Responsible AI planning tool

AI Governance Maturity Assessment

Evaluate governance across fourteen practical control areas, compare current and target maturity, test evidence strength, and produce a prioritised implementation roadmap.

Private by design. No information is sent to external services. Results depend on your inputs and should be reviewed by appropriate business, technical, risk, and legal specialists.
How it works

From structured input to an actionable governance roadmap

Complete the assessment with a cross-functional team where possible. Use evidence you can locate and verify rather than relying only on policy intent.

1. Rate maturity

Score the current and target state for each governance dimension using explicit five-level criteria.

2. Test evidence

Rate supporting evidence from assertion-only through independently checked or tested evidence.

3. Prioritise action

Review critical gaps, governance forums, practical actions, and a phased roadmap for the selected horizon.

Governance maturity assessment

Complete all fourteen dimensions. The basic calculation works without JavaScript; JavaScript adds progress feedback and local export options.

Assessment context
Scoring scale: Current and target maturity use 1 (Initial) to 5 (Optimised). Evidence uses 1 (assertion only) to 4 (assured). Select a realistic target; level 5 is not automatically appropriate for every use case.
AI governance maturity dimensions
Leadership and accountabilityExecutive ownership, decision rights, accountable roles, escalation routes, and board-level visibility.
Policy and standardsApproved AI policy, practical standards, prohibited uses, exceptions, review cycles, and enforcement.
AI inventory and ownershipComplete register of internally built, purchased, embedded, experimental, and retired AI systems.
Risk classificationConsistent risk taxonomy, impact assessment, tiering, approval thresholds, and proportional controls.
Lifecycle controlsStage gates from ideation and design through testing, deployment, change, retirement, and record retention.
Data and model governanceData provenance, quality, suitability, model documentation, validation, versioning, and reproducibility.
Human oversightMeaningful human review, intervention authority, competency, workload, override, and appeal arrangements.
Transparency and documentationUser notices, explainability, traceability, documentation, disclosures, and records of significant decisions.
Monitoring and performanceOperational monitoring, drift, bias, errors, security, complaints, thresholds, alerts, and periodic review.
Incident managementDetection, reporting, containment, investigation, remediation, notification, lessons learned, and recurrence prevention.
Third-party AISupplier due diligence, contract controls, ongoing assurance, change notifications, concentration, and exit planning.
Legal and compliance coordinationCoordinated review across legal, privacy, security, sector obligations, records, employment, consumer, and contractual risks.
Training and competenceRole-based literacy, specialist competence, refresher training, testing, and responsible-use support.
Assurance and auditControl testing, independent challenge, internal audit, evidence quality, remediation tracking, and governance effectiveness.
Do not include confidential, personal, security-sensitive, or legally privileged information.
Privacy note: Calculations run locally within this page request and no external API is used. No persistent storage is implemented here. Any server-side storage added by the site should be deliberate, secure, and disclosed.
Methodology and responsible use

Understand what the result means—and what it does not

The model is designed for practical governance planning. It rewards repeatability, operating evidence, monitoring, and assurance rather than policy documents alone.

Five maturity levels

1 Initial: ad hoc or absent. 2 Developing: partial and inconsistent. 3 Defined: documented and repeatable. 4 Managed: measured and consistently applied. 5 Optimised: integrated, assured, and continuously improved.

Evidence-strength lens

Evidence ranges from unsupported assertion to independently checked or tested records. This separates governance intent from demonstrable operating effectiveness and highlights where confidence should remain cautious.

Using the output

Validate the profile with accountable stakeholders, confirm priorities against actual AI risks, assign owners and dates, establish decision forums, and track evidence of completed actions. Reassess after significant change.

Frequently asked questions

Practical questions about AI governance maturity

What does the AI governance maturity score measure?

It measures how consistently governance controls are defined, implemented, evidenced, monitored, and improved across fourteen dimensions. It is an internal planning score, not a certification or legal determination.

How is the score calculated?

Each dimension receives a current maturity level from 1 to 5 and an evidence score from 1 to 4. The overall maturity score is the arithmetic mean of current maturity ratings. An evidence-adjusted indicator applies a transparent factor from 0.70 to 1.00 to highlight where claims are weakly supported.

Why assess evidence strength separately?

A documented or claimed control may not operate reliably. Evidence scoring distinguishes unsupported assertions from approved records, operating examples, testing, or independent assurance.

Who should complete the assessment?

A cross-functional group usually produces the most credible result, including business, technology, data, risk, security, privacy, legal, compliance, procurement, internal audit, and operational representatives.

Should every AI system have the same controls?

No. Controls should be proportionate to purpose, affected stakeholders, autonomy, sensitivity, scale, reversibility, and applicable obligations. Higher-risk uses normally require stronger review, evidence, monitoring, and oversight.

How often should the assessment be repeated?

Repeat it at least annually and after material changes such as new regulation, major incidents, acquisitions, operating-model changes, significant supplier changes, or rapid expansion of AI use.

Can this assessment replace a legal or regulatory review?

No. It is an operational maturity tool and does not provide legal advice, certification, conformity assessment, or a determination of compliance in any jurisdiction.

What is a critical control gap?

This tool flags a gap as critical when the target is at least two maturity levels above the current state, or when current maturity and evidence are both low. Organisations should also apply their own risk context.

How should target maturity be selected?

Choose the level needed for the assessed scope and risk profile, not automatically level 5. A smaller low-risk portfolio may be well controlled at level 3 or 4, while high-impact or regulated use may require stronger maturity.

What should we do with the recommended forums?

Use them as suggested governance mechanisms, then consolidate them where practical. Existing risk, architecture, data, security, compliance, or audit committees may absorb responsibilities if mandates and decision rights are explicit.

Is any assessment data sent externally?

No data is transmitted by this page. Results are calculated during the request and enhanced locally in the browser. Any future server-side storage should be deliberately implemented with appropriate security and privacy controls.

Why might the evidence-adjusted indicator be lower than the maturity score?

The adjustment is intentionally conservative. It reduces the indicator when maturity claims rely on limited evidence, drawing attention to controls that may be documented but not demonstrably operating.