An Operational Artifact of the Enterprise Integrity Framework™

Enterprise Integrity Assessment™

A structured maturity assessment for organizations governing AI-enabled and automated workflows.

The assessment evaluates whether your organization can demonstrate that approved actions execute as intended, remain within authorized boundaries, and can be independently reconstructed after the fact.

Review the Framework First

35 scored questions across 7 maturity domains, plus workflow prioritization · Estimated completion time: 15–20 minutes · Progress is saved automatically in this browser

For CFOs & Controllers For Internal Audit For Enterprise Risk For CPA & Advisory Firms For Governance Leaders

What this assessment answers.

Most enterprise controls are designed to confirm that an action was approved. As AI and automation extend into execution, a different question becomes material.

Can the organization demonstrate that approved actions execute as intended, remain within authorized boundaries, and can be independently reconstructed after the fact?

How to use this assessment

Each domain question is scored using a consistent three-point maturity scale: No / Not in Place, Partial / Informal / Inconsistent, or Yes / Formal / Documented / Operating.

Respond based on how your organization actually operates today, not how it intends to operate in the future.

Domains Evaluated

The assessment organizes 35 scored questions across seven maturity domains, preceded by an organization and AI adoption profile, and followed by workflow prioritization.

1. Workflow Visibility

Whether critical workflows are inventoried, ranked, and assigned formal ownership.

2. AI & Automation Involvement

Whether AI-enabled and automated workflows are identified, reviewed, and governed before deployment.

3. Authorization Integrity

Whether approval rules, thresholds, and exceptions are documented and consistently applied.

4. Execution Integrity

Whether executed actions can be shown to match approved intent without drift.

5. Evidence & Replayability

Whether execution can be reconstructed, replayed, and independently verified.

6. Governance & Accountability

Whether ownership, escalation, and change control are formally defined.

7. Continuous Assurance

Whether execution drift and control failures are detected before material impact occurs.

We found a saved assessment from a previous session in this browser.

Step 1 of 10 Progress saved automatically
Step 1 of 10

Organization Profile

This information is used only to deliver and contextualize your results. It is not shared or published.

Step 2 of 10

AI Adoption Profile

These questions establish the current and planned scale of AI-enabled and automated workflows in your organization.

Check all that apply.
Check all that apply.
Step 3 of 10 — Domain 1 of 7

Workflow Visibility

Whether critical workflows are inventoried, ranked by impact, and assigned formal ownership.

No — not in place Partial — informal, inconsistent, or in progress Yes — formal, documented, and consistently operating
1. Does the organization maintain an inventory of critical workflows?
2. Are workflows ranked by financial, operational, regulatory, customer, or workforce impact?
3. Are workflows involving automation or AI explicitly identified?
4. Does management know where automated workflows create irreversible outcomes?
5. Are workflow owners formally assigned?
Step 4 of 10 — Domain 2 of 7

AI & Automation Involvement

Whether AI-enabled and automated workflows are identified, distinguished from AI-assisted recommendations, and reviewed before deployment.

No — not in place Partial — informal, inconsistent, or in progress Yes — formal, documented, and consistently operating
6. Does the organization maintain an inventory of AI-enabled or automation-enabled workflows?
7. Are AI-assisted recommendations distinguished from AI-executed actions?
8. Are workflows identified where AI influences money movement, pricing, claims, refunds, credits, customer decisions, or workforce actions?
9. Are AI-enabled workflows reviewed before production deployment?
10. Does the organization define which AI outputs require human review before execution?
Step 5 of 10 — Domain 3 of 7

Authorization Integrity

Whether approval rules, thresholds, and exceptions are documented, consistently applied, and subject to change control.

