GAICC AI Conference & Awards 2026 "Governing the Future – Building Responsible, Safe and Human-centric AI"
A strategy and engineering shift. The framework keeps governance in step with each stage.
AI is the architecture; agents are first-line actors under human accountability.
Governance · a control plane: continuous, automated assurance, bounded agents.
AI central to decisions and daily operations across the business.
Governance · operate controls and embed governance in every function.
AI bolted onto existing tools and workflows; humans firmly in the loop.
Governance · set policy, inventory every system, baseline risk.
AI-enabled is the starting point. AI features are added to existing tools and workflows, with people firmly in the loop — the value is real but localised. Governance here is about getting the basics in place: an AI policy, a full inventory of where AI is used, and a first risk baseline, so adoption is deliberate rather than accidental.
The defining characteristic of this stage is that AI is additive. Existing processes still work if you switch it off, and a person still makes every decision that matters. That makes it the cheapest stage at which to establish governance — and the stage at which organisations most often decide governance can wait, because nothing has gone wrong yet.
Governance at this stage is about making adoption deliberate rather than accidental. Establish the policy, build the inventory while it is still small, and tier what you find. The work maps directly onto roadmap phases 1 to 3, and doing it here costs a fraction of what it costs at the next stage.
Artefacts for this element
Governing AI you can prove means producing documents somebody can read back to you. These are the artefacts this element produces — the template is the starting point, not the answer.
XLSXAI Governance Maturity ScorecardStage is read off the same scorecardDownloadThis framework, the maturity model and the implementation roadmap are the body of knowledge; the GAICC credentials are extracted from it, each examining a defined part. Listed here by the kind of work they suit — none of them is a prerequisite for anything above.
Extending the management system across sectors, borders and business unitsISO/IEC 42001 Senior Lead ImplementerGoverning AI across an organisation — policy, risk, regulation and the operating modelCertified Professional in AI GovernanceRelated standards. ISO/IEC 42001 clauses 4 to 6 · ISO/IEC 23894 · NIST AI RMF — Govern and Map.
Related articles. The two axes · AI-first · Phase 1 · Mobilize & mandate · Phase 3 · Scope & baseline
AI-first is where AI moves from the edges to the centre, shaping decisions and daily operations across the business; teams reach for it first. Governance shifts from setting up to running — operating controls consistently, embedding governance into every function, and managing risk as systems scale rather than after the fact.
The transition into this stage is usually invisible while it happens. No single system makes an organisation AI-first; the estate simply crosses a threshold where switching AI off would break how work gets done. The governance consequence is that ad hoc oversight stops being viable: what worked when there were nine systems does not work at ninety.
Governance at this stage shifts from setting up to running. The two moves that matter are federating — giving each function a playbook and a champion inside written rails — and making evidence a by-product of delivery rather than an audit-time exercise. This maps onto roadmap phases 4 and 5.
Artefacts for this element
Governing AI you can prove means producing documents somebody can read back to you. These are the artefacts this element produces — the template is the starting point, not the answer.
XLSXAI Governance Maturity ScorecardStage is read off the same scorecardDownloadThis framework, the maturity model and the implementation roadmap are the body of knowledge; the GAICC credentials are extracted from it, each examining a defined part. Listed here by the kind of work they suit — none of them is a prerequisite for anything above.
Extending the management system across sectors, borders and business unitsISO/IEC 42001 Senior Lead ImplementerGoverning AI across an organisation — policy, risk, regulation and the operating modelCertified Professional in AI GovernanceRelated standards. ISO/IEC 42001 clauses 7 and 8 · ISO/IEC 42005 · NIST AI RMF — Measure and Manage.
Related articles. The two axes · AI-enabled · AI-native · The Governance Core · Phase 5 · Embed across disciplines
AI-native is where AI is the architecture, not an add-on. Autonomous agents act as first-line participants under clear human accountability. Governance runs as a continuously-automated control plane — runtime guardrails, continuous assurance and bounded agents — so trust and oversight keep pace with systems that increasingly run themselves.
This stage changes what governance is, not just how much of it there is. When systems take actions rather than produce outputs, the distance between a design choice and its consequence collapses, and periodic sampling stops being an adequate control. The organisation has to move from checking work after it happens to constraining what can happen at all.
Governance at this stage runs as a continuously-automated control plane. The tenth control domain — agentic and autonomous AI — adds to the other nine rather than replacing them, and assurance moves from sampling to continuous monitoring. This maps onto roadmap phases 6 and 7.
