AI Governance Hub

Methodology version 1.0 · 27 August 2026

Trace every governance conclusion back to evidence.

This public methodology explains how AI Governance Hub validates work-item exports, identifies AI-related records, assigns risk signals, aggregates a portfolio score and frames human review. It is designed for procurement, internal audit, model risk, security and governance teams evaluating the assessment.

Decision boundary: the assessment prioritizes review. It does not verify that source data is complete, test a deployed model, approve an AI system, certify a management system or determine legal compliance.

Explainable assessment pipeline

Six stages from export to review

Select a stage to inspect what it consumes, what it produces, what evidence remains reviewable and what the stage cannot prove.

Input
Output
Reviewable evidence
Limitation

Published scoring logic

What the scores mean—and what they do not mean

Work-item risk score

When structured fields exist, additive risk points reflect the declared risk level, personal, financial, healthcare or customer data, deployment exposure, data classification and selected external model metadata. The result is capped at 100 and grouped as Low (0–34), Medium (35–69) or High (70–100).

Missing structured evidence

A missing risk column is never treated as proof of low risk. For an AI-related item without structured sensitivity fields, the assessment uses a deterministic text-signal fallback over the title, description, labels and model field, then flags the result for human review.

Portfolio governance score

100 − round(high-risk share × 35) − round(AI-candidate share × 20) − min(medium-risk items × 2, 20), clamped from 0 to 100. The score is a prioritization signal—not a probability, benchmark, compliance percentage or forecast.

Portfolio rating bands

ScoreDisplayed ratingRequired interpretation
90–100ExcellentFewer detected portfolio risk signals; completeness and control effectiveness still require review.
75–89GoodReview the detected medium/high-risk items and missing evidence before relying on the rating.
60–74Needs AttentionMaterial governance work is indicated; assign owners and validate the source evidence.
0–59At RiskPrioritize accountable review; the score itself does not establish harm or non-compliance.

Evidence lineage contract

What must remain traceable in a review

1

Source

File type, matched headers, row count, duplicate count and a non-identifying row reference.

2

Signal

Whether the item was AI-related, which category of evidence contributed and whether structured or text fallback logic was used.

3

Conclusion

Risk band, portfolio contribution, owner status and the plain-language reason shown in the report.

4

Human decision

Named accountable owner, disposition, supporting evidence, approval date and re-review trigger retained outside the score.

Privacy boundary: this methodology page accepts no uploads, names, prompts or free text. It sends no network requests and stores nothing. The download contains only the public method definition. The assessment does not verify control effectiveness; accountable reviewers must test the controls.

Framework mapping is an orientation layer

Reports organize review prompts around governance themes such as Govern, Map, Measure and Manage; inventory and documented controls; risk classification, transparency, human oversight and monitoring. A mapping indicates where evidence may be relevant. It is not a complete applicability analysis, conformity assessment or certification, and it does not show that every legal or standard requirement applies or has been met.

Frequently asked questions

Does this certify EU AI Act, ISO 42001 or NIST AI RMF compliance?

No. The framework mapping helps organize evidence and review; it is not certification, legal advice or a compliance determination.

Can an auditor reproduce every report from this page alone?

No. Reproduction also needs the exact source export, product version, configuration and report-generation code. This page documents the decision logic and evidence boundaries for review.

Why publish the score formula?

Buyers should be able to distinguish a prioritization heuristic from an opaque assurance claim. The published formula makes the portfolio score reviewable while human judgment remains separate.