1. Rate maturity
Score the current and target state for each governance dimension using explicit five-level criteria.
Evaluate governance across fourteen practical control areas, compare current and target maturity, test evidence strength, and produce a prioritised implementation roadmap.
Complete the assessment with a cross-functional team where possible. Use evidence you can locate and verify rather than relying only on policy intent.
Score the current and target state for each governance dimension using explicit five-level criteria.
Rate supporting evidence from assertion-only through independently checked or tested evidence.
Review critical gaps, governance forums, practical actions, and a phased roadmap for the selected horizon.
The model is designed for practical governance planning. It rewards repeatability, operating evidence, monitoring, and assurance rather than policy documents alone.
1 Initial: ad hoc or absent. 2 Developing: partial and inconsistent. 3 Defined: documented and repeatable. 4 Managed: measured and consistently applied. 5 Optimised: integrated, assured, and continuously improved.
Evidence ranges from unsupported assertion to independently checked or tested records. This separates governance intent from demonstrable operating effectiveness and highlights where confidence should remain cautious.
Validate the profile with accountable stakeholders, confirm priorities against actual AI risks, assign owners and dates, establish decision forums, and track evidence of completed actions. Reassess after significant change.
It measures how consistently governance controls are defined, implemented, evidenced, monitored, and improved across fourteen dimensions. It is an internal planning score, not a certification or legal determination.
Each dimension receives a current maturity level from 1 to 5 and an evidence score from 1 to 4. The overall maturity score is the arithmetic mean of current maturity ratings. An evidence-adjusted indicator applies a transparent factor from 0.70 to 1.00 to highlight where claims are weakly supported.
A documented or claimed control may not operate reliably. Evidence scoring distinguishes unsupported assertions from approved records, operating examples, testing, or independent assurance.
A cross-functional group usually produces the most credible result, including business, technology, data, risk, security, privacy, legal, compliance, procurement, internal audit, and operational representatives.
No. Controls should be proportionate to purpose, affected stakeholders, autonomy, sensitivity, scale, reversibility, and applicable obligations. Higher-risk uses normally require stronger review, evidence, monitoring, and oversight.
Repeat it at least annually and after material changes such as new regulation, major incidents, acquisitions, operating-model changes, significant supplier changes, or rapid expansion of AI use.
No. It is an operational maturity tool and does not provide legal advice, certification, conformity assessment, or a determination of compliance in any jurisdiction.
This tool flags a gap as critical when the target is at least two maturity levels above the current state, or when current maturity and evidence are both low. Organisations should also apply their own risk context.
Choose the level needed for the assessed scope and risk profile, not automatically level 5. A smaller low-risk portfolio may be well controlled at level 3 or 4, while high-impact or regulated use may require stronger maturity.
Use them as suggested governance mechanisms, then consolidate them where practical. Existing risk, architecture, data, security, compliance, or audit committees may absorb responsibilities if mandates and decision rights are explicit.
No data is transmitted by this page. Results are calculated during the request and enhanced locally in the browser. Any future server-side storage should be deliberately implemented with appropriate security and privacy controls.
The adjustment is intentionally conservative. It reduces the indicator when maturity claims rely on limited evidence, drawing attention to controls that may be documented but not demonstrably operating.