Artefacts for this element
Governing AI you can prove means producing documents somebody can read back to you. These are the artefacts this element produces — the template is the starting point, not the answer.
XLSXAI Governance Maturity ScorecardStage is read off the same scorecardDownloadThis framework, the maturity model and the implementation roadmap are the body of knowledge; the GAICC credentials are extracted from it, each examining a defined part. Listed here by the kind of work they suit — none of them is a prerequisite for anything above.
Extending the management system across sectors, borders and business unitsISO/IEC 42001 Senior Lead ImplementerGoverning AI across an organisation — policy, risk, regulation and the operating modelCertified Professional in AI GovernanceRelated standards. ISO/IEC 42001 clause 10 · ISO/IEC 5338 · ISO/IEC 24029 (robustness) · NIST AI RMF — Manage. The agentic control domain is a GAICC extension with no direct equivalent in current published control sets.
Related articles. The two axes · AI-first · Control domains · Phase 7 · Adapt & extend · Delivery & Operations
How AI-native you are and how mature your governance is are two different things. Place yourself across five dimensions for a profile and a recommended next step.
Accountability & oversight measures whether a named person is answerable for AI governance and whether oversight genuinely happens. It is first among equals: the only dimension whose absence disables the others, because controls without authority are suggestions.
Every other dimension assumes this one. Lifecycle controls need somebody with the authority to enforce a gate. Assurance needs a route to a body that can act on findings. Capability needs somebody who can hold line managers to a time allocation. An organisation can score well on any of those and deliver nothing, if there is no one who can require it.
| Level | What it looks like in observable terms |
|---|---|
| 1 Initial | No clear owner; AI use is ad hoc. Whatever governance happens, happens because an individual chose to. |
| 2 Developing | An owner is named and the board is aware. The role exists; its authority is unclear and its cadence irregular. |
| 3 Defined | A governing body and an accountable executive are set, with terms of reference, decision rights and a cadence. |
| 4 Managed | Oversight is active and decisions are evidenced. The forum declines and defers things, and the record shows it. |
| 5 Optimizing | Oversight drives strategy and improves itself. Direction changes because evidence demanded it, and that is traceable. |
| Level | Evidence that would satisfy an assessor |
|---|---|
| 1 | Nothing. The absence of a named owner is itself the finding. |
| 2 | An appointment letter or org chart entry; occasional board papers. |
| 3 | Terms of reference, membership, quorum, decision rights, a completed RACI map with one A per activity. |
| 4 | Minutes showing decisions taken, including refusals; board packs across consecutive cycles; escalations resolved. |
| 5 | Policy or risk appetite amendments traceable to specific evidence; autonomy limits revised by decision. |
Roadmap phase 2 · Operating model & Center of Excellence is the phase built to advance this dimension: it stands up the governing body, establishes the hub, appoints the spokes and completes the RACI map. If accountability is at level 1, start further back at phase 1 — you need the mandate before you can appoint anyone under it.
Artefacts for this element
Governing AI you can prove means producing documents somebody can read back to you. These are the artefacts this element produces — the template is the starting point, not the answer.
XLSXAI Governance Maturity ScorecardThe five levels of this dimension, with evidence per levelDownloadThis framework, the maturity model and the implementation roadmap are the body of knowledge; the GAICC credentials are extracted from it, each examining a defined part. Listed here by the kind of work they suit — none of them is a prerequisite for anything above.
Standing up and running the AI management systemISO/IEC 42001 Lead ImplementerGoverning AI across an organisation — policy, risk, regulation and the operating modelCertified Professional in AI GovernanceRelated standards. ISO/IEC 42001 clause 5 (leadership) and 5.3 (roles, responsibilities and authorities) · ISO/IEC 38507 · NIST AI RMF — Govern.
Related articles. Board & Executive · The Governance Core · Phase 2 · Operating model & CoE · Using the RACI / accountability map
Risk, impact & trustworthiness measures whether AI risk and impact are assessed, treated and monitored, and whether trustworthiness characteristics are expressed as tested properties with thresholds and owners rather than as adjectives.
