# Maturity Assessment **Purpose.** A structured baseline of how capable your governance actually is today, across the dimensions that matter, so you can prioritise honestly and show movement over time. **When to use it.** At programme start, then every six to twelve months. Also useful immediately after an incident, when appetite for investment is briefly high. **How to use it.** Score each dimension 0–4 against the descriptors, evidencing every score with something you could show an auditor. Score what is true, not what is intended — an optimistic baseline destroys the credibility of every later improvement you report. --- ### Maturity levels | Level | Name | Description | |---|---|---| | **0** | Absent | Nothing in place. | | **1** | Initial | Ad hoc, individual effort, undocumented. | | **2** | Developing | Documented but inconsistently applied. | | **3** | Defined | Standardised, applied consistently, evidenced. | | **4** | Managed | Measured, reviewed, and improved on evidence. | ### Assessment Score each dimension. Record evidence — a score without evidence is an opinion. | # | Dimension | Score (0–4) | Evidence | Target | Owner | |---|---|---|---|---|---| | 1 | Governance mandate & sponsorship | | | | | | 2 | Committee & decision rights | | | | | | 3 | Roles & accountability (RACI) | | | | | | 4 | Policy & standards coverage | | | | | | 5 | Data ownership & domains | | | | | | 6 | Data quality management | | | | | | 7 | Data classification & handling | | | | | | 8 | AI inventory & classification | | | | | | 9 | AI risk assessment process | | | | | | 10 | Model documentation | | | | | | 11 | Human oversight design | | | | | | 12 | Third-party / vendor AI risk | | | | | | 13 | Incident management | | | | | | 14 | Control library & assurance | | | | | | 15 | Board reporting | | | | | | 16 | AI literacy & training | | | | | | 17 | Regulatory readiness (EU AI Act) | | | | | ### Interpreting the result | Average | Posture | What to do next | |---|---|---| | **0.0–1.0** | Early | Establish mandate, inventory, and prohibited-practice screening before anything else. | | **1.1–2.0** | Developing | Close policy and documentation gaps; stand up the committee properly. | | **2.1–3.0** | Established | Shift from writing documents to evidencing that controls operate. | | **3.1–4.0** | Advanced | Focus on measurement, independent assurance, and continuous improvement. | ### Heat map Plot dimension against score to show the board where the thin ice is. The pattern usually matters more than the average: a 3.5 average hiding a 0 on inventory is worse than a flat 2. ### Re-assessment | Date | Average | Movement | Notes | |---|---|---|---| | [date] | | Baseline | | --- ## Adaptation notes - **Small organisations:** Drop dimensions 14 and 15 if you have no formal assurance function or board, and score the remaining 15. Do not score dimensions you have no realistic path to improving. - **Regulated sectors:** Add dimensions for model validation independence and regulatory reporting accuracy, and align the level descriptors with your supervisor's own maturity language where one exists. - **Using this with the assessment tool:** The role-based assessment scores obligation coverage; this scores organisational capability. They answer different questions — run both, and expect capability to lag coverage. --- *From the [Open Data & AI Governance Kit](https://lsdeva.github.io/governance-kit/). Licensed [CC BY 4.0](https://creativecommons.org/licenses/by/4.0/) — free to use, adapt, and share with attribution.* ***Not legal advice.** Adapt to your jurisdiction, sector, and risk appetite, and have qualified counsel review anything material.*