The National AI Governance Playbook · Part V · Chapter 13
The readiness self-assessment and templates
The playbook closes as a toolbox: twenty readiness questions, five one-page templates including the Regime Interface Agreement, and one rule throughout: name the document, owner and date, or record the gap.
Evidence basis: MindXO design recommendation. A MindXO implementation tool for applying the method and recording gaps.
By Myriam Ayada · MindXO · Version 1.1 · Updated 21 July 2026
In brief
The self-assessment applies one rule: each question is answered by a named document with an owner and date, or recorded as a gap. Five templates carry the work: function map, chain walk, Regime Interface Agreement, design-phase mandate and scorecard skeleton. The twenty questions explicitly test reusable technical evidence, contextual deployment assurance and separation of evaluation, accreditation, assurance delivery and enforcement.
From chapters to working documents
Twelve chapters have made one argument: national AI governance is designed rather than accumulated, the design turns on a small number of decisions, and every decision that holds leaves a document behind. This closing chapter converts the argument into a working session. The self-assessment below runs in half a day, provided the right people are in the room and the right papers are on the table.
The room is small. It holds the design owner of Chapter 9, one voice for each entity expected to deliver a function, one for the evaluation capability of Chapter 10 or its nearest precursor, and a secretariat that writes while the others talk. What comes in: the program portfolio, and the instruments in force, from the strategy to the newest rulebook. What goes out: a scored assessment, twenty questions each resolved under the rule below, and a gap list ordered by the chapter that treats it. Everything else the session produces is conversation, and the secretariat is under no obligation to keep it.
The named-document rule
The assessment runs on a single discipline, inherited from the measurement design of Chapter 12: no maturity scales, no self-rated fives. A question is answered in one of two ways. Either the room names a document, together with the owner who maintains it and the date it last changed, or the room records a gap. Partial credit does not exist, and neither does a promising draft.
The rule converts opinion into an inventory. Asked whether the two regimes are distinct, a room will discuss; asked which document draws the distinction in writing, the room either produces a title or writes down a gap. The discipline is the auditor's: a certification audit under ISO/IEC 42001 reads documented information rather than assurances, and the assessment borrows the habit. Twenty answers gathered this way are comparable from one run to the next, which is what turns a self-assessment into a measurement.
The twenty questions
The twenty questions follow the spine of the book, five groups of four, each group tagged to the chapters it draws on. Group A begins where most strategies begin, with declared principles, commonly adopted from the OECD AI Principles, and ends at the chain that carries them. The numbering runs continuously so that a score has a denominator: a full run yields twenty entries, each one a named document or a recorded gap.
Group A. Functions and regimes (Chapters 3 to 5)
- Which document maps the program portfolio against the four functions?
- Where are evaluation, accreditation, assurance delivery and enforcement assigned to named owners with conflicts controlled?
- Which Regime Interface Agreement states reusable technical evidence, added contextual evidence, request rights and escalation?
- Can the chain be walked from each declared principle to a control, in both directions?
Group B. The five questions (Chapter 6)
- Where is each of the five design questions answered with a dated decision record?
- Which entity holds the coherence frame?
- Which decisions were answered by default rather than by record?
- What has changed since the records were written?
Group C. Instruments and sequencing (Chapters 7 and 8)
- Which binding instrument carries the design, and what does it leave unbound?
- Which obligations are staged, and what switches each on?
- Which sector leads wave one, and against which criteria?
- What holds the design between now and the instrument's adoption?
Group D. Capability and security (Chapters 10 and 11)
- What horizontal evaluation and accreditation capability exists or is funded, and what reusable evidence does it produce?
- Which sectoral rulebooks define contextual assurance requirements and qualified providers for deployed systems?
- Which existing mandates were extended for the three critical-infrastructure exposures?
- Where does an AI incident report today, and how many times?
Group E. Measurement and handover (Chapters 9 and 12)
- Who owns the design phase, and when does it end?
- What transfers at handover, and to whom?
- Which scorecard exists, with which owners and cadences?
- What was published last year, and what will be published next?
The five templates
Five exercises recur through the book. Each is a one-page document a team fills rather than reads, and a completed copy is the natural answer to several readiness questions.
T1. The function map (Chapter 3)
The one-page grid of Chapter 3: programs as rows, the four functions as columns, each claim entered in the program's own words. Overlaps appear as functions claimed by several programs, gaps as functions claimed by none. A filled copy answers question 1.
T2. The chain walk (Chapter 5)
One declared principle traced down the six links of Chapter 5 to a control, then back up, with the instrument, the owner and the date recorded at each link. A break is recorded wherever the next document cannot be named. One walk per principle is the full exercise; a single walk is enough to begin.
T3. The Regime Interface Agreement (Chapter 4)
Records horizontal evidence supplied, contextual evidence required, triggers and request rights, disclosure and confidentiality, escalation and incidents, ownership and review cadence.
T4. The design-phase mandate (Chapter 9)
The one-page mandate of Chapter 9: the owner, the reporting line, the end date, the handover clause, and the decisions the phase must return. It is filled once, signed, and cited thereafter; its end date is the answer to question 17.
T5. The scorecard skeleton (Chapter 12)
The three layers of Chapter 12, milestones, operation and outcomes, as an empty grid: one row per indicator, with an owner, a cadence and a first reporting date. An indicator that cannot attract an owner returns to the gap list.
Sheet 13 of 13: five question groups feed one gap list. Five templates dock below: function map, chain walk, Regime Interface Agreement, design-phase mandate and scorecard skeleton. One rule applies throughout: a named document or a recorded gap.
Running it, and running it again
The assessment is a cadence rather than an event. The first run feeds the design stage of Chapter 2: the gap list, ordered by chapter, is a workplan the design owner can accept or amend on the day it is produced. Subsequent runs read against the scorecard of Chapter 12. Twice a year is common, and the rhythm matches the periodic profile reviews organisations run under the NIST AI Risk Management Framework. The score that matters is the trend: questions that moved from gap to named document, and gaps opened at one run and closed by the next.
A first run produces a snapshot, and a second produces a direction because every named document carries a checkable date. Subscribers receive the PDF edition and five fillable templates when released, with later revisions dated by version.
Common failure mode. The assessment as ceremony. Run once before a summit, scored generously, filed. The pattern is common because a first run is usually commissioned for an occasion, and an occasion rewards a good score. The protections are structural: the named-document rule leaves little room for generosity, a fixed cadence removes the occasion, and publication of the milestone trend (Chapter 12) makes a generous score visible at the second run, when the documents it claimed fail to appear.
The playbook ends where a design stage begins: with a portfolio mapped, a chain walked, five questions answered on the record, a capability funded, and a scorecard that will say, in a year, whether any of it moved. The gap list is the starting brief.
Three questions for every government
- When was the self-assessment last run, and what share of the twenty questions ended in a named document?
- Which gaps were opened at the previous run and closed since?
- Who owns the next run, and on which date?
Selected public sources
- ISO/IEC 42001, AI management systems, ISO/IEC, 2023
- AI Risk Management Framework and Generative AI Profile, NIST, 2023 and 2024
- OECD AI Principles, OECD, 2019, updated 2024