Rate each capability
Select the maturity level that best reflects current, repeatable practice rather than intended future design.
Practical governance assessment
Assess twelve governance capabilities, distinguish maturity from evidence confidence, identify priority gaps, and generate a sequenced roadmap for a realistic target state.
How it works
Complete the assessment using current evidence, review the score and confidence separately, then use the prioritised roadmap to plan improvement.
Select the maturity level that best reflects current, repeatable practice rather than intended future design.
Indicate whether the rating is not evidenced, anecdotal, documented, or supported by current measurements.
Compare current maturity with the target state and sequence gaps by impact, urgency, and evidence strength.
Methodology and limitations
The model separates maturity, evidence strength, and target-state gap so that an optimistic rating cannot hide weak supporting evidence.
Each dimension has equal weight. This avoids implying organisation-specific weighting without enough context.
Confidence uses fixed factors: 35% not evidenced, 55% anecdotal, 75% documented, and 100% measured. It highlights validation needs without changing maturity.
Self-assessments can contain optimism, inconsistent interpretation, incomplete evidence, and scope bias. Validate material decisions through stakeholder review and evidence sampling.
Activities are informal, reactive, person-dependent, or largely absent.
Some repeatable practices exist, but coverage, authority, evidence, and adoption remain inconsistent.
Roles, processes, and standards are documented and broadly established, with uneven execution.
Governance is measured, integrated, actively managed, and supported by reliable evidence.
Governance is outcome-led, continuously improved, automated where appropriate, and embedded in decision-making.
Frequently asked questions
It measures twelve capabilities: executive sponsorship, operating model, decision rights, policy framework, ownership and stewardship, metadata, data quality, privacy and security alignment, issue management, change and adoption, tooling, and performance measurement.
The overall maturity score is the arithmetic mean of the twelve dimension ratings. Each dimension has equal weight, and the final score is rounded to two decimal places.
The levels are Initial, Developing, Defined, Managed, and Optimising. Their numeric thresholds are displayed in the methodology section and applied consistently to every result.
A high rating supported only by perception should not be treated like a high rating supported by current measurements. Separate confidence makes that distinction visible without manipulating the selected maturity score.
Use a cross-functional group where possible. Typical contributors include business data owners, stewards, data and technology leaders, risk, privacy, security, compliance, analytics, architecture, operations, and transformation teams.
No. It is a self-assessment and planning tool. It does not provide independent assurance, certification, legal advice, regulatory conclusions, or a substitute for evidence-based audit work.
Reference concise, current artefacts such as approved policies, role matrices, forum records, catalogue statistics, quality dashboards, issue logs, control results, training records, or benefit reports. Avoid entering sensitive personal or confidential information.
A six- to twelve-month cycle is often practical. Reassess sooner after a major operating-model change, merger, regulatory event, platform rollout, governance transformation milestone, or significant control failure.
Choose the level needed to manage your business, regulatory, operational, and data risks within a realistic planning horizon. Not every dimension needs to reach Level 5, and premature optimisation can add unnecessary cost.
Priority is based on the difference between current and target maturity, with additional urgency where evidence confidence is weak. Large gaps and unsupported ratings are addressed before low-value optimisation.
No external API is used. The form is processed by the page, and CSV and JSON files are created locally in the browser. Persistent storage should occur only if the existing site deliberately implements secure server-side storage.
Validate the highest-priority findings with stakeholders and evidence, agree accountable owners, define measurable outcomes, sequence foundational operating-model changes, and review progress through a time-bound governance roadmap.