An AI governance maturity model should reveal what an organization can reliably do, not reward the number of policies it has written. Maturity is visible in repeated decisions, clear ownership, working controls, and evidence from real use cases.
Assess maturity across eight capabilities: ownership, use-case inventory, risk classification, approval, testing, monitoring, incidents, and workforce capability.
Level 1: Ad hoc
AI use is scattered and mostly invisible. Decisions depend on individual judgment. There is no dependable inventory, risk tier, or escalation path. Training is optional and policies are broad or absent.
Evidence to advance: name an accountable executive and operational owner, publish interim safe-use rules, and create an initial workflow inventory.
Level 2: Defined
The organization has a policy, approved-tool list, intake process, and basic risk categories. Responsibilities exist on paper, but adoption varies by function and evidence is inconsistent.
Evidence to advance: test the intake process on representative use cases, define decision rights, set service levels, and train managers and reviewers.
Level 3: Operational
Governance is embedded in delivery. Higher-risk use cases receive documented assessment and testing. Owners can show approvals, controls, monitoring, and incident procedures. Employees know where to ask questions.
Evidence to advance: measure control performance, review exceptions, and connect governance findings to platform, training, and workflow decisions.
Level 4: Measured
The organization uses portfolio-level data to improve decisions. Leaders can see use-case value, residual risk, review time, control failures, incidents, and adoption. Standards are calibrated using real outcomes.
Evidence to advance: benchmark recurring failure modes, automate reliable evidence collection, and use leading indicators before incidents occur.
Level 5: Adaptive
Governance changes with the technology and operating environment. Teams can introduce new models, agents, and workflows through a proportionate process. Lessons from monitoring and incidents improve design, training, policy, and investment.
Avoid false maturity
Centralization is not automatically mature. A large committee can still make slow, inconsistent decisions. Automation is not automatically mature either; automating an unclear process produces faster confusion.
Score each capability separately. An organization may have strong security review and weak workforce adoption, or a complete inventory and weak monitoring. The lowest critical capability may determine the practical risk of the portfolio.
Run the assessment
For each capability, request an artifact and a recent example. Interview both governance owners and business teams. Score observed practice, not intended practice. Then choose three improvements with owners, dates, and measurable completion evidence.
Maturity improves when useful AI can move through the organization faster because the rules, owners, and evidence are clearer.