Back to AI

AI / GOVERNANCE ASSESSMENT

AI Governance Maturity Assessment

Measure institutional readiness, expose control gaps and determine how far AI should be allowed to influence decisions and execution.

Pilots do not constitute governance. An organization becomes mature when accountability, risk, data, lifecycle controls, human intervention and evidence work together as an operating system.

Governance maturity should determine the operating perimeter of AI — not merely produce a score.
Portrait of José Ñáñez

By José Ñáñez

Technology Advisor · Board Member

Published April 7, 2026 · Updated August 23, 202610 min read

GOVERNANCE → PERIMETER

01Institutional capability
02Critical control floor
03Operating evidence
04Permitted AI perimeter

Assist

Recommend

Decide

Execute

THE REAL QUESTION

The issue is not whether the organization has an AI policy

Most institutions can point to an AI policy, a committee or a list of pilots. Those are useful signals, but they do not prove that AI is governable at scale. The harder question is whether the organization knows who is accountable, how use cases are classified, what evidence is required before production, when humans must intervene and how the institution responds when a system behaves differently from what was intended.

That distinction becomes more important as AI moves from assistance to recommendation, decision and execution. A weak control in a summarization tool may create inconvenience. The same weakness in an agent that changes a customer record, approves a workflow or initiates a financial action can create a materially different consequence.

This assessment therefore measures more than policy maturity. It evaluates whether the organization has built enough institutional capability to support progressively more consequential AI operating models.

The maturity milestone is not “we have AI governance.” It is “we know what AI is allowed to do, under which controls, with what evidence and who remains accountable.”

MATURITY MODEL

Seven domains connect policy to operating capability

The model expands the prior five-domain assessment into seven operating domains. The weights are explicit. Five domains act as a critical control floor because weakness in them can constrain safe execution even when the overall score is high.

01

Governance & accountability

15% Weight

Who owns AI decisions and the consequences they create?

Without explicit accountability, committees can exist while material decisions remain ownerless.

02

Risk, materiality & policy

20% WeightCritical floor

Does control intensity change with consequence?

If use cases are not classified, low-risk assistants and high-consequence decision systems can receive the same controls.

03

Data & knowledge controls

15% WeightCritical floor

Can the institution trust and reconstruct the information AI uses?

Governance fails when models are controlled but the data, context or enterprise knowledge they consume are not.

04

Model lifecycle & AgentOps

15% WeightCritical floor

Can AI be changed, restricted or rolled back safely?

Production maturity requires versioning, testing, deployment discipline and explicit rollback—not only model approval.

05

Human intervention & execution control

15% WeightCritical floor

Where does software stop and accountable human judgment begin?

“Human in the loop” is not a control unless triggers, authority, context transfer and intervention mechanisms actually work.

06

Monitoring, evidence & incident response

10% WeightCritical floor

Can the institution see what AI did and respond when it fails?

Material AI requires continuous evidence, operational thresholds and incident routines—not periodic model review alone.

07

Value, portfolio & scale

10% Weight

Does governance help the organization scale value rather than merely approve technology?

Governance becomes sustainable when business value, risk and control evidence are reviewed together.

MODEL MECHANICS

The scoring model is intentionally transparent

The assessment uses a 0–4 operating scale, weighted domain scores and a separate critical-control floor. The operating perimeter is derived only after all 28 questions are answered.

Response scale

0

Not present

No meaningful practice, ownership or evidence exists.

1

Ad hoc

The practice depends on individuals, isolated teams or informal judgment.

2

Defined in parts

A documented practice exists, but coverage or execution is inconsistent.

3

Operating consistently

The practice is active, repeatable and normally evidenced across relevant use cases.

4

Institutionalized

The practice is embedded, monitored, auditable and continuously improved.

01

Domain score

Domain score = average(question scores in domain) ÷ 4 × 100

Each domain has four questions. A complete domain therefore produces a normalized score from 0 to 100.

