bounded.
- 9
Testing, Evaluation and Independent Assurance
Establish evidence that the complete agentic system behaves acceptably before and after release.
- 10
Operational Control, Monitoring, Incident Response and Resilience
Operate agents visibly, and contain, recover from and learn from failure.
- 11
Legal, Regulatory, Ethical and Affected-Person Rights
Translate obligations and legitimate expectations into effective agent constraints and remedies.
- 12
Workforce, Organisation and Change
Prepare the people who design, supervise, work with and are affected by agents.
- 13
Third Parties, Economics and Lifecycle Roadmap
Understand external dependencies, true economics, and the path from adoption to retirement.
A foundation for decisions, not a document that sits on a shelf.
A process can look technically suitable while organisational ownership or governance remains insufficient. Strong enterprise governance does not make every process ready. This is the context that makes the screening meaningful.
- A shared organisational context supported by evidence.
- A disagreement and unknowns register.
- An agent and use-case inventory.
- Clear decision rights and accountable owners.
- Initial prohibited, restricted and higher-risk areas.
- Cross-cutting organisational actions.
- Candidate processes for Process and Use-Case Screening.
- A baseline that can be refreshed after material change.
Designed with reference to recognised frameworks.
The discovery reflects organisational and lifecycle concepts from the NIST AI Risk Management Framework and ISO/IEC 42001, risk, transparency and human-oversight concepts relevant to the EU AI Act, and agent-specific control areas identified by OWASP. These sources give credible foundations, but no framework can answer the questions for your organisation. That takes evidence from the people who own, operate, govern and experience the work.
IGX360 independently developed this discovery. It is not certification, assurance, legal advice or endorsement by the referenced organisations.
Move from organisational context to a defined use case.
Once the team can identify a process, an intended outcome, a proposed agent role and its principal actions, use the Process and Use-Case Screening. It determines whether the idea should be clarified, stopped, strengthened or progressed to a detailed assessment.
The Organisational Readiness Discovery provides a structured basis for internal discovery and discussion. It does not constitute legal, regulatory, security or technical advice, certification, assurance, or authorisation to deploy an AI system. Obtain appropriate specialist advice and assurance for the use case, sector and jurisdictions involved.