No result found
This report needs a scored result to generate.
This is a static sample and does not depend on a scored result.
Back to the course pageIllustrative example · fictional company, for format reference only
AI Governance Readiness Scorecard
Meridian Trust Financial Services
Overall Readiness Score Developing
A mixed profile: governed well enough to run a bounded pilot, with two named constraints, process definition and team capability, holding back a wider rollout.
| Dimension | Score | Status | |
|---|---|---|---|
| Data readiness | 2 / 3 | Developing | |
| Process definition | 1 / 3 | Blocker | |
| Governance structure | 2 / 3 | Developing | |
| Team capability | 1 / 3 | Blocker | |
| Measurement | 2 / 3 | Developing |
Priority: Process definition
The SME loan process is not documented past branch level; new analysts learn escalation steps informally from colleagues, not from a written procedure.
An eight-out-of-fifteen score sits exactly where most first-time attendees land, and it is worth being precise about what that does and does not mean. Meridian Trust is not unready to touch AI; the readiness constraint framework was built to find the one gap that actually blocks deployment, not to produce a pass/fail verdict on the whole organisation. Governance structure and data readiness both score a 2, which means a credit committee already exists, bureau and KYC data is already centralised, and neither of those needs to be rebuilt before a bounded pilot can start. The two dimensions scoring 1, process definition and team capability, are the ones that decide whether that pilot survives contact with a real audit.
Process definition scoring below governance is the more consequential of the two constraints, not the more visible one. A credit committee that reviews flagged applications looks, from the outside, like a functioning control. What it cannot do, if the underlying escalation steps live only in individual analysts' heads, is prove to a regulator that the control is repeatable rather than personality-dependent. If the analyst who currently carries that informal knowledge leaves, the control leaves with them, and no amount of committee oversight recovers that. This is the same failure mode I have seen in three of the last five financial-services organisations I have assessed against this framework: governance exists as a meeting, not as a documented, transferable process.
Team capability scoring a 1 compounds the risk rather than sitting beside it. A team that can read the model's risk band but cannot independently audit or explain a specific score is, in practice, dependent on the vendor for the exact moment a regulator or an internal auditor asks the hardest question: why did the model say this. That dependency is tolerable during a pilot. It is not tolerable at the point Meridian Trust wants to raise its S$250,000 human-only threshold, because that is precisely the point at which someone needs to defend a specific automated decision without calling the vendor first.
My recommendation, and the one this course would generate live for a real use case, is not to close both gaps at once. It is to sequence them: document the process first, since that documentation is what makes team capability trainable in the first place, rather than running the two work-streams in parallel and finding the training has nothing written to train against.
Three-Level Delegation Map
Built for one live use case brought into the room. Meridian Trust Financial Services's example use case: AI-assisted risk banding for SME loan applications. Every decision below is sorted into exactly one of three tiers, not left as a general policy statement.
Level 1 — AI decides, unsupervised
Auto-decline applications missing a mandatory KYC document.
Auto-approve renewal applications under S$30,000 from an existing customer with a clean 24-month repayment record.
Level 2 — AI recommends, a person checks
Risk-band assignment for new applications between S$30,000 and S$250,000.
Any application the model's anomaly detector flags for an unusual income-to-loan ratio.
Level 3 — Fully human
Final approval for any application above S$250,000.
Any application involving a politically exposed person or a sanctions-list match.
The tier boundaries above are a genuine judgement call, not an arithmetic one, and it is worth stating plainly why S$30,000 and S$250,000 were the two numbers that came out of the room rather than, say, S$10,000 and S$100,000. The Level 1 unsupervised boundary was set at the point where a wrong decision is both low-value and reversible: a S$30,000 renewal to an existing customer with a clean two-year record is a decision the bank has effectively already made once, and letting the model repeat it is a genuine efficiency gain with a bounded downside. Push that boundary higher without evidence, and the "reversible" property quietly stops being true, because a larger loan takes longer to unwind if the model is wrong.
The Level 3 fully-human boundary at S$250,000 is doing different work. It is not there because the model is unreliable above that figure, it is there because the EU AI Act's Annex III already classifies creditworthiness assessment as a high-risk AI use case, and a board asked to defend a fully automated decision above that size, to a regulator or to its own risk committee, needs a human name attached to the sign-off regardless of how well the model performs. This is the distinction the TRACE framework is built to force: a delegation tier is not set by asking whether the model is accurate here, it is set by asking who has to answer for the decision if it is wrong, and how quickly that answer needs to be available.
The PEP and sanctions-match carve-out inside Level 3 is the one line in this map I would flag as non-negotiable rather than adjustable. That is not a risk-appetite decision Meridian Trust's credit committee gets to recalibrate; it is a category that stays fully human regardless of loan size, because the consequence of a wrong automated decision there is regulatory, not commercial.
What is missing from this page, and what the session builds next for a live use case, is the audit trail: a record of every Level 1 decision the model made unsupervised, retained long enough that a Level 2 or Level 3 reviewer, or an external auditor eighteen months from now, can reconstruct why a specific application landed in a specific tier. A delegation map without an audit trail behind it is a policy statement. With one, it is evidence. I would not call this map complete, in a real engagement, until that retention period and its named owner sit on the same page as the tiers themselves.
Meridian Trust Financial Services and its loan thresholds are invented for this sample only, to show the shape of the output, not a real client's actual policy. In the session, this tier map is built from the use case a participant brings, not assigned from a template.
Governance Checklist
The four questions an IMDA- or EU AI Act-aligned reviewer will actually ask, answered for Meridian Trust Financial Services's example use case above, not left as an abstract framework.
