Sample consultancy report
Initech: Security Governance, Risk & Assurance
Where AI has moved into this function, whether the controls kept up, and the one move that earns the next rung. Read in five minutes; decided in one meeting.
- Prepared on
- The aisecurityskills function diagnostic
- Basis
- Cloud Security Alliance (CSA) AI Controls Matrix (AICM) · AI Security Maturity Model (AISMM) × AI Cyber Maturity Model (AI-CMM)
- Evidence state
- Illustrative · fictional organisation
- Issued
- 18 Jul 2026
The verdict
An honest early-days starting point: a few foundational policies are written, while assurance, continuity, and provider risk still sit at Initial and most workflows stay human-run.
Initech's security governance, risk and assurance function reads at L1.7 governance against L1.6 autonomy: a small-software starting posture, not a finished programme. An AI governance programme, an AppSec policy for the apps teams assure, a threat-and-vulnerability policy covering AI components, and a written audit approach are in place. What keeps the read early-days is the rest: named risk ownership and supervision are only partial or absent, independent assurance and corrective-action tracking have not started, supplier and portability controls are unfinished, and AI-scoped continuity is still missing. Policy drafting and audit evidence run assisted; vendor risk, BCP exercises, and people-security reviews remain largely manual.
Governance
L1.7
AI Security Maturity Model (AISMM) · how well it is secured
Autonomy
L1.6
AI Cyber Maturity Model (AI-CMM) · how far AI has gone
The gate
Shut
autonomy is running ahead of its controls
Where this function stands
The whole method in one drawing. Governance runs across, autonomy runs up, and the staircase is the gate: each governance level earned is the autonomy an organisation may responsibly claim.
What was measured
Two ladders, one instrument. Each answer maps to a Cloud Security Alliance AI Controls Matrix (AICM) control; a category claims a level only when that tier is evidenced, and an absent control caps it. The same rule scores every live run.
How well it is secured
L1.7
The CSA AI Security Maturity Model (AISMM): every answer maps to an AI Controls Matrix (AICM) control, and a level is claimed only when the tier is evidenced.
How far AI has gone
L1.6
The AI Cyber Maturity Model (AI-CMM): where the human sits in each workflow — in, on, then over the loop. our model · calibrated to SAE J3016.
Held below the next tier: GRC-15 absent
Held below the next tier: AIS-04 absent
Held below the next tier: TVM-03 absent
Held below the next tier: A&A-02 absent
Held below the next tier: tier 2 not yet evidenced
Held below the next tier: BCR-01 absent
Findings
Three, ranked, classified by what leadership does with each: act on a priority, protect a strength, and hold a deliberate choice.
- 01Priority
Assurance, continuity, and provider risk still sit at Initial
Independent assessment, managed audit findings, and corrective-action tracking are absent. Continuity has no AI-scoped plan, and provider risk plus portability stay partial or absent. Those gaps are the board priority: without them the function cannot claim Defined beyond the four foundational policies.
The exact control ids (for your security and governance, risk and compliance team)
A&A-02 · BCR-01 · STA-01 · IPY-01
- 02Strength
Four foundational policies are written and claim Defined
An AI governance programme with documented policies, an application security policy covering AI-enabled apps, a threat-and-vulnerability policy for AI components, and a written audit-and-assurance approach are implemented. That floor is the honest early-days strength: starting points exist to build on.
The exact control ids (for your security and governance, risk and compliance team)
GRC-01 · AIS-01 · TVM-01 · A&A-01
- 03By design
Most workflows stay human while Defined evidence finishes
Policy drafting and audit evidence run assisted. Vendor risk, BCP exercises, and people-security reviews stay manual on purpose. Analyst training and named supervision of AI-assisted assurance are only partial or absent. That restraint keeps autonomy from outrunning the still-thin governance floor.
The exact control ids (for your security and governance, risk and compliance team)
HRS-15 · GRC-15 · GRC-02
The climb
Direction, not a how-to: the next rung, and the governance that must move before autonomy does.
- Next quarter
Stand up independent assurance of the highest-risk AI areas and write an AI-scoped continuity policy so Privacy and Compliance and Infrastructure Security can evidence Defined.
- Two quarters
Document supply-chain and portability approaches for AI providers, name supervision for AI-assisted assurance work, and close the risk-management partial so Governance and provider-risk categories can climb together.
- Continuous
Hold the four foundational policies through each product and vendor change; re-run the diagnostic before lifting vendor-risk or BCP workflows another autonomy rung.
About this instrument
What a reader should carry out of the room: how the diagnostic works, how progress is tracked, and what the practice is for.
One questionnaire, two reads
Every answer maps to a Cloud Security Alliance AI Controls Matrix (AICM) control. Read one way, the answers grade the function: governance versus autonomy, joined by the gate. Read the other way, the same answers name the skills each person in the function must acquire. Diagnosis and reskilling from one sitting.
Tracked, not judged
The first run is a baseline, never a verdict. Re-assess after the work and the radar overlays the previous run, so leadership sees movement, not a grade. The compatible-standard packs (ISO/IEC, the National Institute of Standards and Technology, and the CSA AI Consensus Assessments Initiative Questionnaire) are lenses on the same answers: assess once, report many ways.
Direction, not a solution
AI is a moving target, so the report names the next rung and the governance that must move first — never a vendor stack or a how-to. The gate keeps the climb honest: autonomy is claimed only after the controls that catch it are in place.