Chapter 25. Maturity Assessment
Five levels defined by adopted mechanisms, not narrative, and how to place yourself honestly.
25.1 The levels
Each level is defined by which named mechanisms are actually in use. That makes self-assessment falsifiable: you either run independent countersignature or you do not.
Table 70. The levels
| Level | Defining characteristics |
|---|---|
| L1 Fragmented | No named AI governance role. Ad hoc process, no risk tiering. No shared artifacts, no telemetry. AI not recognized as an architecture domain |
| L2 Controlled | Part-time AI Governance Lead. S0–S2 tiering on new initiatives. G1–G3 informal. Manual artifact tracking. Single informal review body. Risk Classification Records exist but are unaudited |
| L3 Integrated | Full role catalogue staffed. Full G1–G5. Partial Control Plane with manual and some automated observation. ARB expanded to five domains, AI Governance Body stood up, independent countersignature adopted. Sixteen-record artifact set maintained. Value scorecard in use |
| L4 Adaptive | Procurement integrated. Iterative G2 sequencing in practice. Real Control Plane with automated observe, compare, evaluate. Machine-readable G3 boundaries enabling actual autonomy-change detection. Audit sampling of Tier 1–2 running. Regulatory Overlay Reference populated. Tier scores crosswalked to the enterprise risk register |
| L5 Continuously Assured | Roles shift from transaction review to exception handling and anchor calibration. Evidence-as-code throughout. Full telemetry. Enforce active for objectively defined preventive rules. Patterns cover most new builds. Real incident data recalibrating scoring anchors. Metrics validated against outcomes rather than asserted |
Two honest caveats. No organization has been observed progressing through these levels; the model is asserted design, not observed practice. And Level 5 is not autonomous governance. The conventional label for a top maturity level is rejected here as inconsistent with the framework’s own design, which permanently prohibits automated corrective enforcement for Tier 3–4 systems. Maturity means faster and better-evidenced human decisions, not fewer of them.
25.2 The single most useful discriminator
If you assess only one thing, assess whether independent countersignature of risk scores is actually happening.
It is the boundary between L2 and L3, and it is the control the framework’s own review identified as most load-bearing. An organization with a full artifact set, five gates, and two governance bodies but unaudited self-scoring is at L2 with L3 decoration. Every tier-scaled control it operates inherits the accuracy of a number nobody checked.
25.3 A self-assessment instrument
Answer yes only where the mechanism is in routine use, not where it exists on paper.
Table 71. A self-assessment instrument
| # | Question | Level indicated |
|---|---|---|
| 1 | Is there a named person accountable for AI governance? | L2 |
| 2 | Do new AI initiatives receive a risk tier before architecture work begins? | L2 |
| 3 | Is AI represented as a domain in architecture governance? | L2 |
| 4 | Are risk scores countersigned by someone independent of delivery? | L3 |
| 5 | Do all five gates operate, with authority scaled by tier? | L3 |
| 6 | Is the full primary record set maintained with named owners? | L3 |
| 7 | Is any deployed state automatically compared against approved state? | L3 |
| 8 | Are agent authority boundaries recorded machine-readably? | L4 |
| 9 | Is Tier 1–2 self-certification audit-sampled? | L4 |
| 10 | Is procurement routed into the lifecycle for embedded AI? | L4 |
| 11 | Are tier scores connected to the enterprise risk register? | L4 |
| 12 | Is most gate evidence captured automatically? | L5 |
| 13 | Have scoring anchors been recalibrated against your own incident data? | L5 |
| 14 | Do reference patterns cover the majority of new builds? | L5 |
Your level is the highest at which you can answer yes to every question at that level and below. Partial credit is how organizations convince themselves they are at L4 while operating at L2.