The model assigns a preliminary risk band (Low / Medium / High) to each SME loan application. A wrong band routes the application to the wrong review tier above, not to an automatic approval or decline outside those tiers, so the cost of a wrong classification is a delay or an extra review step, not an unchecked credit decision reaching a customer.
The Head of Credit Risk is the named owner of the model's output and its escalation path. Case-level accountability for any Level 2 or Level 3 decision sits with the reviewing credit analyst or committee member who signs off on it, not with the model.
Bureau credit scores, 24 months of repayment history, and self-declared income. The training data's source and refresh date are documented in the vendor's model card; the repayment-history feed's own lineage is still being traced, flagged as the Data readiness gap on the scorecard opposite.
Not yet, against a defined baseline. Default rates are reviewed quarterly, but no baseline was set before the model went live, so a change in default rate cannot yet be credibly attributed to the model. Setting that baseline is the first item on the roadmap.
Read in sequence, these four answers tell a consistent story, and it is worth naming the story rather than treating each answer as a separate box to tick. Questions one and two are answered well: the cost of a wrong decision is bounded to a routing error rather than an unchecked credit outcome, and a specific accountable owner, the Head of Credit Risk, is named rather than left as "the model" or "the vendor". Those two answers, together, are what an IMDA reviewer or an internal audit committee is actually screening for at the first pass, and Meridian Trust would clear that pass.
Question three is where I would stop the meeting and push back, in a real engagement, rather than let the answer stand as written. "Still being traced" is an honest answer, and honesty is the right instinct under this framework, but it is also the answer that directly explains the Data readiness score of 2 rather than 3 on the scorecard opposite. A reviewer working through the EU AI Act's Article 12 record-keeping expectations does not accept "documented in the vendor's model card" as sufficient on its own for a feed that determines a customer's credit outcome; they expect the institution using the model to be able to independently trace its own inputs, not to rely entirely on a third party's documentation of them. This is not a compliance technicality. If the repayment-history feed's lineage is genuinely untraced, Meridian Trust cannot currently answer a much harder follow-up question: has that feed ever silently changed format, source, or refresh cadence in a way that shifted the model's behaviour without anyone noticing.
Question four's answer is the most important one on the page, precisely because it is the most uncomfortable: no baseline exists, so no claimed improvement in default rate can yet be credibly attributed to the model at all. I would rather see this answer written honestly, as it is here, than see a fabricated baseline retrofitted to make the checklist look complete. A governance checklist's job is to survive a sceptical question from a regulator, not a friendly one from a vendor demo, and an honest gap, named and dated, survives that question. A confident but unbaselined claim does not. The roadmap on the next page exists specifically because this answer, not the higher-scoring dimensions on the scorecard, is where Meridian Trust's actual exposure sits.
Twelve-Week Roadmap
The scorecard, delegation map and governance checklist above, brought together into one sequenced plan, ordered by impact and reversibility rather than by department.
- Document the SME loan process end to end, including today's informal escalation steps.
- Set a default-rate baseline before any further change to the model.
- Name a specific owner and backup for Level 3 sign-off.
- Formalise the escalation path and audit trail for Level 2 human-checked decisions.
- Run a hands-on session for the risk analyst team to review and explain individual model outputs without vendor support.
- Trace the repayment-history feed back to its source system and document data lineage.
- Present the completed governance checklist and delegation map to the credit committee for board-level sign-off.
- Re-score the five dimensions and compare against this baseline.
- Schedule the first quarterly review against the newly set baseline.
The reason this plan runs foundation, then structure, then governance, and not the reverse, is that each phase's output is a direct input to the one after it, and reversing the order produces work that has to be redone. Weeks one to four exist to produce two artefacts nothing later in the plan can substitute for: a written version of the SME loan process, and a default-rate baseline set before the model changes again. Skip straight to weeks five to eight without those, and the training session for the risk analyst team has no written process to train against, and the escalation audit trail has no documented process to audit against. I have watched organisations attempt the reverse order, formalising escalation paths before the underlying process was written down, and the result is an audit trail for a process that changes shape every time someone documents it slightly differently, which satisfies no one.
Weeks five to eight are the phase most likely to be quietly dropped under time pressure, because none of its three items produce a document a board can see. Training the risk analyst team to explain a model output without vendor support does not look, on a status update, like progress the way a signed-off checklist does. It is nonetheless the phase that converts the Team capability score from a 1 to something defensible, and skipping it is exactly how an organisation ends up with a well-documented governance checklist that nobody internal can actually operate without calling the vendor.
Weeks nine to twelve are where the first three phases get tested against an audience that was not in the room when they were written: the credit committee. Presenting the checklist and delegation map for board-level sign-off is not a formality step; it is the point at which gaps in the earlier work surface, because a committee member who was not part of building the delegation map will ask questions the drafting team did not think to ask themselves. Re-scoring the five dimensions in week eleven or twelve, against this exact baseline, is what turns "we did some governance work" into a number a board can compare year over year.
What "done" looks like at the end of week twelve is not a perfect score. It is a Meridian Trust that can answer all four governance-checklist questions without a caveat, including question four, because a baseline now exists to measure against. That is a materially different, and more defensible, position than the one this scorecard describes today.
Every score, quote and figure on these four pages is invented for Meridian Trust Financial Services, a fictional company, so the format of what a participant leaves with can be judged before enquiring. It is not a real client's deliverable, and no organisation named Meridian Trust Financial Services is a Praxora Lab client. The session itself scores your own organisation's own use case, in the room, on the day.
Four hours, one session, facilitated by Terence Kok.