Five maturity levels, six dimensions to score, and the imbalance patterns that predict audit findings
Organizations setting out to build AI governance run into the same question before any other: "Where are we now, and what should we do first?" Without knowing the starting point, there is no way to design the route. An AI governance maturity model answers that question — it measures how systematically and responsibly the organization currently governs its AI, and points to what the next level requires. This article lays out a five-level model, a six-dimension self-assessment you can run this week, and the score patterns that tend to predict ISO/IEC 42001 audit findings.
What a maturity model does
A maturity model assesses AI governance capability across several dimensions, in defined stages. It serves two purposes: it establishes an objective picture of where the organization stands, and it converts that picture into a concrete direction — what has to change to reach the next level. Used that way, it is both the starting point for ISO/IEC 42001 preparation and the compass for continual improvement after certification.
The five maturity levels
Level 1 — Initial
No formal AI governance exists; AI use depends on individual or team judgment. There is no AI policy, no systematic risk assessment has ever been performed, leadership has no visibility into where AI is used, and incidents are handled ad hoc. ISO 42001 readiness: not ready — the foundations come first.
Level 2 — Aware
The organization recognizes that AI governance matters and has produced some policies or guidelines, but they are not applied consistently. A policy document exists but sees little use, some AI systems get informal risk reviews, ownership of AI governance is unassigned or unclear, and each department runs AI its own way. ISO 42001 readiness: early stage — the pieces exist but need to become a system.
Level 3 — Defined
Policies, processes, and roles are formally defined and documented; consistent execution is still the open challenge. The AI policy is approved and published, the risk assessment procedure is documented, an owner or committee is in place, and governance covers most AI systems. ISO 42001 readiness: certification preparation can begin — commonly six to nine months of work, depending on scope and organization.
Level 4 — Managed
Governance operates consistently across the organization, and performance is measured and monitored. Every AI system gets risk and impact assessment, AI objectives are quantitative and tracked, internal audits and management reviews run on schedule, and corrective action works. This is broadly the level ISO/IEC 42001 certification demonstrates. ISO 42001 readiness: certifiable — often within three to six months, depending on the certification body's schedule and audit scope.
Level 5 — Optimizing
AI governance is integrated with strategy and improves continuously. Governance performance feeds management decisions in near real time, risk management is predictive rather than reactive, the organization handles ISO/IEC 42001, the EU AI Act, and other applicable regulation as one integrated program, and it shares its governance posture transparently with external stakeholders. ISO 42001 readiness: sustaining and extending certification — multi-standard, integrated operation.
The self-assessment: six dimensions, scored 1–5
Score each item from 1 to 5, where 1 means absent, 3 means partial or informal, and 5 means systematic, documented, and embedded. The anchors below describe what a 5 looks like.
Dimension 1 — Leadership and governance structure
- AI policy — approved, published, and known across the organization
- Governance structure — a functioning committee, not just a named contact
- Top-management involvement — active and regular, not occasional
- Budget and resources — formally allocated to AI governance
Dimension 2 — Risk management
- AI risk assessment — performed regularly, across all AI systems
- AI-specific risks — bias, opacity, oversight failure fully covered, not just generic IT risk
- Risk treatment — a formal plan with implementation records
- AI impact assessment — performed for every in-scope system
If this dimension is where your scores sag, a structured AI risk assessment methodology is the fastest fix.
Dimension 3 — Transparency and explainability
- Disclosure of AI use — systematic notice wherever AI affects people
- Explanation of decisions — the organization can explain outcomes to those affected
- Appeal channels — a formal procedure for contesting AI-driven decisions
Dimension 4 — Human oversight
- Oversight mechanisms — formal procedures with records, not informal review
- High-risk AI controls — mandatory review gates for high-risk uses
- Automated decision controls — defined limits on what runs without a human
Dimension 5 — Competence and culture
- AI ethics training — regular, for all staff
- Specialist competence — qualified people in AI governance roles
- Culture — responsible-AI thinking embedded across the organization, not confined to one team
Dimension 6 — Monitoring and improvement
- Performance measurement — regular, reported
- Internal audit — at least annual, on a schedule (our internal audit checklist covers how)
- Management review — regular, minuted
- Improvement — systematic and preventive, not incident-driven
Reading your score
Average the dimension scores:
- 1.0–1.8 — Level 1 (Initial). Start with an AI policy and an AI system inventory.
