- Input
- Output
- Reviewable evidence
- Limitation
Methodology version 1.0 · 27 August 2026
Trace every governance conclusion back to evidence.
This public methodology explains how AI Governance Hub validates work-item exports, identifies AI-related records, assigns risk signals, aggregates a portfolio score and frames human review. It is designed for procurement, internal audit, model risk, security and governance teams evaluating the assessment.
Explainable assessment pipeline
Six stages from export to review
Select a stage to inspect what it consumes, what it produces, what evidence remains reviewable and what the stage cannot prove.
AI governance assessment tool: a worked example
Suppose an export contains 100 work items: 20 are identified as AI candidates, 10 are high risk and 5 are medium risk. Using the portfolio formula below, the score is 100 − 4 − 4 − 10 = 82 (Good). This fictional example illustrates the calculation; it is not a customer benchmark or evidence of effective controls.
A reviewer should still inspect the 10 high-risk records, confirm owners and evidence, and investigate missing fields. A high score cannot establish that an export includes every AI system.
Choose a sample export · Explore a report example · Start a free assessment preview
One-time assessment or ongoing Jira governance?
The website assessment analyzes a work-item export. The separate Jira Cloud governance app supports review workflows inside Jira. Choose the export assessment for a snapshot; evaluate the app when your team needs ongoing intake, review and evidence tracking.
Published scoring logic
What the scores mean—and what they do not mean
Work-item risk score
When structured fields exist, additive risk points reflect the declared risk level, personal, financial, healthcare or customer data, deployment exposure, data classification and selected external model metadata. The result is capped at 100 and grouped as Low (0–34), Medium (35–69) or High (70–100).
Missing structured evidence
A missing risk column is never treated as proof of low risk. For an AI-related item without structured sensitivity fields, the assessment uses a deterministic text-signal fallback over the title, description, labels and model field, then flags the result for human review.
Portfolio governance score
100 − round(high-risk share × 35) − round(AI-candidate share × 20) − min(medium-risk items × 2, 20), clamped from 0 to 100. The score is a prioritization signal—not a probability, benchmark, compliance percentage or forecast.
Evidence lineage contract
What must remain traceable in a review
Source
File type, matched headers, row count, duplicate count and a non-identifying row reference.
Signal
Whether the item was AI-related, which category of evidence contributed and whether structured or text fallback logic was used.
Conclusion
Risk band, portfolio contribution, owner status and the plain-language reason shown in the report.
Human decision
Named accountable owner, disposition, supporting evidence, approval date and re-review trigger retained outside the score.
Privacy boundary: this methodology page accepts no uploads, names, prompts or free text. It sends no network requests and stores nothing. The download contains only the public method definition. The assessment does not verify control effectiveness; accountable reviewers must test the controls.
Framework mapping is an orientation layer
Reports organize review prompts around governance themes such as Govern, Map, Measure and Manage; inventory and documented controls; risk classification, transparency, human oversight and monitoring. A mapping indicates where evidence may be relevant. It is not a complete applicability analysis, conformity assessment or certification, and it does not show that every legal or standard requirement applies or has been met.
Frequently asked questions
Does this certify EU AI Act, ISO 42001 or NIST AI RMF compliance?
No. The framework mapping helps organize evidence and review; it is not certification, legal advice or a compliance determination.
Can an auditor reproduce every report from this page alone?
No. Reproduction also needs the exact source export, product version, configuration and report-generation code. This page documents the decision logic and evidence boundaries for review.
Why publish the score formula?
Buyers should be able to distinguish a prioritization heuristic from an opaque assurance claim. The published formula makes the portfolio score reviewable while human judgment remains separate.