Logiciel Solutions Contact Us
Success Stories Tech News Investors Contact Us
framework

AI Governance Maturity Assessment.

Most AI governance assessments are answered from memory in a leadership meeting. Nobody sets an evidence bar, so intent, practice and enforcement all collapse into the same number, and eight domains get averaged into one figure that goes upward as a trend. Then an enterprise customer asks not for your score but for the artifact behind three statements they pick themselves, and the room cannot produce any of the three. The question was never "how mature do we feel". It is "what could we show somebody", and that has a measurable answer.

In depth

Everyone Scores Themselves A Three. The Evidence Column Decides.

01

What happens by default: the score is remembered, not evidenced.

Teams rate intent and practice and enforcement as the same thing, average eight domains into one headline number, and present it as a trend line. Shadow AI and embedded SaaS AI sit outside the denominator because counting them makes the number worse. A score with no evidence column is a feeling with a number attached.

In shortA score with no evidence column is a feeling with a…
02

What good scoring does: it fixes the evidence bar before anything is rated.

A three means written down and assigned to a role; a four means enforced by something other than a person remembering. You score the whole estate rather than the strongest squad, count shadow AI inside the denominator, and record the evidence reference beside every score so the assessment doubles as your audit index. Then you read the lowest domain rather than the mean, because that is the one a reviewer, a regulator and an incident all find first.

In shorta regulator and an incident all find first
The detail

What Separates A Scored Instrument From A Questionnaire.

Three design choices do the work. Each one is the reason a score produced this way survives somebody checking it.

Zone · 01

The evidence scale

Zero is absent and unowned. One is intent with no owner and no date. Two is informal, happening because one person does it and stopping when they get busy. Three is defined: written, assigned to a role, followed in the normal case. Four is verified, enforced by a gate in CI, an access control or a review with a record. The step from two to three is documentation. The step from three to four is what survives an audit.

Zone · 02

The floor

not the average

A total of 104 built from eight scores of 13 is a different company from a 104 built from five scores of 18 and three of 4.7, and the second is in more trouble. Reviews, regulators and incidents all probe the weakest domain rather than the mean. Any single domain below 10 out of 20 is the headline finding regardless of the total.

Zone · 03

Shadow AI inside the denominator

Consumer chat tools, a marketing team's unreviewed vendor, an engineer's personal API key and the AI feature your SaaS provider switched on last quarter are all in scope. Registry coverage, meaning systems in the register divided by systems found in an independent sweep, is the one metric that tests whether everything else measures the whole estate.

By the numbers

The figures that make it a board-level conversation.

12%
of enterprises have mature AI governance processes in place
68%
of organisations have no AI governance able to manage AI or detect shadow AI, up from 63%
2.84x
return on AI investment with a structured governance framework, against 0.84x without
Inside the report

What you'll take away.

01

Step 1 - Get the right four people in one room

The engineering leader who owns the AI surface chairs it, with a security lead, whoever answers customer security questionnaires, and one product manager who owns an AI-facing feature.

02

Step 2 - Score all forty statements against the evidence scale

Work through eight domains. Score by consensus rather than average, and where the room disagrees take the lower score and write down why, because that disagreement is usually the real finding.

03

Step 3 - Read the floor before you read the total

Transfer the eight subtotals, total out of 160, then check for any domain below 10 out of 20. That domain is your finding regardless of what the headline number says.

04

Step 4 - Convert the weakest domain into next quarter

Use the band-specific plan to sequence days 1-30, 31-60 and 61-90, then re-score quarterly and keep every scorecard so the trend is provable.

Questions

Frequently asked.

How is this different from a free maturity model from a vendor or a Big Four firm?

Two things. The evidence scale, because most models let you score intent, which is why most companies self-report as Defined and then fail an evidence-based review. And the sizing: this assumes no chief risk officer, no model validation function and no internal audit, because at 200 to 1,000 people you have none of those and a model that assumes them produces a plan you cannot execute.

Do we need a finished AI inventory before we can score ourselves?

No, and waiting for one means never starting. One of the eight domains is the inventory domain, so an incomplete register simply scores low and becomes your first finding. What matters is honesty about the denominator: score against your best estimate of the whole estate, not against the systems you happen to know about.

Who needs to be in the room?

Four people. The engineering leader who owns the AI surface chairs it, plus a security or IT lead, whoever answers customer security questionnaires, and one product manager who owns an AI-facing feature. Score by consensus, and take the lower number wherever the room disagrees.

Does a good score here help with ISO 42001 certification?

It tells you whether certification is worth starting. Certifying below roughly 112 is expensive theatre, because the audit surfaces the same gaps you would have found here for free. Above that, the assessment plus its framework crosswalk is a credible gap-assessment starting point and the evidence references become the index a certification body asks for.

How often should we re-score?

Quarterly for the first year, then semi-annually once no domain sits below 14. Also after any material change: a new model provider, a first agentic deployment, an acquisition, or entry into a regulated vertical. Keep every completed scorecard, because the trend line is worth more in a customer conversation than any single score.

We are a security team, not a governance function. Is there a version for us?

Yes. The AI Security Maturity Assessment uses the same scale and bands so the two results are comparable. Governance asks whether you are building the right things with the right oversight; security asks what happens when someone attacks what you already shipped. Most companies need both numbers and they are rarely the same.

Get the framework

Have it emailed to you.

Drop your details and we'll send AI Governance Maturity Assessment straight to your inbox - no spam, unsubscribe anytime.

Download framework
Next step

A score you cannot evidence is a score you cannot defend.

Talk through your result with our engineering leads once you have scored it, and we will work through the weakest domain with you. A working session, not a sales pitch. SECTION 7 - FAQ - 5 to 8 questions

Talk to our engineers