This is the dimension external parties probe first. A regulator asks what you assessed and when. A customer asks how you know the system is fair. An incident review asks whether the harm that occurred was one you had considered. All three are answerable only if assessment happened before reliance, was recorded, and produced something measurable.
| Level | What it looks like in observable terms |
|---|---|
| 1 Initial | Risks unassessed. Nobody has systematically asked what these systems could do to people. |
| 2 Developing | Some risks noted case by case, usually for the systems that felt significant to whoever was asked. |
| 3 Defined | A risk and impact method is defined: when it runs, who runs it, what it covers, how depth scales with tier. |
| 4 Managed | Risks are tracked, treated and monitored. Residual risk has named acceptors; trustworthiness has thresholds and tests. |
| 5 Optimizing | Risk management is predictive and data-driven — monitoring signals emerging risk rather than recording realised risk. |
| Level | Evidence that would satisfy an assessor |
|---|---|
| 1 | Nothing, or a generic corporate risk register with no AI entries. |
| 2 | A handful of assessments for prominent systems; no consistent method or trigger. |
| 3 | A documented method, tiering criteria, and impact assessments completed before build for higher-risk systems. |
| 4 | Risk register with owners, treatments and dated named acceptances; disaggregated performance results; threshold breaches with responses. |
| 5 | Monitoring that flags drift and emerging risk ahead of incidents; assessments re-run on trigger, not only on schedule. |
Roadmap phase 4 · Policy, risk & controls is the phase built to advance this dimension: it treats risk against the tiered estate, sets the Statement of Applicability and puts controls in place. Its exit criterion — one real system through the full control set — is what moves this dimension from Defined to Managed.
Artefacts for this element
Governing AI you can prove means producing documents somebody can read back to you. These are the artefacts this element produces — the template is the starting point, not the answer.
XLSXAI Governance Maturity ScorecardThe five levels of this dimension, with evidence per levelDownloadThis framework, the maturity model and the implementation roadmap are the body of knowledge; the GAICC credentials are extracted from it, each examining a defined part. Listed here by the kind of work they suit — none of them is a prerequisite for anything above.
Standing up and running the AI management systemISO/IEC 42001 Lead ImplementerGoverning AI across an organisation — policy, risk, regulation and the operating modelCertified Professional in AI GovernanceRelated standards. ISO/IEC 23894 (risk management) · ISO/IEC 42005 (impact assessment) · ISO/IEC TR 24027 (bias) · ISO/IEC 24029 (robustness) · NIST AI RMF — Map and Measure.
Related articles. Risk, impact & trustworthiness · Foundations · Phase 4 · Policy, risk & controls · Using the AI Impact Assessment template
Lifecycle control measures whether governance controls apply across the life of each AI system, from inception to retirement, and whether they produce retrievable evidence as work happens rather than reconstructed accounts afterwards.
This dimension is where governance meets delivery, and it is the one that determines whether the rest of the framework is real. Policy, risk method and assurance all express themselves as controls applied at a lifecycle stage. If they do not attach to a step in how work actually happens, they exist in documents and nowhere else.
| Level | What it looks like in observable terms |
|---|---|
| 1 Initial | No lifecycle controls. Systems are built and deployed with no governance touchpoint. |
| 2 Developing | Ad hoc checks on some systems, usually triggered by someone noticing rather than by a process. |
| 3 Defined | Controls are defined for the lifecycle: which control applies at which stage, scaled by risk tier, with gates named. |
| 4 Managed | Controls operate with evidence. Approvals, tests and monitoring records exist and can be produced on request. |
| 5 Optimizing | Controls are automated and adaptive — enforced at the point of build and deploy, adjusting as risk changes. |
| Level | Evidence that would satisfy an assessor |
|---|---|
| 1 | Nothing. Systems in production with no record of who approved them. |
| 2 | Evidence for some systems, inconsistently, usually the ones somebody worried about. |
| 3 | A documented control-to-stage mapping, defined gates, tiering criteria that set depth. |
| 4 | Release approvals, test results, monitoring and incident logs, retrievable in minutes for a system an assessor picks. |
| 5 | Policy-as-code and automated guardrails; evidence emitted by pipelines; drift detected rather than discovered. |
Roadmap phase 3 · Scope & baseline is the phase built to advance this dimension — you cannot apply lifecycle controls to systems you have not inventoried, and the risk tier assigned there is what keeps control depth proportionate. Phase 4 then implements the controls themselves.
Artefacts for this element
Governing AI you can prove means producing documents somebody can read back to you. These are the artefacts this element produces — the template is the starting point, not the answer.
