Sample report. Windward Bank & Trust Ltd. is a fictional composite client. Every score, finding, quote and figure below is illustrative, shown to demonstrate the structure and depth of a Skyrocket AI Readiness engagement.
AI is already inside your organization. This is what finding out looks like.
A complete sample deliverable: six dimensions scored, shadow AI inventoried, SANS AISMM and NIST AI RMF overlaid, and a 90/180/365 roadmap sequenced. This is the report, not a brochure about it.
Section 01
Executive Summary
The one-sentence read
The bank's foundation is stronger than its leadership believes, and its exposure is more immediate than its leadership realizes. Three dimensions already sit in Operational territory, meaning the raw material for AI is largely in place. But there is no AI use policy while 40+ staff already use consumer AI tools on personal accounts, including two confirmed cases of customer correspondence. Overall posture: 39 of 100 (Developing, Tier 2 of 5).
The Three Findings That Matter
| # | Finding | What it means |
|---|---|---|
| 1 | AI is already inside the bank, unmanaged
Most urgent |
40+ employees across five departments use personal accounts on consumer AI tools; at least two confirmed cases of customer correspondence pasted into those tools. No AI use policy, no approved-tool list, no monitoring. The exposure is live today. |
| 2 | The biggest operational returns are concentrated in three processes | Consumer loan processing averages 11 days (~60% document chasing and re-keying), daily reconciliation consumes ~3 FTE, and ten inquiry types drive ~68% of customer-service volume. These are where AI produces measurable returns first. |
| 3 | The foundation is better than expected | A true single source of truth in core banking, seven years of clean history, 45 AI assistant seats already owned (6 active), and capable champions in credit operations and IT ready to lead. |
Recommended Next Steps
Quick-Win Sprint
Intelligence Build
Credit Operations
The sequencing rule is absolute: governance first, because the exposure is live. Every recommendation in this report assumes the 30-day governance sprint happens before any build work begins. AI doesn't need to be stopped; it needs to be steered.
Section 02
AI Posture Map
Each dimension is scored 0–100 against observed evidence and mapped to a maturity tier: Nascent (0–19) · Developing (20–39) · Operational (40–59) · Advanced (60–79) · AI Forward (80–100). The detail behind the number matters more than the number itself.
| Dimension | Score | Tier | In one line |
|---|---|---|---|
| Strategy & Vision | 38 | Developing | Executive interest is real; goals, KPIs, and ownership are not yet defined |
| Data Foundation | 52 | Operational | Core banking is a true system of record; the edges are spreadsheets and email |
| Process Readiness | 44 | Operational | Compliance processes are well documented; operations run on tribal knowledge |
| Technology & Infrastructure | 47 | Operational | Solid identity and licensing base; integration capability unused |
| People & Skills | 31 | Developing | Two strong champions, no training program, wide interest without direction |
| Governance, Risk & Security | 22 | Developing | No AI policy while AI use is already widespread; the gap driving the score |
Reading the shape: middle-heavy and governance-light. Three dimensions sit in Operational territory: Data Foundation (52), Technology & Infrastructure (47) and Process Readiness (44). That's the raw material for AI, largely in place. The two people-and-direction dimensions trail (Strategy 38, People 31), and Governance, Risk & Security (22) is the outlier pulling the weighted score down.
This is the inverted risk profile we see most often. The organization believes it has not adopted AI, so it has not governed AI, while adoption is already underway without controls. Governance is weighted more heavily in the roll-up because this is a regulated institution handling customer financial data.
Section 03
SANS AISMM Security Overlay
The six-dimension score is cross-checked against the SANS AI Security Maturity Model, using the Financial Services weighting profile (Protect 0.40 · Utilize 0.25 · Govern 0.35).
| Pillar | Score | Weight | What was observed |
|---|---|---|---|
| Protect | 2.3 | 0.40 | Identity, access control and audit posture are strong for existing systems, but no AI-specific controls exist. |
| Utilize | 1.6 | 0.25 | 6 of 45 owned AI seats are active; departmental pilots are uncoordinated and unmeasured. |
| Govern | 1.0 | 0.35 | No AI use policy, no vendor review, and live shadow usage with confirmed customer-data exposure. |
How the stage was derived, and why the raw score isn't the answer. The weighted roll-up lands at 1.67, which would read as Stage 2. Two cap rules bind at the same level anyway: the Governance Floor Rule and the Minimum Pillar Rule each cap the stage at ⌊1.0⌋ + 1 = 2. The final stage is 2 (Reactive), consistent with the six-dimension Developing tier. Raising Govern is the fastest lever to reach Stage 3.
