Compliance Score & Posture Trend
Your compliance score (0–100, graded A–F) is a single, weighted read on how your AI governance program is doing right now. It's computed live across four dimensions.
The score measures your program on the platform; it is not a determination that you meet any law or standard.
Two things about the weights, because they are shares rather than fixed percentages of 100:
- A dimension with no data yet is left out of the average — not counted as zero, and not counted as perfect. If you have not written any policies, the Policies dimension does not drag your score down, and the remaining weights below are shares of what has been measured. An organization with nothing recorded anywhere is not scored at all, and the dashboard says so rather than showing a grade.
- The weights add up to 85, not 100, so each is a share of the dimensions measured: with all four measured, Findings counts for 30/85 of the score.
The dimensions and their weights:
- Findings (weight 30) — the share of findings that are resolved, accepted, or marked false-positive vs. still open, weighted by severity: an open critical finding drags the score roughly five times as hard as an open low one (critical 5×, high 3×, medium 2×, low/informational 1×). Severity comes from the finding's risk level, which in turn reflects each question's criticality weight in the question bank.
- Policies & docs (weight 20) — coverage across the policy types, minus a penalty for any overdue for review.
- Training (weight 20) — the share of your workforce trained within the last 365 days. The workforce is the union (de-duplicated by email) of active platform members and the delivered-training employee roster; a person counts as trained if either a logged training record or a passed delivered course falls within the window.
- Incident response (weight 15) — penalized for AI incidents left open or under review for more than 30 days.
The vendor register and the AI risk register are not scored: a count of vendors or risks says nothing about whether they are well managed. Their state shows on their own pages and in the risk portfolio.
Assessment scores, and how N/A is treated
The org-wide score above is separate from the score on an individual assessment, which is simply the share of applicable questions you answered Yes.
Questions you mark N/A are excluded from the score entirely — they leave both the top and the bottom of the fraction. A question that doesn't apply to you isn't a partial failure, so it shouldn't pull your score down. If your assessment has 130 questions and 40 genuinely don't apply to your organization, your score is measured out of the 90 that do.
This is why marking N/A honestly matters in both directions: marking something N/A that does apply hides a real gap, and answering No to something that doesn't apply understates a program that's actually in good shape. The platform requires a note when you mark a question N/A so the reasoning is on the record for an auditor.
The posture trend
Once a day a snapshot of your score is recorded. Score History shows today's score immediately, plus a 90-day trend chart once a few days of snapshots have accrued. The trend is org-wide and continuous — distinct from the per-assessment score, which is recorded only when an assessment is completed.
Drift alerts
If your score drops by 5 or more points versus the previous snapshot, your org admins are notified (the alert names which dimensions regressed). This is the "3 controls slipped this quarter" early-warning — catch a regression before an auditor does. The alert respects the weekly-digest notification preference.
Gap analysis
Reports → Gap Analysis turns the score into a work list. Pick a target (default A / 90) and the report shows every program dimension and assessment category that's below it — worst gap first — with the points-to-target and a concrete next action for each ("Resolve or formally accept the open findings.", "Answer 4 remaining questions and remediate the gaps.", "Close out long-running open incidents."). It's deterministic (no AI): program scores come from findings, policies, training and incidents; category scores come from your assessment answers. When nothing is below target, it says so.