Reading progress
0 of 17 sections read
10 / 17

SECTION 07

07The assessment: measuring maturity

3 min read10 of 17

Twenty items, four dimensions, one sheet. Each statement is scored from 1 to 5, the average of each dimension is calculated, and then the organisation's level is the level of its weakest dimension — not the overall average. The rule is deliberate: capability is a chain, and a chain is measured by its weakest link.

FIGURE 6 — THE ASSESSMENT METHOD
FIGURE 6 — THE ASSESSMENT METHOD
Text in this figure

20 · Items, five per dimension · → · 1–5 · Scored on evidence, not intent · → · ×4 · Average per dimension · → · MIN · Level = weakest dimension

SCOREENGLISH
1Does not exist
2Partly in place, undocumented
3Documented and applied
4Measured and reviewed periodically
5Automated and self-improving
TABLE 2 — THE SCORING SCALE

Score on evidence, not intent: if you cannot point to a document, a record or an indicator, the score does not exceed 2.

#STATEMENT
A. AI governance
A1An approved register captures every AI system in use, including third-party tools.
A2Every model has a named owner accountable for its risk to an internal oversight body.
A3Deploying any model passes through a documented, mandatory security review gate.
A4A known authority exists that can pull a model out of service immediately, without long escalation.
A5The board receives periodic reporting in indicators, not descriptions.
B. Cyber resilience
B1Continuity plans cover the failure of a critical model or loss of trust in its outputs.
B2We can roll back to a trusted previous version of any production model within a defined time.
B3A simulation exercise involving an AI component was run during the past year.
B4Detection, containment and recovery times are measured and known to management.
B5Third-party dependencies and model vendors are managed within supply-chain risk.
C. Threat detection
C1Behavioural baselines exist for users and systems, and deviation is raised as an alert.
C2Production model outputs are monitored for drift and accuracy degradation.
C3Training-data integrity and provenance are checked before every training cycle.
C4External threat intelligence is embedded in detection logic, not only in a monthly report.
C5We measure the true-positive rate and deliberately work to reduce noise.
D. Adaptive management
D1Every incident ends in a review that produces a documented change to a control, policy or training.
D2The AI risk register is updated on a faster cadence than the annual cycle.
D3Repetitive response steps are automated through approved, auditable playbooks.
D4Security, data and product teams work through a shared escalation path, not separate channels.
D5Staff receive up-to-date training on AI risk and synthetic-media impersonation.
TABLE 3 — THE INSTRUMENT · ITEMS 11–20

Running the assessment workshop

Three hours is enough: one hour to gather evidence before the session, one hour to score the twenty items with the four role owners (security, data, technology and compliance), and one hour to set three priorities — only three.

AVERAGELEVEL · PRIORITY
1.0 – 1.9Initial — priority: inventory, policy and ownership. Do not start with tools.
2.0 – 2.9Managed — priority: the pre-deployment review gate and training-data controls.
3.0 – 3.9Defined — priority: measurement; turn documented controls into time-based indicators.
4.0 – 5.0Quantitatively managed to cognitive-optimised — priority: automation and the proactive learning cycle.
TABLE 4 — INTERPRETING THE RESULT

Document each dimension's result and the date of assessment, and reassess every six months. The difference between two assessments is the truest indicator that the programme is working. A dimension's level is its average rounded down: 2.6 is level 2.

FIGURE 7 — A FOUR-SCORE PROFILE (ILLUSTRATIVE)
FIGURE 7 — A FOUR-SCORE PROFILE (ILLUSTRATIVE)
Text in this figure

D1 · AI governance · 2.4 · D2 · Cyber resilience · 3.1 · D3 · Threat detection · 2.9 · D4 · Adaptive management · 2.2 · 0 · 1 · 2 · 3 · 4 · 5 · Enterprise level: 2 — the first investment goes to D4

Every score needs a source: an assessment with no evidence behind it produces a plan that solves a problem the organisation does not have.

Tip: use ← → to move between sections.