02

Overall maturity

Overall maturity = Σ(domain score × domain weight)

Weights total 100%. Risk and materiality receive the highest weight because weak classification can expose the institution before other controls are applied.

03

Critical control floor

Critical floor = minimum(risk, data, lifecycle, human intervention, monitoring)

A strong average cannot compensate for a severe weakness in a control domain required for consequential AI.

04

Operating perimeter

Permitted operating mode = f(overall maturity, critical floor, monitoring readiness)

The assessment does not use maturity as a direct authorization. It applies minimum score and control-floor thresholds to progressively more consequential operating modes.

This is an executive diagnostic model, not a certification, legal opinion, regulatory determination or substitute for a use-case-specific risk assessment.

EXECUTIVE INSTRUMENT

Assess the organization as it operates today

Answer all 28 questions using current evidence—not future plans. The model will calculate maturity, the weakest control floor, the operating perimeter and the next governance actions.

A high score is not the objective. The objective is to identify the next level of AI consequence the organization can support without pretending that missing controls do not matter.

Assessment progress

0 / 28 questions answered

Current domain · 01

Governance & accountability

Who owns AI decisions and the consequences they create?

Domain score

01

Does the organization maintain a current inventory of material AI systems and use cases?

02

Does every material AI use case have a named business owner with explicit accountability for outcomes?

03

Are decision rights defined across business, technology, risk, compliance, security and audit?

04

Does senior leadership receive recurring reporting that connects AI value, risk, incidents and control posture?

Calculation trace

The score is reconstructable. Each completed domain shows its question average, normalized score, weight and contribution to the overall result.

Governance & accountability

15% weight

0/4 questions answered

Risk, materiality & policy

20% weight

0/4 questions answered

Data & knowledge controls

15% weight

0/4 questions answered

Model lifecycle & AgentOps

15% weight

0/4 questions answered

Human intervention & execution control

15% weight

0/4 questions answered

Monitoring, evidence & incident response

10% weight

0/4 questions answered

Value, portfolio & scale

10% weight

0/4 questions answered

Operating-perimeter thresholds

01Assist: overall ≥ 25 and critical floor ≥ 25
02Recommend: overall ≥ 45 and critical floor ≥ 37.5
03Bounded decision: overall ≥ 65 and critical floor ≥ 62.5
04Bounded execution: overall ≥ 75, critical floor ≥ 75 and monitoring ≥ 75
05High-materiality autonomy: never authorized by enterprise maturity score alone

HOW TO READ THE RESULT

Maturity is a constraint system, not a leaderboard

Two organizations can obtain the same overall score and still have different operating perimeters. One may have strong strategy and value management but weak human intervention. Another may have solid controls but weak executive ownership. The aggregate matters, but the floor determines where consequence must stop.

This is why the model keeps overall maturity and critical-control readiness separate. Governance should enable useful AI to scale, but it should also make explicit where the organization is not yet ready to delegate a decision or an action.

A maturity score tells you how developed the system is. The control floor tells you how much consequence it can safely absorb.

RESEARCH CONTEXT

The model is informed by established governance frameworks

The assessment is an original executive model. It is not a reproduction of any one standard. Its domains reflect recurring governance requirements across major AI risk and management frameworks.

Model boundaries

01

The weights and operating-perimeter thresholds are part of this executive assessment model; they are not regulatory thresholds or industry standards.

02

The assessment measures institutional capability at an enterprise level. A specific AI system may require stricter controls because of product, customer, jurisdiction, materiality or legal requirements.

03

The assessment should be supported with evidence. A self-reported score without documentation is a hypothesis, not proof of control effectiveness.

04

High-materiality autonomous execution is deliberately not authorized by the enterprise maturity score alone.

THESIS

Governance should not slow AI down by treating every use case the same. It should make consequence explicit, strengthen the weakest control and expand the operating perimeter only when evidence supports it.

The objective is not to reach Level 5 on a slide. It is to know what the institution can safely allow AI to do next.

José Ñáñez