Join our Newsletter — 33% off our NHI Course

What do companies get wrong when preparing for a GNI assessment?

A common mistake is treating the assessment as documentation only. The process requires more than written policies, because assessors also examine case studies, implementation evidence, and how the company handles difficult rights-based trade-offs in practice. Another error is limiting participation to one team. Effective preparation needs legal, policy, product, and AI governance input.

Where GNI Assessment Prep Usually Goes Off Track

Companies often underestimate that a GNI assessment is a test of governance in motion, not a paper review. Assessors want to see whether policies are translated into decisions, escalation paths, and evidence that a team can handle contested rights questions when the easy answer is not available. That means preparation has to connect policy, product behaviour, legal reasoning, and AI governance into one coherent story. It is also where organisations discover that internal alignment matters as much as the documentation set, because gaps between teams quickly become visible when evidence is challenged. In practice, many companies find this only after they have assembled a strong document pack but cannot show how real decisions were made under pressure.

One useful reference point is the OWASP Non-Human Identity Top 10, not because a GNI assessment is an NHI exercise, but because it illustrates a broader pattern: governance breaks down when teams focus on form rather than the operational reality behind access, trust, and control.

How Strong Preparation Works in Practice

Good preparation starts by treating the assessment as an evidence exercise. Teams should be able to show the policy, the decision record, the implementation trail, and the example that proves the process works in practice. The central question is not whether a policy exists, but whether the organisation can demonstrate that the policy influenced a real product or operational decision. That is especially important when the issue involves competing rights, because assessors will usually look for how the company weighed the trade-off, who signed off, and whether the reasoning was consistent.

A practical preparation model usually includes three layers. First, map each key assessment theme to an owner who can explain the decision and provide evidence. Second, select case studies that show the organisation handling both routine and difficult situations, not only the cleanest examples. Third, verify that the evidence set is internally consistent, meaning the policy language, implementation detail, and submitted narrative all tell the same story. Where those layers do not match, the assessment usually becomes harder, not easier.

  • Use real examples that show the policy being applied, not only drafted.
  • Prepare cross-functional reviewers so legal, product, policy, and AI governance can answer the same question coherently.
  • Check that escalation routes are documented and that they match what teams actually do.
  • Retain the artefacts that show how a difficult decision was resolved, not just the final outcome.

For organisations with AI-enabled products, this often means showing how model or product behaviour was reviewed when rights implications changed or became uncertain. That is where many teams uncover a maturity gap: they have governance language, but not enough decision evidence to prove governance is operational. The guidance breaks down when the company cannot tie its narrative to a specific, defensible example.

Trade-Offs, Edge Cases, and the Questions Assessors Probe

Tighter preparation often increases internal coordination overhead, requiring organisations to balance assessment readiness against the time cost of collecting and validating evidence.

There is no single consensus on how much detail is enough, but the safer assumption is that assessors will expect substance wherever a claim sounds high-level. A policy that is broadly correct but unsupported by case material is usually weaker than a narrower policy with a clear example trail. The edge case is when the company has strong controls but poor documentation discipline: the control may exist, yet the assessment still suffers because the evidence is fragmented or owned by different teams.

Another common issue appears when organisations prepare only their central compliance function. That can work for straightforward governance questions, but it breaks down when the assessment probes product design choices, AI-specific risk handling, or rights-based trade-offs that depend on operational context. In those cases, the company needs people who can explain not just what the rule says, but how the rule affected a real decision.

Assessors also tend to focus on consistency across examples. If one case study suggests a mature review process while another shows an ad hoc exception path, the inconsistency itself becomes part of the finding. This is why teams should test the whole package before submission, not only each document in isolation.

Risk and Threat Considerations

The main risk in weak GNI assessment preparation is governance failure being exposed as an evidence failure. Organisations may believe they have the right controls, but if they cannot demonstrate decision quality, accountability, or repeatable handling of difficult cases, the assessment can surface material gaps in oversight and implementation.

Failure mechanism: the weakness usually materialises when written policy, product practice, and cross-functional ownership drift apart. Assessors then encounter incomplete evidence, inconsistent explanations, or a process that exists in principle but not in operational reality. In AI-enabled contexts, that gap can also obscure how rights-sensitive decisions were reviewed, escalated, or constrained.

Impact: the organisation may receive an adverse assessment outcome, but the deeper consequence is loss of trust in its governance claims. That can force remediation work, delay approvals, and reveal that decision-making is not yet robust enough for scrutiny.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST AI RMF, NIST CSF 2.0 and CIS Controls v8 set the technical controls, while ISO/IEC 42001:2023 and EU AI Act define the regulatory obligations.

Framework Control / Reference Relevance
ISO/IEC 42001:2023 4.2 — Understanding the needs and expectations of interested parties GNI prep hinges on governance that addresses rights-holder expectations.
Recommendation — Align assessment evidence to stakeholder expectations and AI governance decisions.
NIST AI RMF MAP 1 — Context and scope mapping Assessments need a mapped governance context, not only policy artefacts.
Recommendation — Map assessment topics to concrete AI risk contexts and decision evidence.
EU AI Act Art. 9 — Risk management system AI-related assessments often test whether risks are managed in practice.
Recommendation — Document how rights-sensitive AI risks are identified, evaluated, and controlled.
NIST CSF 2.0 GV.RM-01 — Risk Management Strategy GNI prep exposes whether governance claims are backed by operating practice.
Recommendation — Show how governance decisions are embedded in operational risk management.
CIS Controls v8 14.1 — Security Awareness and Skills Training Cross-functional assessment readiness depends on shared process knowledge.
Recommendation — Train participating teams on evidence handling and consistent assessment responses.

Practitioner Guidance

What to prioritise: build the submission around three evidence types: policy intent, operational proof, and one or two difficult examples that show how trade-offs were actually handled. If any of those is missing, the package is usually incomplete even if the documentation volume looks strong.

What to verify: confirm that the people named in the process can explain the same decision in the same way. The fastest way to expose weakness is to ask legal, product, and AI governance teams to walk through one contested case independently and compare the narratives.

Common mistake: treating preparation as a document assembly task. The better test is whether an outsider can see a credible chain from policy to implementation to outcome without relying on unstated context.

Practitioner takeaway: the strongest submissions do not merely prove that controls exist; they prove that the organisation can defend how those controls behaved when the decision was difficult.