AI Governance Maturity Model
A five-level maturity model, applied independently across 14 control domains, so a program's strengths and gaps show up as a profile rather than a single misleading score.
Why one overall score doesn't work
A program can have excellent documentation practices and weak monitoring at the same time. Averaging those into a single maturity number hides exactly the gap a maturity assessment exists to find. This model is designed to be applied per control domain. You should end up with 14 scores, not one, and the lowest scores are where to focus first.
Initial
Controls are ad hoc or don't exist. Activity happens reactively, usually after an incident, with no documented process.
What counts as evidence: No inventory, no assigned owners, no written policy for the domain.
Developing
A policy exists on paper, but enforcement is inconsistent and depends on individual diligence rather than a system.
What counts as evidence: A written policy or checklist, but no way to verify whether it was actually followed for a given system.
Defined
A documented, repeatable process exists and is generally followed, with clear ownership. Enforcement still relies partly on manual steps.
What counts as evidence: A named process owner, a documented workflow, and records showing the process ran, though gaps can still go undetected between reviews.
Managed
The control is measured and enforced systematically, with monitoring that would catch a failure or bypass before it causes harm.
What counts as evidence: Automated enforcement or alerting, a defined escalation path, and metrics tracked over time. The control cannot be silently skipped.
Optimizing
The control is continuously improved based on incident data, near-misses, and changes in regulation or AI capability, not left static once implemented.
What counts as evidence: A feedback loop from incidents and audits back into the control design, with a documented revision history.
Documented is not the same as enforced
The most common maturity-assessment mistake is crediting a domain at Defined or Managed because a policy document exists, without verifying the control actually operates as described. A human-review checkpoint that a bug could bypass was documented, but the control it described was not actually enforced. That domain was Developing in practice, not Managed. Score maturity against enforcement evidence, not policy language. See our guide to auditing an AI governance program for how to test the difference.
Score every domain
Get your maturity profile
Use the AI Governance Institute self-assessment to see where your program scores across each control domain, and where the biggest gaps are.
Start the self-assessment →