AI Governance Assessment Scoring Guide
What each question measures, why it matters, and how to improve your score.
Take the AI Governance AssessmentAI Governance Assessment for the PMO
The questions in this assessment map to the practices that separate PMOs reacting to AI adoption from those managing it intentionally. This guide explains what each question is measuring, why it matters for project delivery, and what your team can do to improve.
Score Interpretation
How to read your total maturity score (0–100).
1–20: Struggling. AI governance does not exist in a meaningful form. Tools are used without policy, oversight, or accountability. The risk of compliance violations, data misuse, and inconsistent outcomes is high. Foundational policy work is the starting point.
21–40: Developing. Some awareness of AI governance exists, but policies are informal, ownership is unclear, and enforcement is inconsistent. Practices vary widely by project and team. The priority is establishing written policy and assigning clear ownership.
41–60: Norming. A governance framework is taking shape. Policies exist, compliance is considered, and some oversight mechanisms are in place. Consistency and communication across the PMO are the next areas to strengthen.
61–80: Performing. Your PMO governs AI with documented policy, assigned ownership, structured risk management, and regular review cycles. Communication and enforcement are generally strong, though gaps in monitoring or training may remain.
81–100: Thriving. AI governance is embedded into how your PMO operates. Policy is comprehensive, risk is managed proactively, tools are evaluated formally, and the team is equipped to use AI responsibly and effectively.
AI Governance Policy
Does your organization have a documented AI governance policy covering acceptable use, data handling, and model risk oversight?
Why it matters: Without a documented policy, every team makes its own call on what is acceptable. That creates inconsistency in risk exposure, data handling, and delivery quality across your portfolio. A written policy gives project managers a clear standard to operate against and gives leadership confidence that AI use is not creating unmanaged liability.
To improve your score: Start with a one-page acceptable-use policy that names which AI tools are permitted, what data they can process, and who approves exceptions. Assign an owner, circulate it to all project teams, and set a calendar reminder to review it quarterly. Even a lightweight policy is meaningfully better than none.
AI Use Guidelines
How clearly does your PMO define acceptable and prohibited uses of AI tools in project delivery?
Why it matters: General awareness that “AI is allowed” is not the same as knowing which use cases are safe, which require review, and which are off-limits. Without specific guidance, project managers fill the gaps with their own judgment, which creates uneven risk exposure and inconsistent practices across your project portfolio.
To improve your score: Document three to five common use cases your teams actually encounter. State which are approved as-is, which require a review step, and which are prohibited. Make those examples part of your project kickoff process so expectations are set at the start of each engagement.
AI Policy Review Cadence
How often is your AI governance policy reviewed and updated?
Why it matters: AI capabilities and associated risks are evolving faster than most policy cycles can keep up with. A policy written eighteen months ago may already be materially outdated. Regular review is what keeps governance connected to the actual AI landscape your teams are operating in, rather than the one that existed when the policy was first written.
To improve your score: Build an AI policy review into your existing governance calendar. Quarterly is the target, but even an annual review with a named owner and a documented outcome is a significant improvement over no scheduled review. Track what changed and why each time.
AI Risk Management
How does your PMO identify and manage AI-related risks in projects?
Why it matters: AI introduces risks that don’t appear on a standard project risk register, including model bias, hallucinated outputs used as facts, vendor lock-in, and unintended data exposure. Teams that don’t explicitly scan for these risks tend to discover them after they have already caused a problem, by which point the options for mitigation are narrower and more expensive.
To improve your score: Add an AI-specific risk checkpoint to your project planning template. Even three to five standard questions, such as whether the tool processes client data, who validates outputs before they inform decisions, and what happens if the tool is discontinued, will surface the most common exposures early enough to address them.
AI Compliance
How does your PMO ensure compliance with data privacy and regulatory requirements when AI is used in project work?
Why it matters: Data privacy laws, sector-specific regulations, and client contract terms can all restrict how AI tools process or store information. Assuming compliance without verifying it is a liability, especially as AI vendors update their data handling practices frequently. The cost of discovering a compliance gap after the fact is almost always higher than a short review up front.
To improve your score: Create a simple pre-use checklist that prompts project teams to verify whether a proposed AI tool touches regulated data, review the vendor’s data processing agreement, and confirm alignment with any relevant legal or client requirements before use begins.