Section 04
Dimension Findings
Every dimension below its ceiling produces line items on the remediation roadmap. Findings are evidence-based, drawn from 20 interviews, direct workflow observation, system and license inventory, and a 30-day operational sample, never questionnaire-derived.
Strategy & Vision
What we observedThe board has raised AI twice in 2026. The CEO can articulate a general goal but no specific outcomes, budgets or timelines exist. No executive owns AI. Three departments have experimented independently with no coordination and no way to compare results.
What it meansInterest without ownership produces scattered pilots that stall. Until outcomes and decision rights are defined, every AI initiative competes for attention with no way to win.
Strengths to build onGenuine board-level attention · a CEO willing to sponsor · no legacy of failed AI projects to overcome.
Gaps to addressNo named owner · no defined outcomes tied to business metrics · no KPIs per process · no budget appetite established · no prioritization mechanism.
Data Foundation
What we observedThe core banking platform is the authoritative record for accounts, transactions and customers, with seven years of accessible history. Around the core the picture degrades: reporting is exported to spreadsheets and re-keyed, loan files live in email threads and shared folders, and three departments keep parallel customer contact lists.
What it meansAI initiatives drawing on the core platform can start on solid ground now. Initiatives needing documents (lending, compliance) require a document-handling layer first: buildable, and already reflected in the roadmap.
Strengths to build onSingle source of truth for core records · vendor API access available (currently unused) · long clean history for context and retrieval.
Gaps to addressUnstructured document storage · no labeling or searchability standards · spreadsheet re-keying introduces errors AI would inherit · parallel contact lists create identity-matching problems.
Process Readiness
What we observedCompliance-driven processes (KYC, AML review, regulatory reporting) are documented to a high standard because the regulator requires it. Operational processes are not: loan origination, reconciliation and customer service run on experience and tribal knowledge.
What it meansThree processes quantified during the assessment carry most of the opportunity: consumer loan processing (11-day average cycle, ~60% document chasing), daily reconciliation (~3 FTE), and customer service (ten inquiry types covering ~68% of volume).
Strengths to build onCompliance documentation discipline proves the organization can document processes when there is a reason · bottlenecks are known and acknowledged rather than hidden.
Gaps to addressNo per-process success metrics · undocumented operational workflows · no measurement discipline to confirm whether any improvement works.
Technology & Infrastructure
What we observedThe bank runs a modern productivity suite with strong identity, access control and audit posture. It already owns 45 AI assistant seats; six are actively used. The core banking vendor offers API access the bank has never enabled. No integration layer connects core systems; data moves by export and re-key.
What it meansThe bank is already paying for AI capability it is not using, and the identity and audit foundation that makes AI deployment safe is largely in place. The missing piece is integration.
Strengths to build onStrong identity, access and audit infrastructure · licenses already owned · vendor API available · no significant technical debt blocking a start.
Gaps to address39 of 45 owned AI seats inactive · no API integrations enabled · no integration layer between core systems · cloud adoption partial and unplanned.
People & Skills
What we observedTwo genuine champions exist: a senior analyst in credit operations who has automated parts of her own workload, and an IT manager who runs AI tools personally. Beyond them fluency is thin. A pulse survey found ~70% of staff interested but unsure where to start. Branch and teller staff showed the most hesitancy, tied to job-security concerns nobody has addressed.
What it meansThe adoption problem is absence of direction, not resistance. Interest this broad, with champions this capable, converts quickly under a structured program. Left unaddressed, it converts into more shadow usage instead.
Strengths to build onTwo capable internal champions in high-impact departments · broad latent interest · leadership willing to be trained first.
Gaps to addressNo training program at any level · no communication about what AI means for roles · champions have no mandate or time allocation · no ownership of adoption as a workstream.
Governance, Risk & Security
What we observedNo AI use policy, no approved-tool list, no vendor review process for AI services, and no incident-response consideration for AI events. Meanwhile 40+ staff across five departments use personal accounts on consumer AI tools, with at least two confirmed instances of customer correspondence pasted into them.
What it meansThe exposure is live today. For a regulated institution handling customer financial data this dimension is weighted heavily, and it is the first thing to fix. Every recommendation in this report assumes the governance sprint happens first.
Strengths to build onA compliance function with real discipline and regulator-facing experience · existing data-handling policies that extend naturally to AI · leadership that responded with urgency rather than denial.
Gaps to addressNo written AI use policy · no approved / prohibited tool list · active shadow usage with confirmed customer-data exposure · no vendor or model risk review · no AI incident playbook.
