24-Month Roadmap Builder
Turn assessment results into a phased, owned roadmap.
How it works
- 1
Your profile
Your saved UCSMM self-assessment is read from this browser, or you enter the four dimension levels by hand.
- 2
Balance before height
Only the dimensions at the weakest level are raised, one level only; the lowest-scored statements become the actions.
- 3
Owners and months
Give each action one name and a target month, track its status, and export the roadmap.
Roadmap builder
Your 24 months, wave by wave.
Everything stays in this browser. One name per action: "the team is responsible" means in practice that nobody is.
- Wave 1 · Months 0–3
Visibility
Inventory every AI system in use, including what business units adopted without security's knowledge. Assign an owner to each. Run the assessment and document each dimension's result. Draft a use and deployment policy.
ActionOwnerTarget monthStatusAInventory every AI system in use, including what business units adopted without security's knowledge.AAssign an owner to each system.ADraft a use and deployment policy.A1We keep an approved register of every AI system we use, third-party tools included.A2We name an owner for every model, who answers for its risk to an internal oversight body.A4We know who can pull a model out of service on the spot, without a long escalation.B5We manage our third-party dependencies and model vendors as supply-chain risk.·Run the assessment and document each dimension's result.Auditable outputs · Month 3Due at the end of the wave. No level is claimed without them.
Applying this wave: Start the inventory from the business units, not the data centre: the tools marketing or HR bought on a monthly subscription are the ones most absent from the records, and the closest to sensitive data.
- Wave 2 · Months 4–12
Control
A pre-deployment security review gate, graduated by impact. Controls for training-data integrity and provenance. Model drift monitoring in production. An AI scenario in the response plan and one simulation exercise.
ActionOwnerTarget monthStatusAA pre-deployment security review gate, graduated by impact.A3We put every model through a documented security review before it goes live, with no exceptions.BAn AI scenario in the response plan and one simulation exercise.B1Our continuity plans cover a critical model failing, or our losing trust in what it produces.B2We can roll any live model back to a version we trust, inside a time we have fixed.B3We ran a simulated incident involving an AI component within the past year.CControls for training-data integrity and provenance.CModel drift monitoring in production.C2We watch what our live models produce for drift and for accuracy slipping.C3We check where our training data came from and that it is sound before every training run.D4Our security, data and product teams escalate down one shared path, not three separate channels.D5We train our people on AI risk and on impersonation by synthetic media, and we keep the training current.Auditable outputs · Month 12Due at the end of the wave. No level is claimed without them.
Applying this wave: The decisive choice in the second wave is designing the gate so it is not routed around: light review for low-impact models, full review for critical ones. A gate that treats everything equally is abandoned within six months.
- Wave 3 · Months 13–24
Adaptation
Automate repetitive response paths. Enterprise-wide behavioural analytics. Proactive simulation of attack scenarios against models. A quarterly learning cycle that adjusts controls. Reassessment against the baseline.
ActionOwnerTarget monthStatusA5We report to the board on a regular cycle in indicators, not descriptions.BProactive simulation of attack scenarios against models.B4We measure how long detection, containment and recovery take, and management knows the numbers.CEnterprise-wide behavioural analytics.C1We hold behavioural baselines for users and systems, and anything off them raises an alert.C4We feed outside threat intelligence into the detection logic itself, not only into a monthly report.C5We measure how many of our alerts are real, and we work deliberately at cutting the noise.DAutomate repetitive response paths.DA quarterly learning cycle that adjusts controls.D1We close every incident with a review that changes a control, a policy or the training — and we write the change down.D2We update the AI risk register more often than once a year.D3We automate the response steps we repeat, through approved playbooks an auditor can follow.·Reassessment against the baseline.Auditable outputs · Month 24Due at the end of the wave. No level is claimed without them.
Applying this wave: By the end of the third wave one question must be answered with a number: how much did the weakest dimension improve in two years? If the answer has no number, the programme produced activity, not capability.
The wave activities and outputs are the study’s (Fig. 8). Placing each of the twenty statements in a wave is this tool’s reading of the figure and of the evidence each level requires.
Three rules the plan follows
Three rules the roadmap keeps.
- 1
No skipping
Tools can produce an apparent level four on top of level-two governance, and that is more fragile than nothing, because it creates the illusion of safety.
- 2
Balance before height
Raise the weakest dimension before improving the strongest; enterprise resilience is set by its weakest dimension, not its average.
- 3
Evidence before declaration
Claim no level without an auditable output behind it: a document, a record, or a measured indicator.
Decision rights
Every answer is a name, not a committee.
Governance is not the writing of a policy. It is the answer to four questions with names and dates: who decides to deploy the model, who monitors it afterwards, who owns stopping it, who is informed when it fails.
- 1
Approving deployment of a high-impact model
Consulted: model owner · security · legal
- AI governance committee
- 2
Classifying training-data sensitivity
Consulted: security · privacy
- Data owner
- 3
Withdrawing a model from service
Informed: CEO · business owner
- CISO — sole authority
- 4
Accepting residual risk
Informed: committee · internal audit
- Executive business owner, in writing
- 5
Escalating to the board
Informed: the board · audit
- Risk committee
The four most expensive mistakes
Four mistakes to steer around.
Starting with the tool
An advanced platform over an incomplete inventory watches part of the organisation and gives full confidence.
Separating security from the data team
Builder and protector must meet in one path, or governance becomes bureaucracy to route around.
A one-off assessment
A number with no number after it is a photograph of a moving environment.
Ignoring the shadow
The most dangerous AI systems in an organisation are the ones nobody knows exist.
About the roadmap
The three waves, their auditable outputs, the rules for crossing levels and the decision rights come from my UCSMM Applied Research Study (2026), Sections 06–09 · registered with the UAE Ministry of Economy and Tourism, certificate 3414-2026.
Elgendi, M. F. (2026). UCSMM: An applied research study for the AI-powered post-digital enterprise (Registration No. 3414-2026). Fawzooz.