AI Output Handling
How does your PMO handle AI-generated outputs that inform executive or stakeholder decisions?
Why it matters: AI-generated content, analysis, and recommendations can look authoritative while containing errors, omissions, or fabrications. When those outputs reach executive decisions without a review step, the consequences range from embarrassing corrections to serious delivery failures. Governance that normalizes review before use builds appropriate trust in the outputs that do reach leadership.
To improve your score: Establish a lightweight review step for any AI-generated content that will appear in a decision, a deliverable, or a stakeholder communication. Name who is responsible for that review on each project and document that it happened. The review does not need to be exhaustive, it just needs to be deliberate.
AI Tool Evaluation
How does your PMO evaluate and approve AI tools before they are adopted by project teams?
Why it matters: Teams adopting AI tools without evaluation often discover data handling problems, integration risks, or vendor reliability issues after those tools are already embedded in live projects. A formal evaluation process, even a lightweight one, surfaces these issues before adoption rather than after, when the switching costs are much higher.
To improve your score: Create a one-page AI tool evaluation template that covers data handling practices, security posture, contractual terms, and integration requirements. Route new tool requests through a named reviewer, such as IT or a PMO lead, before any project team begins using them in delivery work.
AI Tool Monitoring
How does your PMO monitor the ongoing use of AI tools across active projects?
Why it matters: Approved tools can drift in usage over time. Vendors change their terms, project teams extend AI use into areas not covered by the original approval, and new tools get adopted informally without going through the evaluation process. Without ongoing visibility, your governance posture can erode significantly before anyone notices.
To improve your score: Add AI tool usage as a standing topic in your project status reviews. A simple monthly question, such as what AI tools are being used and for what purpose, gives meaningful visibility without creating a heavy reporting burden. Patterns across projects are often only visible at the PMO level.
AI Governance Owner
Is there a designated owner or governing body responsible for AI governance within your PMO?
Why it matters: Governance without ownership is aspirational at best. When no single person or body is accountable for AI governance, policies don’t get updated, questions from project teams don’t get answered, and issues that should be escalated get absorbed quietly at the team level instead. Clear ownership is what makes governance operational rather than theoretical.
To improve your score: Assign a named owner for AI governance, even if it is a part-time responsibility added to an existing role. That person should own policy updates, field questions from project teams, and report on AI usage periodically to PMO leadership. Clarity about where to go with questions is itself a governance function.
AI Governance Communication
How are AI governance expectations communicated to project managers and team leads?
Why it matters: A policy that lives only in a shared drive is not an operating governance framework. Project managers and team leads need to know the rules, understand the reasoning behind them, and have somewhere to bring questions. Communication is what turns a document into a practice that actually shapes how people work.
To improve your score: Include AI governance expectations in your PMO onboarding materials and add a brief AI policy review to your annual team kickoff or training cycle. A short written summary and a known point of contact for questions is often enough to shift behavior meaningfully, without requiring a full training program.
AI Team Literacy
How would you rate your PMO team’s overall understanding of AI capabilities and limitations in a project delivery context?
Why it matters: Teams that don’t understand how AI tools work tend to either over-trust their outputs or avoid them entirely. Neither is the right answer. Literacy doesn’t mean everyone needs deep technical knowledge, but project managers should understand enough to evaluate outputs critically, recognize common failure modes, and know when to escalate or validate before proceeding.
To improve your score: Run a short AI literacy session for your PMO covering how large language models work at a conceptual level, common failure modes such as hallucination and bias, and practical guidance for the tools your teams use most. A focused half-day session can close the most critical gaps and give the team a shared vocabulary for talking about AI risk.
AI Governance Training
How does your organization support PMO staff in building AI governance competencies?
Why it matters: Governance competency doesn’t develop on its own. Without intentional support for learning, most practitioners default to self-directed trial and error, which is slow, uneven, and often uninformed by the specific risks associated with AI governance in project environments. Organizations that invest in structured learning develop more consistent and confident governance practices across the team.
To improve your score: Identify one or two training resources your PMO will endorse, such as a relevant certification, a curated reading list, or a vendor-provided course on responsible AI use. Pair those resources with protected time to complete them and make governance competency a visible part of how you develop project leadership.