Section 05
NIST AI RMF Alignment
Governance and strategy findings were mapped to the four functions of the NIST AI Risk Management Framework. The profile confirms the six-dimension read: exposure concentrates in GOVERN and MANAGE: exactly the functions the 30-day sprint addresses first.
Each roadmap phase is annotated with the functions it advances.
| Function | Score | Gap note |
|---|---|---|
| GOVERN | 1.0 | No AI policy, ownership, or risk appetite. The floor of the whole profile: the 30-day sprint targets it directly. |
| MAP | 1.8 | Context is now partially mapped through this assessment (processes, data, usage); no internal mapping practice yet exists. |
| MEASURE | 1.2 | No per-process metrics or AI performance measurement discipline; Week-0 baselines are established in the first 90 days. |
| MANAGE | 1.0 | AI events are absent from incident-response playbooks; no vendor / model risk treatment exists. |
MITRE ATLAS and OWASP LLM Top 10: scoped out for this cycle. The bank operates no deployed AI/ML systems or LLM applications today, so AI attack-surface mapping and OWASP LLM Top 10 ranking were excluded by evidence rule rather than by omission. Both overlays activate at the second posture assessment, once the loan document intelligence build and the customer-service assistant are in production.
Section 06
Top Risks
Five risks, scored on likelihood and impact (1–5). Marker numbers on the matrix correspond to the ranked risks in the table below.
Risk 1 sits at the extreme corner of the map because both terms are maximal: the behavior is happening today (likelihood) and the payload is customer financial correspondence in a regulated institution (impact). It is also the cheapest risk on this page to retire: the AI use policy, guardrails baseline and license rationalization collapse it within 30 days.
| # | Risk | Lkhd | Impact | Score | Band | Why it matters now |
|---|---|---|---|---|---|---|
| 1 | Customer data leakage through shadow AI | 5 | 5 | 25 | Critical | 40+ staff on personal AI accounts, with confirmed cases of customer correspondence shared. Exposure is live, unmonitored, and outside every existing control. |
| 2 | Regulatory gap | 4 | 4 | 16 | High | Regional regulator expectations on AI governance are rising while the bank has no policy, no framework, and demonstrable ungoverned usage. The gap is documentable in an examination. |
| 3 | Unvetted vendor risk | 3 | 4 | 12 | High | Free consumer AI tools in active use have never passed a vendor review. Terms, data handling, and model training practices are unknown to the bank. |
| 4 | Pilot failure and AI fatigue | 3 | 3 | 9 | Medium | Three uncoordinated experiments with no measurement discipline. Most AI pilots stall without structure; failed pilots poison future adoption. |
| 5 | Key-person concentration | 4 | 2 | 8 | Medium | The bank's practical AI capability lives in two people with no mandate. Either departure would remove most of the institution's working knowledge. |
Section 07
Shadow AI & License Inventory
Discovery combined interviews, workflow observation and productivity-suite license data. The pattern is the classic shadow-AI inversion: the sanctioned, governed, already-paid-for capability sits idle while ungoverned personal accounts carry the real workload.
| Inventory item | Status | Risk | Assessment note |
|---|---|---|---|
| Productivity-suite AI assistant: 45 seats owned | Sanctioned | Low | 6 seats active; 39 idle. Spend already committed. Rationalization recovers it within 30 days. |
| Consumer AI chat tools: personal accounts | Shadow | Critical | 40+ users across retail operations, credit, compliance, customer service, and IT. Two confirmed customer-data instances. |
| Departmental experiments: 3 uncoordinated pilots | Ungoverned | Medium | No shared measurement, no comparison mechanism, no vendor review performed. |
| Employee-built automation: spreadsheet macros | Latent demand | Low | Credit-operations analyst independently automated part of loan file assembly: evidence of both the bottleneck and internal appetite. |
Shadow usage is unmet demand, not a discipline problem. The correction is a communicated path from shadow to sanctioned: policy, approved tools, activated seats and training, not prohibition. Prohibition without an alternative drives usage further underground.
