AI Governance Benchmarks by Sector and Company Size

Explore real-world AI governance benchmarks by sector and size, with red/amber/green distributions showing what top-quartile firms do differently.

By Harmeen Birk, AI Governance Advisor · 2026-06-10 · 6 min read

Benchmarking AI governance by sector and size


Every leader asks the same question after their first AI governance diagnostic: am I behind? This is the question our diagnostic was built to answer. Below are red/amber/green distributions across the four sectors we see most often — accountancy, legal, healthcare and SaaS — split by company size. We also name the few things top-quartile firms in each sector do differently.

The numbers below are indicative, drawn from anonymised AI Assured diagnostics across UK SMEs over the last twelve months. Treat them as a yardstick, not a regulator's benchmark.

→ Run the free AI Risk Assessment to get your own red/amber/green score, then compare it to your sector below.

How to read the bands


Each diagnostic scores six governance domains: inventory, oversight, use policy, vendor risk, risk assessment, incident response. A domain is red if it has no controls in place, amber if partial, green if documented and evidenced. We report typical counts of red domains at first assessment — fewer reds is better.

Accountancy and professional services


  • 1–10 people: 5–7 red domains. Most have a use policy in draft; almost none have a register or vendor process.
  • 11–50 people: 4–6 red. Inventory starts appearing; oversight is the typical weak spot.
  • 51–250 people: 3–5 red. Use policies are common, but evidence is thin and incident plans rare.

Top quartile do differently: they treat AI risk as part of professional indemnity exposure, not an IT issue, and they put a partner, not the IT manager, on the hook.

→ See where your firm sits and run the free assessment for your accountancy-specific score.

::cta[Start free assessment]{href=/assessment variant=primary}

Legal services


  • 1–10 people: 5–8 red. Heavy reliance on off-the-shelf tools with little contractual scrutiny.
  • 11–50 people: 4–6 red. Most have a confidentiality policy but no AI-specific overlay.
  • 51–250 people: 2–5 red. Better policy hygiene; weakest on vendor due diligence.

Top quartile do differently: they map AI tools to client matters and disclose AI use in engagement letters by default.

Healthcare and life sciences


  • 1–10 people: 6–8 red. The most regulated, often the least prepared, because AI hasn't yet hit clinical workflow.
  • 11–50 people: 4–7 red. Strong on data protection, weak on AI-specific risk assessment.
  • 51–250 people: 3–5 red. Increasingly looking to ISO 42001 as a procurement signal.

Top quartile do differently: they extend their existing clinical governance committee to cover AI, rather than spinning up a parallel structure.

SaaS and tech


  • 1–10 people: 4–7 red. Move fast, document later. Inventory is usually the surprise gap.
  • 11–50 people: 3–6 red. Strong engineering controls, weak human-oversight evidence.
  • 51–250 people: 2–4 red. The most mature SME segment, often pulled forward by enterprise buyers.

Top quartile do differently: they treat their assurance posture as a sales asset, publish a trust page, and refresh the register quarterly as part of the release process.

→ See where your firm sits — run the free assessment for your SaaS-specific score. ::cta[Start free assessment]{href=/assessment variant=primary}

What the data tells us


Three patterns hold across every sector:

  1. Size beats sector. A 200-person firm in any sector is more mature than a 10-person firm in the same sector. Maturity correlates more with headcount and customer pressure than with industry rules.
  2. Inventory is the universal weak spot. Across every cohort, the AI register is the most commonly red domain. It is also the cheapest to fix.
  3. Incident response is the silent risk. Few firms have a written process. When something goes wrong, they will improvise, badly.

The register and incident process are both single questions on the AI Assured Essential self-assessment — closing the two most common gaps doesn't require a consultant, it requires an afternoon.

→ Get Essential (£499/year) and close your register and incident-response gaps as part of certifying.

::cta[Find your tier]{href=/selector variant=primary}


What to do with this


Take the free AI Risk Assessment. Compare your red count to your sector and size band above. If you are at or above the typical count, you are not behind — this is normal, which is not a defensible position when a buyer asks. Use the 30-day sprint to close the gap, then certify with AI Assured Essential (£499/year) to self-certify or Professional (£2,999/year) for a verified badge and public certificate.

→ Start free, benchmark your score, then certify when you're ready.

::cta[Start free assessment]{href=/assessment variant=primary}