Governance & accountability
Who owns AI decisions and the consequences they create?
Without explicit accountability, committees can exist while material decisions remain ownerless.
AI / GOVERNANCE ASSESSMENT
Measure institutional readiness, expose control gaps and determine how far AI should be allowed to influence decisions and execution.
Pilots do not constitute governance. An organization becomes mature when accountability, risk, data, lifecycle controls, human intervention and evidence work together as an operating system.
Governance maturity should determine the operating perimeter of AI — not merely produce a score.

By José Ñáñez
Technology Advisor · Board Member
GOVERNANCE → PERIMETER
Assist
Recommend
Decide
Execute
THE REAL QUESTION
Most institutions can point to an AI policy, a committee or a list of pilots. Those are useful signals, but they do not prove that AI is governable at scale. The harder question is whether the organization knows who is accountable, how use cases are classified, what evidence is required before production, when humans must intervene and how the institution responds when a system behaves differently from what was intended.
That distinction becomes more important as AI moves from assistance to recommendation, decision and execution. A weak control in a summarization tool may create inconvenience. The same weakness in an agent that changes a customer record, approves a workflow or initiates a financial action can create a materially different consequence.
This assessment therefore measures more than policy maturity. It evaluates whether the organization has built enough institutional capability to support progressively more consequential AI operating models.
The maturity milestone is not “we have AI governance.” It is “we know what AI is allowed to do, under which controls, with what evidence and who remains accountable.”
MATURITY MODEL
The model expands the prior five-domain assessment into seven operating domains. The weights are explicit. Five domains act as a critical control floor because weakness in them can constrain safe execution even when the overall score is high.
Who owns AI decisions and the consequences they create?
Without explicit accountability, committees can exist while material decisions remain ownerless.
Does control intensity change with consequence?
If use cases are not classified, low-risk assistants and high-consequence decision systems can receive the same controls.
Can the institution trust and reconstruct the information AI uses?
Governance fails when models are controlled but the data, context or enterprise knowledge they consume are not.
Can AI be changed, restricted or rolled back safely?
Production maturity requires versioning, testing, deployment discipline and explicit rollback—not only model approval.
Where does software stop and accountable human judgment begin?
“Human in the loop” is not a control unless triggers, authority, context transfer and intervention mechanisms actually work.
Can the institution see what AI did and respond when it fails?
Material AI requires continuous evidence, operational thresholds and incident routines—not periodic model review alone.
Does governance help the organization scale value rather than merely approve technology?
Governance becomes sustainable when business value, risk and control evidence are reviewed together.
MODEL MECHANICS
The assessment uses a 0–4 operating scale, weighted domain scores and a separate critical-control floor. The operating perimeter is derived only after all 28 questions are answered.
Response scale
Not present
No meaningful practice, ownership or evidence exists.
Ad hoc
The practice depends on individuals, isolated teams or informal judgment.
Defined in parts
A documented practice exists, but coverage or execution is inconsistent.
Operating consistently
The practice is active, repeatable and normally evidenced across relevant use cases.
Institutionalized
The practice is embedded, monitored, auditable and continuously improved.
Domain score = average(question scores in domain) ÷ 4 × 100Each domain has four questions. A complete domain therefore produces a normalized score from 0 to 100.
Overall maturity = Σ(domain score × domain weight)Weights total 100%. Risk and materiality receive the highest weight because weak classification can expose the institution before other controls are applied.
Critical floor = minimum(risk, data, lifecycle, human intervention, monitoring)A strong average cannot compensate for a severe weakness in a control domain required for consequential AI.
Permitted operating mode = f(overall maturity, critical floor, monitoring readiness)The assessment does not use maturity as a direct authorization. It applies minimum score and control-floor thresholds to progressively more consequential operating modes.
This is an executive diagnostic model, not a certification, legal opinion, regulatory determination or substitute for a use-case-specific risk assessment.
EXECUTIVE INSTRUMENT
Answer all 28 questions using current evidence—not future plans. The model will calculate maturity, the weakest control floor, the operating perimeter and the next governance actions.
A high score is not the objective. The objective is to identify the next level of AI consequence the organization can support without pretending that missing controls do not matter.
Assessment progress
0 / 28 questions answered
Current domain · 01
Who owns AI decisions and the consequences they create?
Domain score
—
Does the organization maintain a current inventory of material AI systems and use cases?
Does every material AI use case have a named business owner with explicit accountability for outcomes?
Are decision rights defined across business, technology, risk, compliance, security and audit?
Does senior leadership receive recurring reporting that connects AI value, risk, incidents and control posture?
Calculation trace
The score is reconstructable. Each completed domain shows its question average, normalized score, weight and contribution to the overall result.
Governance & accountability
15% weight
0/4 questions answered—Risk, materiality & policy
20% weight
0/4 questions answered—Data & knowledge controls
15% weight
0/4 questions answered—Model lifecycle & AgentOps
15% weight
0/4 questions answered—Human intervention & execution control
15% weight
0/4 questions answered—Monitoring, evidence & incident response
10% weight
0/4 questions answered—Value, portfolio & scale
10% weight
0/4 questions answered—Operating-perimeter thresholds
Assist: overall ≥ 25 and critical floor ≥ 25Recommend: overall ≥ 45 and critical floor ≥ 37.5Bounded decision: overall ≥ 65 and critical floor ≥ 62.5Bounded execution: overall ≥ 75, critical floor ≥ 75 and monitoring ≥ 75High-materiality autonomy: never authorized by enterprise maturity score aloneHOW TO READ THE RESULT
Two organizations can obtain the same overall score and still have different operating perimeters. One may have strong strategy and value management but weak human intervention. Another may have solid controls but weak executive ownership. The aggregate matters, but the floor determines where consequence must stop.
This is why the model keeps overall maturity and critical-control readiness separate. Governance should enable useful AI to scale, but it should also make explicit where the organization is not yet ready to delegate a decision or an action.
A maturity score tells you how developed the system is. The control floor tells you how much consequence it can safely absorb.
RESEARCH CONTEXT
The assessment is an original executive model. It is not a reproduction of any one standard. Its domains reflect recurring governance requirements across major AI risk and management frameworks.
Model boundaries
The weights and operating-perimeter thresholds are part of this executive assessment model; they are not regulatory thresholds or industry standards.
The assessment measures institutional capability at an enterprise level. A specific AI system may require stricter controls because of product, customer, jurisdiction, materiality or legal requirements.
The assessment should be supported with evidence. A self-reported score without documentation is a hypothesis, not proof of control effectiveness.
High-materiality autonomous execution is deliberately not authorized by the enterprise maturity score alone.
THESIS
Governance should not slow AI down by treating every use case the same. It should make consequence explicit, strengthen the weakest control and expand the operating perimeter only when evidence supports it.
The objective is not to reach Level 5 on a slide. It is to know what the institution can safely allow AI to do next.
José Ñáñez