Section 08
Quick Wins: Next 30 Days
Five actions, each deliverable within 30 days with minimal investment. Together they close the urgent exposure and produce visible momentum. The governance sprint leads because the exposure is live.
| Quick win | What it delivers | Illustrative range |
|---|---|---|
| AI use policy and safe-use rollout | Written policy, approved-tool list, employee guidance, and a communicated path from shadow usage to sanctioned usage | $3,500 – $5,000 |
| License rationalization | The 45 owned AI seats audited, configured, and reassigned to the roles that need them; recovers spend already committed | $2,500 – $4,000 |
| Shadow AI discovery and guardrails baseline | Inventory of actual AI usage across departments, risk-ranked, with immediate guardrails for the highest-exposure cases | $2,500 – $4,500 |
| Structured AI training, operations teams | Two hands-on workshops (English and Spanish) covering sanctioned tools, real bank workflows, and safe data handling | $3,000 – $6,000 |
| Executive outcomes session | Facilitated working session with leadership: three defined AI outcomes, KPIs per outcome, and a named owner | $1,500 – $2,500 |
Ranges shown are illustrative planning figures; each engagement is scoped and confirmed individually. The five quick wins map to the Assess → Prioritize stages of the Skyrocket journey and lift the AISMM Govern pillar from 1.0 toward 2.0, the single fastest lever for the capped maturity stage.
Section 09
Strategic Roadmap: 90 / 180 / 365
The roadmap sequences the Skyrocket journey: Assess → Prioritize → Implement → Operate, with the governance sprint first because the exposure is live. Every phase advances specific NIST AI RMF functions.
Exit criteria for the year
Overall AI Readiness Score above 50 (Operational tier) · Governance, Risk & Security moved from 22 into the 50s · AISMM stage lifted from 2 (Reactive) toward 3 (Defined) as the Govern pillar clears the floor rule · three production AI capabilities measured against their Week-0 baselines.
Section 10
Implementation Opportunities
Each opportunity was identified during the assessment, sized by impact and complexity, and mapped to the engagement that would address it. Sequencing: governance first because the exposure is live; document intelligence and reconciliation next because the returns are largest and most measurable; the customer-facing assistant once internal wins have built confidence.
| # | Opportunity | Impact | Complexity | Engagement type | Illustrative range |
|---|---|---|---|---|---|
| 1 | Loan document intelligence Intake, extraction, verification, exception flagging | High | Medium | Implementation project | $20,000 – $35,000 |
| 2 | Daily reconciliation automation Branch and card settlement matching | High | Medium | Implementation project | $12,000 – $20,000 |
| 3 | Bilingual customer service assistant EN/ES, top inquiry types, human handoff | High | Med-High | Implementation project | $15,000 – $25,000 |
| 4 | AI workspace deployment & adoption Credit operations first, then compliance | High | Low-Med | Adoption engagement | $8,000 – $15,000 |
| 5 | KYC / compliance document review Screening support, human decision | Med-High | Medium | Implementation project | $15,000 – $25,000 |
| 6 | AI governance framework & monitoring Policy through examination readiness | High | Low | Governance engagement | $5,000 – $10,000 |
| 7 | Retained advisory & posture tracking Quarterly re-score, capability review | Ongoing | Low | Monthly retainer | $2,500 – $5,000 / mo |
Ranges are illustrative planning figures, not quotes. Each engagement is scoped against the client's actual environment before any number is committed.
Section 11
Next Steps & Services Map
The immediate ask
Authorize the 30-day governance and quick-win sprint. It retires the report's #1 risk, activates capability the bank already pays for, and creates the measured baseline every later phase depends on. AI doesn't need to be stopped; it needs to be steered.
Follow-On Engagements: Secure AI Adoption
| Engagement | How it extends this assessment |
|---|---|
| Skyrocket Your AI: Implementation | Delivers the loan document intelligence, reconciliation and customer-service builds, each measured against the Week-0 baseline. |
| AI Governance Engagement | Policy through examination readiness: vendor / model risk review process, AI incident playbook, and regulator-facing documentation. |
| Retained Advisory & Posture Tracking | Quarterly re-score against the six dimensions and AISMM, new-capability review, and board-level reporting cadence. |
Cybersecurity Cross-Map: Where AI Risk Meets the Security Program
| DigitalEra service | Relevance to findings in this report |
|---|---|
| vCISO Service | Owns AI governance inside the broader security program: the "named owner" gap in Strategy and the regulator-readiness gap in Governance. |
| Penetration Testing (AI systems) | Tests the loan document pipeline and customer-service assistant before production; activates the ATLAS and OWASP LLM overlays at the second assessment. |
| Policy Development | Extends existing data-handling policies to AI use, vendor review and incident response: the three documented floors in the Governance scoring. |
| User Awareness Training | Carries the EN/ES safe-use training beyond the 30-day sprint into a standing security-culture program for branch and teller staff. |
| Dark Web Monitoring | Watches for credential or customer-data exposure stemming from the confirmed shadow-AI data instances. |
Appendix
Evidence Excerpt
The full appendix contains the complete interview record, system inventory, observed-evidence log, and dimension-by-dimension scoring rationale. The excerpt below shows the format.
