AI Governance Assessment Agent
Automated first pass AI risk and governance reviews
An AI tool that reviews supplied system documentation against a selected governance framework and drafts a structured assessment. It surfaces risks, missing information, and questions worth following up.

Start with the real need
AI governance reviews often begin with a vague request to assess a system and a large set of uneven documentation. That invites generic conclusions before the evidence has been organized. I built this prototype to test whether a framework-led first pass could make the material easier to review without disguising the result as a final assessment.
How I shaped the product
The tool takes supplied system documentation, applies the governance framework chosen by the user, and drafts a control-by-control assessment. The useful output is not a risk label on its own. It is a clearer record of what the documentation supports, what is missing, and what a reviewer should examine next.
Decisions that mattered
Choose the framework first
The assessment should follow a named set of requirements or controls. Selecting the framework before analysis gives the output a structure that a reviewer can inspect.
Make missing information visible
An unanswered question should remain a gap. The model should not quietly complete the story with a plausible assumption.
Draft, not determination
The output is designed as material for a responsible reviewer to challenge. It cannot determine compliance or certify that a system is safe.
What this does not prove
- The assessment depends on the accuracy and completeness of the information entered.
- The current prototype has not been benchmarked against assessments produced by experienced reviewers.
- A structured answer can create false confidence even when caveats are present.
How I would strengthen the evidence
- 01Create a set of expert-reviewed scenarios and compare the tool against them.
- 02Trace every material conclusion back to the answer or source that supports it.
- 03Measure unsupported claims, missed risks, and unnecessary escalations separately.
Interested in the reasoning behind the build?
I share the decisions, failed assumptions, and useful lessons as the work develops.