- 1.9–2.6 — Level 2 (Aware). Design the governance structure; formalize risk assessment.
- 2.7–3.4 — Level 3 (Defined). Extend coverage organization-wide, build measurement, begin ISO 42001 preparation.
- 3.5–4.2 — Level 4 (Managed). Pursue ISO 42001 certification; consider multi-standard integration.
- 4.3–5.0 — Level 5 (Optimizing). Sustain, share externally, keep innovating.
The patterns matter more than the average
The average hides the most useful information. A dimension stuck near 1 while others sit at 4 is where an ISO/IEC 42001 audit will concentrate its findings — and three imbalance patterns come up repeatedly.
Documents without operation. Leadership and governance structure scores 4; monitoring and improvement scores 1. The policies and procedures are impeccable, but nothing is measured and nothing runs on schedule. This is the gap behind the most common ISO 42001 audit nonconformities — the distance between what is written and what is practiced.
Technology without governance. Competence and culture scores 4; leadership and governance scores 1. The teams building AI are excellent; the management layer above them is absent. Common in AI-native startups, and it surfaces in audits as missing policy, missing oversight structure, and missing management review.
Operation without transparency. Risk management scores 4; transparency and explainability scores 1. AI is well controlled internally, but people affected by it are told nothing. This pattern turns painful under the EU AI Act's transparency obligations — and it is increasingly the pattern regulators probe first.
What moving up a level actually takes
Level 1 → 2: build the AI system inventory, draft the AI policy and get top-management approval, assign an AI governance owner, and take stock of any ISO management systems you already hold.
Level 2 → 3: formalize the AI risk assessment procedure, run AI awareness training for all staff, set measurable AI objectives, and establish supplier management for external AI services.
Level 3 → 4 (the certification level): extend governance to every AI system, stand up a regular internal audit program, make management review routine, and prepare for the certification audit itself.
Level 4 → 5: build near-real-time governance dashboards, integrate ISO/IEC 42001 with ISO/IEC 27001 and applicable regulation such as the EU AI Act into one program, share good practice externally, and participate in the standards community.
Four tips for running the assessment well
Run it annually, before management review. The results give top management an immediate, intuitive picture of where AI governance stands — exactly what a management review input should do.
Score it with more than one department. Legal, HR, compliance, and the business should score alongside the AI team. Where their scores diverge is itself a finding: a dimension the AI team rates 4 and legal rates 2 is telling you something.
Validate the self-assessment externally. Self-scoring drifts optimistic. Before decisions that depend on the answer — certification timing above all — cross-check against an independent gap analysis or structured external assessment. A flattering self-score helps no one: the level you talk yourself into is the finding an auditor talks you out of.
Read patterns, not totals. The weak dimension, and how it connects to your actual business risk, is worth more than the average ever will be.
The bottom line
A maturity self-assessment answers "where are we?" — and a low score is not a verdict, it is a starting point. Knowing your true position is the first step toward moving in the right direction. Link the result to an ISO/IEC 42001 gap analysis and the certification roadmap almost writes itself: the weak dimensions are the work plan, and the level you are at sets the realistic timeline.
If you want that starting point measured rather than guessed, our free AI governance readiness assessment takes about 10 minutes, requires no document uploads, and shows where you stand against ISO/IEC 42001 — dimension by dimension.
Written by a certified ISO/IEC 42001 Lead Auditor and principal consultant at ITG insights.
ITG insights specializes in ISO/IEC 42001 and ISO/IEC 20000 certification consulting, risk management, and governance framework design. Consulting and training inquiries: info@ai42001.ai
ai42001.ai is an AI governance platform structured around ISO/IEC 42001.
Related
🔍 Where audits concentrate: the 5 nonconformities most likely to appear in your ISO 42001 audit.
✅ Testing your own system: the ISO 42001 internal audit checklist, phase by phase.
⚖️ Reading audit findings: OFI vs nonconformity — how auditors actually draw the line.
🗺 The whole portfolio: part of our SC 42 AI Standards Map — the international AI standards portfolio, explained.