Scoring Rationale: Governance, Risk & Security (22)
| Criterion | Evidence observed | Contribution |
|---|---|---|
| Written AI use policy | None exists; confirmed by compliance lead and CEO | Critical floor |
| Shadow AI exposure | 40+ users across 5 departments; 2 confirmed customer-data instances | Strong negative |
| Data handling practices | Solid for existing systems; no extension to AI tools | Partial |
| Compliance awareness | Team aware of rising regulator expectations; no framework in response | Partial |
| Vendor and model risk process | No review process for AI services | Critical floor |
| Incident response readiness | AI events absent from existing playbooks | Critical floor |
Interview Evidence Log Entry
Operational interview, credit operations (week 2). Analyst demonstrated current loan file assembly: documents arrive by email, are saved to a shared folder, and key fields are re-typed into the origination system. Average handling confirmed against a 30-day sample: 11.2 days application to decision, of which 6.7 days were waiting on documents or re-keying. The analyst had independently built a spreadsheet macro to partially automate one step: unprompted evidence of both the bottleneck and the internal appetite to fix it.
Next step
What your AI posture report would contain
Everything above, built on your organization rather than a composite: your six-dimension scores, your shadow AI inventory, your quantified processes, and a 90/180/365 roadmap sequenced for your constraints and your regulator.
Six-dimension scoring
Each dimension scored against observed evidence, with strengths and gaps named specifically.
Your shadow AI inventory
What is actually running, who is using it, which licenses you already pay for and don’t use.
Quantified processes
Your highest-impact workflows measured, so improvement can be proven against a Week-0 baseline.
A live walkthrough
A named consultant presents every finding to your leadership, and stays engaged while you execute.
Find out where you actually stand
Start with the two-minute AI readiness self-check, or book fifteen minutes. We will tell you whether a full assessment would help, including if the answer is not yet.
Questions
Frequently Asked Questions
What is the Skyrocket AI Readiness Assessment?
It is an evidence-based assessment of an organization’s readiness to adopt AI safely, scored across six dimensions: Strategy & Vision, Data Foundation, Process Readiness, Technology & Infrastructure, People & Skills, and Governance, Risk & Security. Findings come from interviews, direct workflow observation, system and license inventory, and an operational sample, never from a questionnaire. The output is a scored posture map, a shadow AI inventory, sized opportunities, and a 90/180/365 roadmap.
How is this different from a cybersecurity assessment?
A cyber maturity assessment measures how well you protect what you already run. An AI readiness assessment measures whether you can adopt AI safely and where it would actually pay off: which means scoring your data, your processes, your people and your governance, not just your controls. The two share the same Skyrocket method and the same standard of care, and they cross-map: AI governance findings routinely become security program work.
We have not adopted AI yet. Is this premature?
That belief is the most common finding in this practice, and it is usually wrong. In this sample the organization believed it had not adopted AI, while 40+ staff were using consumer AI tools on personal accounts with confirmed customer data involved. The inverted risk profile (believing you have not adopted AI, so not governing AI, while adoption is already underway) is precisely why the assessment exists.
What do the six dimensions and five tiers mean?
Each dimension is scored 0–100 against observed evidence and mapped to a tier: Nascent (0–19), Developing (20–39), Operational (40–59), Advanced (60–79), AI Forward (80–100). The overall score is a weighted roll-up, and Governance is weighted more heavily for regulated organizations handling sensitive data.
Why is governance always sequenced first?
Because the exposure is usually live. Ungoverned AI use with real company or customer data is happening today in most organizations we assess, and no build project should start while that continues. The governance sprint is also the cheapest item on the roadmap and the fastest to retire the top risk: policy, an approved-tool list, guardrails and license rationalization typically take 30 days.
Do you use SANS AISMM and NIST AI RMF, or your own model?
Both. The six-dimension model is DigitalEra’s scoring instrument; the SANS AI Security Maturity Model and the NIST AI Risk Management Framework are applied as overlays so findings map to frameworks your auditors and regulators already recognize. MITRE ATLAS and the OWASP LLM Top 10 are added once you have AI systems actually in production. Mapping an attack surface that does not exist yet would be theatre.
Will you tell us not to proceed if that is the honest answer?
Yes. Where an organization is not ready, or where the highest-value action costs nothing and needs no vendor, the report says so. In this sample two of the five quick wins recover spend the client had already committed rather than adding new spend.