Maturity Assessment¶
Ready
Purpose. A structured baseline of how capable your governance actually is today, across the dimensions that matter, so you can prioritise honestly and show movement over time.
When to use it. At programme start, then every six to twelve months. Also useful immediately after an incident, when appetite for investment is briefly high.
How to use it. Score each dimension 0–4 against the descriptors, evidencing every score with something you could show an auditor. Score what is true, not what is intended — an optimistic baseline destroys the credibility of every later improvement you report.
Fill it in here¶
Work directly in the browser — nothing is uploaded, and your rows are saved on this device. Download to Excel whenever you want, or save a file you can reopen later.
Loading the editable register…
The template¶
Maturity levels¶
| Level | Name | Description |
|---|---|---|
| 0 | Absent | Nothing in place. |
| 1 | Initial | Ad hoc, individual effort, undocumented. |
| 2 | Developing | Documented but inconsistently applied. |
| 3 | Defined | Standardised, applied consistently, evidenced. |
| 4 | Managed | Measured, reviewed, and improved on evidence. |
Assessment¶
Score each dimension. Record evidence — a score without evidence is an opinion.
| # | Dimension | Score (0–4) | Evidence | Target | Owner |
|---|---|---|---|---|---|
| 1 | Governance mandate & sponsorship | ||||
| 2 | Committee & decision rights | ||||
| 3 | Roles & accountability (RACI) | ||||
| 4 | Policy & standards coverage | ||||
| 5 | Data ownership & domains | ||||
| 6 | Data quality management | ||||
| 7 | Data classification & handling | ||||
| 8 | AI inventory & classification | ||||
| 9 | AI risk assessment process | ||||
| 10 | Model documentation | ||||
| 11 | Human oversight design | ||||
| 12 | Third-party / vendor AI risk | ||||
| 13 | Incident management | ||||
| 14 | Control library & assurance | ||||
| 15 | Board reporting | ||||
| 16 | AI literacy & training | ||||
| 17 | Regulatory readiness (EU AI Act) |
Interpreting the result¶
| Average | Posture | What to do next |
|---|---|---|
| 0.0–1.0 | Early | Establish mandate, inventory, and prohibited-practice screening before anything else. |
| 1.1–2.0 | Developing | Close policy and documentation gaps; stand up the committee properly. |
| 2.1–3.0 | Established | Shift from writing documents to evidencing that controls operate. |
| 3.1–4.0 | Advanced | Focus on measurement, independent assurance, and continuous improvement. |
Heat map¶
Plot dimension against score to show the board where the thin ice is. The pattern usually matters more than the average: a 3.5 average hiding a 0 on inventory is worse than a flat 2.
Re-assessment¶
| Date | Average | Movement | Notes |
|---|---|---|---|
| [date] | Baseline |
Adaptation notes¶
- Small organisations: Drop dimensions 14 and 15 if you have no formal assurance function or board, and score the remaining 15. Do not score dimensions you have no realistic path to improving.
- Regulated sectors: Add dimensions for model validation independence and regulatory reporting accuracy, and align the level descriptors with your supervisor's own maturity language where one exists.
- Using this with the assessment tool: The role-based assessment scores obligation coverage; this scores organisational capability. They answer different questions — run both, and expect capability to lag coverage.
Related¶
- Governance Charter — Draft
- Control Library & Assurance Map — Ready
- KPI / KRI Dashboard — Ready
- Board Pack Template — Ready
Not legal advice
These templates are a head start, not a substitute for professional judgement. Adapt them to your jurisdiction, sector, and risk appetite, and have qualified counsel review anything material before you rely on it.