Accountability and decision rights
Executive ownership, business ownership, control ownership, approvals, exceptions, escalation, and retirement authority.
Score six operating domains from Reactive to Adaptive. Record the owner, evidence, next action, and review date for each domain.
An AI governance maturity model measures whether AI controls operate consistently and produce evidence. This model has five levels: Reactive, Defined, Controlled, Measured, and Adaptive. It covers accountability, inventory, data and vendors, evaluation, monitoring, and evidence. Use the lowest material domain as the overall level. A high average can hide a serious gap.
Boundary: this model does not certify compliance. It helps an enterprise find missing operating evidence and choose the next improvement.
Read each level from left to right. Select the highest level that current evidence supports. Do not give credit for a planned control.
| Level | Operating state | Evidence test |
|---|---|---|
| 1. Reactive | Individuals make AI decisions without a common operating system. | Evidence is missing, incomplete, or held by one person. |
| 2. Defined | The company has common policies, terms, and minimum requirements. | Documents exist, but use and ownership are inconsistent. |
| 3. Controlled | Named owners apply controls before release and during operation. | Approvals, tests, decisions, and changes can be reconstructed. |
| 4. Measured | The company measures control performance, exceptions, and incidents. | Management reports show whether controls work over time. |
| 5. Adaptive | The company changes governance from verified results and new risks. | Incidents, tests, and portfolio evidence cause documented changes. |
A company can be strong in policy and weak in production control. Score each domain separately before you assign an overall level.
Executive ownership, business ownership, control ownership, approvals, exceptions, escalation, and retirement authority.
Systems, models, vendors, intended use, affected users, data, locations, owners, status, and risk tier.
Rights, quality, lineage, security, privacy, vendor evidence, concentration, change notice, continuity, and exit.
Acceptance tests, representative cases, quality, safety, bias where relevant, override rights, and escalation tests.
Production thresholds, alerts, reviewers, response times, incident exercises, change review, and stop conditions.
Decision records, versions, approvals, tests, incidents, outcomes, independent review, and verified improvement.
Overall score: use the lowest domain that can cause material harm, loss, delay, or non-compliance. An arithmetic average is useful for trend reporting, but it must not override a critical weakness.
This is an original operating model. It does not reproduce a standard and does not replace current legal or assurance advice.
An AI governance maturity model is a structured method for assessing how consistently an organization assigns AI accountability, classifies systems, applies controls, measures performance, manages incidents, and retains evidence. It shows the current operating state and the next verifiable improvement. It does not prove legal compliance.
Score each domain from level 1 to level 5 using current evidence. Do not score from policy language alone. Record the owner and supporting artifact. Use the lowest material domain to set the overall maturity level because a high average can hide a critical control gap.
The five levels in this model are Reactive, Defined, Controlled, Measured, and Adaptive. Reactive work depends on individuals. Defined work has common rules. Controlled work has named owners and operating evidence. Measured work tracks control performance. Adaptive work changes the system from verified results and incidents.
No. This model is an operational assessment, not a certification or legal opinion. The EU AI Act applies by role, system type, risk category, use, and date. ISO IEC 42001 has its own requirements and certification process. Confirm applicability with qualified legal, risk, and assurance professionals.
The original wording and scoring structure are licensed under CC BY 4.0 with attribution to Paul Okhrem.