SECTION 07
07The assessment: measuring maturity
Twenty items, four dimensions, one sheet. Each statement is scored from 1 to 5, the average of each dimension is calculated, and then the organisation's level is the level of its weakest dimension — not the overall average. The rule is deliberate: capability is a chain, and a chain is measured by its weakest link.

Text in this figure
20 · Items, five per dimension · → · 1–5 · Scored on evidence, not intent · → · ×4 · Average per dimension · → · MIN · Level = weakest dimension
| SCORE | ENGLISH |
|---|---|
| 1 | Does not exist |
| 2 | Partly in place, undocumented |
| 3 | Documented and applied |
| 4 | Measured and reviewed periodically |
| 5 | Automated and self-improving |
Score on evidence, not intent: if you cannot point to a document, a record or an indicator, the score does not exceed 2.
| # | STATEMENT |
|---|---|
| A. AI governance | |
| A1 | An approved register captures every AI system in use, including third-party tools. |
| A2 | Every model has a named owner accountable for its risk to an internal oversight body. |
| A3 | Deploying any model passes through a documented, mandatory security review gate. |
| A4 | A known authority exists that can pull a model out of service immediately, without long escalation. |
| A5 | The board receives periodic reporting in indicators, not descriptions. |
| B. Cyber resilience | |
| B1 | Continuity plans cover the failure of a critical model or loss of trust in its outputs. |
| B2 | We can roll back to a trusted previous version of any production model within a defined time. |
| B3 | A simulation exercise involving an AI component was run during the past year. |
| B4 | Detection, containment and recovery times are measured and known to management. |
| B5 | Third-party dependencies and model vendors are managed within supply-chain risk. |
| C. Threat detection | |
| C1 | Behavioural baselines exist for users and systems, and deviation is raised as an alert. |
| C2 | Production model outputs are monitored for drift and accuracy degradation. |
| C3 | Training-data integrity and provenance are checked before every training cycle. |
| C4 | External threat intelligence is embedded in detection logic, not only in a monthly report. |
| C5 | We measure the true-positive rate and deliberately work to reduce noise. |
| D. Adaptive management | |
| D1 | Every incident ends in a review that produces a documented change to a control, policy or training. |
| D2 | The AI risk register is updated on a faster cadence than the annual cycle. |
| D3 | Repetitive response steps are automated through approved, auditable playbooks. |
| D4 | Security, data and product teams work through a shared escalation path, not separate channels. |
| D5 | Staff receive up-to-date training on AI risk and synthetic-media impersonation. |
Running the assessment workshop
Three hours is enough: one hour to gather evidence before the session, one hour to score the twenty items with the four role owners (security, data, technology and compliance), and one hour to set three priorities — only three.
| AVERAGE | LEVEL · PRIORITY |
|---|---|
| 1.0 – 1.9 | Initial — priority: inventory, policy and ownership. Do not start with tools. |
| 2.0 – 2.9 | Managed — priority: the pre-deployment review gate and training-data controls. |
| 3.0 – 3.9 | Defined — priority: measurement; turn documented controls into time-based indicators. |
| 4.0 – 5.0 | Quantitatively managed to cognitive-optimised — priority: automation and the proactive learning cycle. |
Document each dimension's result and the date of assessment, and reassess every six months. The difference between two assessments is the truest indicator that the programme is working. A dimension's level is its average rounded down: 2.6 is level 2.

Text in this figure
D1 · AI governance · 2.4 · D2 · Cyber resilience · 3.1 · D3 · Threat detection · 2.9 · D4 · Adaptive management · 2.2 · 0 · 1 · 2 · 3 · 4 · 5 · Enterprise level: 2 — the first investment goes to D4
Every score needs a source: an assessment with no evidence behind it produces a plan that solves a problem the organisation does not have.
Tip: use ← → to move between sections.