XLSXAI Governance Maturity ScorecardThe five levels of this dimension, with evidence per levelDownloadThis framework, the maturity model and the implementation roadmap are the body of knowledge; the GAICC credentials are extracted from it, each examining a defined part. Listed here by the kind of work they suit — none of them is a prerequisite for anything above.
Standing up and running the AI management systemISO/IEC 42001 Lead ImplementerGoverning AI across an organisation — policy, risk, regulation and the operating modelCertified Professional in AI GovernanceRelated standards. ISO/IEC 5338 (AI system lifecycle processes) · ISO/IEC 42001 clause 8 and Annex A lifecycle controls · NIST AI RMF — Manage.
Related articles. The AI system lifecycle · Delivery & Operations · Phase 3 · Scope & baseline · Using the AI System Inventory register
Assurance & audit measures whether anyone independent of delivery tests that controls actually work, whether findings are closed with evidence, and whether the board's picture of AI governance comes from a source management cannot edit.
Everything the first line reports about itself is self-assessment. This dimension exists to produce the finding the organisation would not have generated on its own — and to give the board a source it can rely on. Without it, an organisation is governing on a single view supplied by the people being assessed.
| Level | What it looks like in observable terms |
|---|---|
| 1 Initial | No assurance. Nobody checks whether controls work; the question has not been asked. |
| 2 Developing | Informal review only, usually by the same people who designed or operate the controls. |
| 3 Defined | Assurance roles and cadence are defined: who tests what, how often, and where findings go. |
| 4 Managed | Independent internal audit runs and certification is sought. Findings have owners, dates and closure evidence. |
| 5 Optimizing | Continuous assurance, externally certified — control conformance monitored in near real time rather than sampled. |
| Level | Evidence that would satisfy an assessor |
|---|---|
| 1 | Nothing. |
| 2 | Occasional reviews with no defined scope, performed within the governance function. |
| 3 | An assurance calendar, defined scope per cycle, a reporting line that preserves independence. |
| 4 | Internal audit reports; findings register with closure evidence; management review minutes; conformity assessment reports. |
| 5 | Continuous control monitoring output with exception routing; surveillance assessment records; findings closed within cycle. |
Roadmap phase 6 · Assure & certify is the phase built to advance this dimension: it runs the three lines, completes independent internal audit and management review, and enters external conformity assessment. Do not enter it before controls are embedded — auditing an incomplete control set produces a finding list that discredits the programme rather than improving it.
Artefacts for this element
Governing AI you can prove means producing documents somebody can read back to you. These are the artefacts this element produces — the template is the starting point, not the answer.
XLSXAI Governance Maturity ScorecardThe five levels of this dimension, with evidence per levelDownloadThis framework, the maturity model and the implementation roadmap are the body of knowledge; the GAICC credentials are extracted from it, each examining a defined part. Listed here by the kind of work they suit — none of them is a prerequisite for anything above.
Providing second-line assurance and running internal auditsISO/IEC 42001 Internal AuditorAuditing an AI management system independentlyISO/IEC 42001 Lead AuditorRelated standards. ISO/IEC 42001 clause 9 (internal audit, management review) and clause 10 · ISO 19011 · ISO/IEC 17021 · ISO/IEC 42006 · NIST AI RMF — Measure.
Related articles. The assurance rhythm · Risk, Assurance & Audit · Phase 6 · Assure & certify
Capability & culture measures whether the competence to govern AI exists at the point where decisions are made, and whether governance has become part of how functions work rather than something a central team performs on their behalf.
This is the dimension that determines whether an AI governance programme is finishable. Every other dimension can be delivered by a central team; this one cannot, by definition. It is also the dimension that decays fastest when unattended, because it lives in people who move roles and in habits that erode without reinforcement.
| Level | What it looks like in observable terms |
|---|---|
| 1 Initial | Little awareness or skill. AI decisions are made by people with no governance grounding. |
| 2 Developing | Pockets of skill; training starting. A few individuals carry the knowledge, informally. |
| 3 Defined | Roles and training are defined: who needs what depth, and how they get it. |
| 4 Managed | Embedded champions and broad fluency. Functions run their own playbooks without prompting. |
| 5 Optimizing | Governance is part of the culture. Functions propose control improvements from what they have learned. |
| Level | Evidence that would satisfy an assessor |
|---|---|
| 1 | Nothing, or generic AI awareness content with no governance element. |
| 2 | Ad hoc training attendance; capability concentrated in one or two people. |
| 3 | A competence framework by role at defined depths; a training plan; role descriptions carrying governance duties. |
| 4 | Function playbooks in use; named champions with recorded time allocation; credential records matched to roles; two cycles of unprompted operation. |
| 5 | Control changes originated by functions rather than the hub; spoke-to-hub forum minutes showing adopted proposals. |
Roadmap phase 5 · Embed across disciplines is the phase built to advance this dimension: it writes function playbooks, resources embedded champions and transfers operation from the hub to the spokes. Its exit criterion — functions using their playbooks without prompting — is precisely the level 4 descriptor.
