Benchmarking AI governance by sector and size

Every leader asks the same question after their first AI governance diagnostic: am I behind? This is the question our diagnostic was built to answer. Below are red/amber/green distributions across the four sectors we see most often — accountancy, legal, healthcare and SaaS — split by company size. We also name the few things top-quartile firms in each sector do differently.

The numbers below are indicative, drawn from anonymised AI Assured diagnostics across UK SMEs over the last twelve months. Treat them as a yardstick, not a regulator's benchmark.

Run the free AI Risk Assessment to get your own red/amber/green score, then compare it to your sector below.

How to read the bands

Each diagnostic scores six governance domains: inventory, oversight, use policy, vendor risk, risk assessment, incident response. A domain is red if it has no controls in place, amber if partial, green if documented and evidenced. We report typical counts of red domains at first assessment — fewer reds is better.

Accountancy and professional services

  • 1–10 people: 5–7 red domains. Most have a use policy in draft; almost none have a register or vendor process.

  • 11–50 people: 4–6 red. Inventory starts appearing; oversight is the typical weak spot.

  • 51–250 people: 3–5 red. Use policies are common, but evidence is thin and incident plans rare.

Top quartile do differently: they treat AI risk as part of professional indemnity exposure, not an IT issue, and they put a partner, not the IT manager, on the hook.

  • 1–10 people: 5–8 red. Heavy reliance on off-the-shelf tools with little contractual scrutiny.

  • 11–50 people: 4–6 red. Most have a confidentiality policy but no AI-specific overlay.

  • 51–250 people: 2–5 red. Better policy hygiene; weakest on vendor due diligence.

Top quartile do differently: they map AI tools to client matters and disclose AI use in engagement letters by default.

Healthcare and life sciences

  • 1–10 people: 6–8 red. The most regulated, often the least prepared, because AI hasn't yet hit clinical workflow.

  • 11–50 people: 4–7 red. Strong on data protection, weak on AI-specific risk assessment.

  • 51–250 people: 3–5 red. Increasingly looking to ISO 42001 as a procurement signal.

Top quartile do differently: they extend their existing clinical governance committee to cover AI, rather than spinning up a parallel structure.

SaaS and tech

  • 1–10 people: 4–7 red. Move fast, document later. Inventory is usually the surprise gap.

  • 11–50 people: 3–6 red. Strong engineering controls, weak human-oversight evidence.

  • 51–250 people: 2–4 red. The most mature SME segment, often pulled forward by enterprise buyers.

Top quartile do differently: they treat their assurance posture as a sales asset, publish a trust page, and refresh the register quarterly as part of the release process.

What the data tells us

Three patterns hold across every sector:

  1. Size beats sector. A 200-person firm in any sector is more mature than a 10-person firm in the same sector. Maturity correlates more with headcount and customer pressure than with industry rules.

  2. Inventory is the universal weak spot. Across every cohort, the AI register is the most commonly red domain. It is also the cheapest to fix.

  3. Incident response is the silent risk. Few firms have a written process. When something goes wrong, they will improvise, badly.

The register and incident process are both single questions on the AI Assured Essential self-assessment — closing the two most common gaps doesn't require a consultant, it requires an afternoon.

Get Essential (£499/year) and close your register and incident-response gaps as part of certifying.

What to do with this

Take the free AI Risk Assessment. Compare your red count to your sector and size band above. If you are at or above the typical count, you are not behind — this is normal, which is not a defensible position when a buyer asks. Use the 30-day sprint to close the gap, then certify with AI Assured Essential (£499/year) to self-certify or Professional (£2,999/year) for a verified badge and public certificate.

Start free, benchmark your score, then certify when you're ready.

Essential Takeaways

  1. Most SMEs have 3–8 'red' AI governance domains in their first assessment, depending on size and sector.

  2. Company size is a stronger predictor of AI maturity than industry-specific regulations.

  3. AI system inventories and incident response plans are the most common weak spots across all cohorts.

  4. Top-quartile firms assign AI risk ownership to senior partners, not just the IT department.

Scope

AI Assured is a governance programme, not an accredited certification body. It does not issue ISO/IEC 42001 certificates or statutory sign-off for the EU AI Act, FCA, FDA, NYC LL144 or other regulatory regimes. Articles are general information, not legal or regulatory advice.

Frequently asked questions

How is AI governance maturity measured in these benchmarks?

AI governance is scored across six domains, including inventory, oversight, and vendor risk. A domain is rated 'red' for no controls, 'amber' for partial controls, and 'green' for fully documented controls. The benchmarks compare firms by counting the number of 'red' domains they have at their first assessment. A lower count of red domains indicates a more mature governance posture compared to peers.

What is the most common weakness in AI governance across all sectors?

The most common weakness across every sector and company size is the AI inventory, also known as an AI register. This domain is the most frequently rated 'red', indicating that most organisations do not have a comprehensive list of the AI systems they use. The article notes that while this is a universal weak spot, it is also one of the simplest and cheapest gaps to fix.

Does company size or industry have a bigger impact on AI governance?

Company size has a bigger impact on AI governance maturity than the industry sector. The data consistently shows that a larger firm in any sector is likely to be more mature than a smaller firm in the same sector. This correlation is driven by factors like having more resources, a larger headcount, and increased pressure from enterprise customers who demand stronger governance and assurance from their vendors.

What do top-performing SaaS companies do differently for AI governance?

Top-quartile SaaS and tech companies treat their AI governance and assurance posture as a key sales asset. Instead of seeing it as a compliance burden, they proactively publish a 'trust page' to demonstrate their commitment to responsible AI. They also integrate governance into their development lifecycle, refreshing their AI register quarterly as part of their standard software release process, keeping it consistently up to date.

What are the two biggest silent risks in corporate AI governance?

The two most significant and widespread risks are the lack of an AI inventory and the absence of a formal incident response plan. Without an inventory, companies cannot manage tools they don't know they have. The lack of an incident plan means that when an AI system inevitably fails or causes harm, the company will be forced to improvise its response, likely leading to poor outcomes.

Harmeen Birk, AI Governance Advisor

Harmeen Birk is an ex-Citi senior AI strategist and executive advisor with over 20 years of experience leading large-scale data and AI programs within global financial institutions. As an IAPP-trained Artificial Intelligence Governance Professional (AIGP) she specialises in bridging the gap between rigorous compliance and practical innovation. Her expertise focuses on establishing robust AI governance frameworks and responsible AI practices for mid-market companies, boards, and emerging tech vendors.

Credentials: AI Governance Advisors, Institutions & Financial Services | Ex-Citi | HBS | AIGP | CGI

Keep Reading