Free scorecard · five levels · no lead gate

AI Governance Maturity Model.

Score six operating domains from Reactive to Adaptive. Record the owner, evidence, next action, and review date for each domain.

An AI governance maturity model measures whether AI controls operate consistently and produce evidence. This model has five levels: Reactive, Defined, Controlled, Measured, and Adaptive. It covers accountability, inventory, data and vendors, evaluation, monitoring, and evidence. Use the lowest material domain as the overall level. A high average can hide a serious gap.

Download editable CSV

Boundary: this model does not certify compliance. It helps an enterprise find missing operating evidence and choose the next improvement.

Five maturity levels

Use evidence, not confidence, to select a level.

Read each level from left to right. Select the highest level that current evidence supports. Do not give credit for a planned control.

LevelOperating stateEvidence test
1. ReactiveIndividuals make AI decisions without a common operating system.Evidence is missing, incomplete, or held by one person.
2. DefinedThe company has common policies, terms, and minimum requirements.Documents exist, but use and ownership are inconsistent.
3. ControlledNamed owners apply controls before release and during operation.Approvals, tests, decisions, and changes can be reconstructed.
4. MeasuredThe company measures control performance, exceptions, and incidents.Management reports show whether controls work over time.
5. AdaptiveThe company changes governance from verified results and new risks.Incidents, tests, and portfolio evidence cause documented changes.
Six operating domains

Score the complete governance system.

A company can be strong in policy and weak in production control. Score each domain separately before you assign an overall level.

Govern

Accountability and decision rights

Executive ownership, business ownership, control ownership, approvals, exceptions, escalation, and retirement authority.

Govern and Map

Inventory and risk classification

Systems, models, vendors, intended use, affected users, data, locations, owners, status, and risk tier.

Map and Manage

Data, model, and vendor controls

Rights, quality, lineage, security, privacy, vendor evidence, concentration, change notice, continuity, and exit.

Measure

Evaluation and human oversight

Acceptance tests, representative cases, quality, safety, bias where relevant, override rights, and escalation tests.

Manage

Monitoring, incidents, and change

Production thresholds, alerts, reviewers, response times, incident exercises, change review, and stop conditions.

All functions

Evidence and improvement

Decision records, versions, approvals, tests, incidents, outcomes, independent review, and verified improvement.

Scoring method

Complete the scorecard in four steps.

  1. Set the scope. Name the business units, systems, jurisdictions, and review date.
  2. Collect evidence. Use current approvals, registers, tests, logs, incident records, and management reports.
  3. Score each domain. Select the highest level supported by evidence. Record the owner and artifact.
  4. Choose the next control. Fix the lowest material domain first. Give it an owner, due date, and acceptance test.

Overall score: use the lowest domain that can cause material harm, loss, delay, or non-compliance. An arithmetic average is useful for trend reporting, but it must not override a critical weakness.

Primary sources

Frameworks that inform the model.

This is an original operating model. It does not reproduce a standard and does not replace current legal or assurance advice.

  1. NIST AI Risk Management Framework 1.0Voluntary framework for managing AI risks and trustworthiness considerations.
  2. NIST AI RMF PlaybookSuggested actions aligned with Govern, Map, Measure, and Manage.
  3. ISO/IEC 42001:2023Official overview of the AI management system standard.
  4. European Commission: AI ActOfficial overview of the risk-based legal framework and implementation resources.
FAQ

AI governance maturity model questions.

What is an AI governance maturity model?

An AI governance maturity model is a structured method for assessing how consistently an organization assigns AI accountability, classifies systems, applies controls, measures performance, manages incidents, and retains evidence. It shows the current operating state and the next verifiable improvement. It does not prove legal compliance.

How should a company score AI governance maturity?

Score each domain from level 1 to level 5 using current evidence. Do not score from policy language alone. Record the owner and supporting artifact. Use the lowest material domain to set the overall maturity level because a high average can hide a critical control gap.

What are the five AI governance maturity levels?

The five levels in this model are Reactive, Defined, Controlled, Measured, and Adaptive. Reactive work depends on individuals. Defined work has common rules. Controlled work has named owners and operating evidence. Measured work tracks control performance. Adaptive work changes the system from verified results and incidents.

Does a high maturity score prove AI Act or ISO 42001 compliance?

No. This model is an operational assessment, not a certification or legal opinion. The EU AI Act applies by role, system type, risk category, use, and date. ISO IEC 42001 has its own requirements and certification process. Confirm applicability with qualified legal, risk, and assurance professionals.

Paul Okhrem, AI transformation consultant

About Paul Okhrem

Paul Okhrem is an AI Transformation Consultant and Fractional Chief AI Officer. He helps companies assign AI decision rights, controls, implementation gates, and evidence ownership.

The original wording and scoring structure are licensed under CC BY 4.0 with attribution to Paul Okhrem.