No — not in place Partial — informal, inconsistent, or in progress Yes — formal, documented, and consistently operating
11. Are authorization rules documented for critical workflows?
12. Are approval thresholds documented and consistently applied?
13. Are exceptions to approval rules tracked and reviewed?
14. Can management demonstrate who approved a critical action and under what authority?
15. Are authorization rules version-controlled or subject to change control?
Step 6 of 10 — Domain 4 of 7

Execution Integrity

Whether executed actions can be shown to match approved intent, without drift, duplication, or undetected failure.

No — not in place Partial — informal, inconsistent, or in progress Yes — formal, documented, and consistently operating
16. Can management demonstrate that an approved action executed exactly as authorized?
17. Are execution outcomes compared to approved intent?
18. Are duplicate, excessive, incomplete, or divergent executions detected?
19. Are execution failures identified before financial, operational, or customer impact occurs?
20. Are controls positioned at or near the point of execution, not only at the approval layer?
Step 7 of 10 — Domain 5 of 7

Evidence & Replayability

Whether execution can be reconstructed, replayed, and independently verified after the fact.

No — not in place Partial — informal, inconsistent, or in progress Yes — formal, documented, and consistently operating
21. Can the organization reconstruct a critical execution event after the fact?
22. Does the evidence show what was approved, what executed, and why?
23. Are execution records complete, timestamped, and linked to authorization records?
24. Can prior execution decisions be replayed or independently verified?
25. Are logs and evidence sufficient for Internal Audit, Enterprise Risk, regulatory inquiry, dispute resolution, or Audit Committee review?
Step 8 of 10 — Domain 6 of 7

Governance & Accountability

Whether ownership, cross-functional alignment, escalation, and change control are formally defined.

No — not in place Partial — informal, inconsistent, or in progress Yes — formal, documented, and consistently operating
26. Is there a defined owner for AI-enabled workflow governance?
27. Are Internal Audit, Enterprise Risk, Compliance, Finance, and IT aligned on how AI-enabled execution is governed?
28. Are escalation paths defined for uncertain or elevated-risk execution events?
29. Are governance rules reviewed and approved before changes are deployed?
30. Does the organization have a documented process for responding to execution failures or governance exceptions?
Step 9 of 10 — Domain 7 of 7

Continuous Assurance

Whether critical workflows are monitored continuously and control failures are detected before material impact occurs.

No — not in place Partial — informal, inconsistent, or in progress Yes — formal, documented, and consistently operating
31. Are critical workflows monitored continuously for execution drift?
32. Are exceptions surfaced in real time or near real time?
33. Can execution be allowed, escalated, or blocked based on defined risk criteria?
34. Are control failures detected before material impact occurs?
35. Does management receive reporting on execution integrity, workflow drift, or assurance gaps?
Step 10 of 10

Workflow Prioritization

Identify up to three workflows that may warrant deeper review. For each workflow, score the listed factors from 1 (low) to 5 (high). This step is optional — leave a workflow name blank to skip it.

Candidate Workflow 1

Candidate Workflow 2

Candidate Workflow 3

Enterprise Integrity Assessment™ Results

Your results reflect organizational maturity across workflow visibility, AI and automation involvement, authorization integrity, execution integrity, evidence and replayability, governance and accountability, and continuous assurance.

out of 100

Domain Scores

Domain Profile

Top Findings

    Recommended Next Step for Your Maturity Band

    Workflow Prioritization

    Recommended Next Step

    Organizations seeking to validate these results against an actual workflow may consider an Enterprise Integrity Diagnostic™ — a deeper, evidence-based review of one specific workflow.

    Workflow Mapping
    Policy Review
    Authorization Review
    Conformance Testing
    Historical Replay Analysis
    Evidence Assessment
    Findings & Recommendations
    Request an Enterprise Integrity Diagnostic™ Conversation

    Part of a single methodology.

    The Enterprise Integrity Assessment™ operationalizes the Enterprise Integrity Framework™, which defines the principles, domains, and criteria used throughout this evaluation.

    Execution Integrity Infrastructure™ describes the category of capability organizations may eventually require to act on these results.

    Explore the Framework