Artefacts for this element
Governing AI you can prove means producing documents somebody can read back to you. These are the artefacts this element produces — the template is the starting point, not the answer.
XLSXAI Governance Maturity ScorecardThe five levels of this dimension, with evidence per levelDownloadThis framework, the maturity model and the implementation roadmap are the body of knowledge; the GAICC credentials are extracted from it, each examining a defined part. Listed here by the kind of work they suit — none of them is a prerequisite for anything above.
HR, people and workforce functionsCertified AI HR ProfessionalStanding up and running the AI management systemISO/IEC 42001 Lead ImplementerRelated standards. ISO/IEC 42001 clause 7 (support, competence, awareness) and Annex A resources controls · ISO/IEC 17024 for personnel certification · NIST AI RMF — Govern.
Related articles. People, Functions & Capability · Foundations · Phase 5 · Embed across disciplines
A maturity assessment scores each of the five governance dimensions against five levels, evidences each score, and converts the result into a specific next action on the roadmap. Its output is not a number. It is a decision about what to do next.
Maturity assessments have a poor reputation, and it is deserved. Run badly they produce a self-flattering number, a radar chart, and no change. Run well they are the cheapest diagnostic in governance: an afternoon of honest scoring tells you what six months of work should target.
The difference is entirely in two disciplines — evidencing each score, and being willing to record the uncomfortable one. A dimension scored Managed with no evidence is not an assessment; it is an aspiration in a table.
The second value is longitudinal. A single assessment tells you where you are. Three tell you whether you are moving, and movement is what a board can actually act on.
Decide first which entities and which part of the estate the assessment covers. A group-level score that averages a well-governed head office with three ungoverned subsidiaries is accurate about nothing. Where maturity genuinely differs across the organisation, assess separately and report both.
Each level should be scored against something you could show someone, not against how the dimension feels. The descriptors below are the framework’s, and the discipline is to pick the highest level for which you can produce evidence — not the highest that sounds right.
| Level | Accountability & oversight | Lifecycle control | Assurance & audit |
|---|---|---|---|
| 1 Initial | No clear owner; AI use ad hoc | No lifecycle controls | No assurance |
| 2 Developing | An owner named; board aware | Ad hoc checks on some systems | Informal review only |
| 3 Defined | Governing body & accountable exec set | Controls defined for the lifecycle | Assurance roles & cadence defined |
| 4 Managed | Oversight active; decisions evidenced | Controls operating with evidence | Independent audit; certification sought |
| 5 Optimizing | Oversight drives strategy; improving | Controls automated & adaptive | Continuous assurance; externally certified |
| Level | Risk, impact & trustworthiness | Capability & culture |
|---|---|---|
| 1 Initial | Risks unassessed | Little awareness or skill |
| 2 Developing | Some risks noted case by case | Pockets of skill; training starting |
| 3 Defined | Risk & impact method defined | Roles & training defined |
| 4 Managed | Risks tracked, treated, monitored | Embedded champions; broad fluency |
| 5 Optimizing | Predictive, data-driven risk mgmt | Governance part of the culture |
Self-assessment drifts upward, reliably and without anyone intending it. Build in a challenge: someone independent of the governance function picks two dimensions and asks for the evidence behind the score. This takes an hour and is the difference between an assessment and a self-portrait.
The framework’s rule is to fix the earliest gap, not the biggest one, because the roadmap is sequenced by dependency. The self-assessment on the maturity page applies this automatically; the logic is worth knowing.
| If the lowest gap is… | Go to |
|---|---|
| Accountability & oversight at level 1 | Phase 1 · Mobilize & mandate |
| Accountability & oversight below 3 | Phase 2 · Operating model & Center of Excellence |
| Lifecycle control below 3 | Phase 3 · Scope & baseline |
| Risk, impact & trustworthiness below 3 | Phase 4 · Policy, risk & controls |
| Capability & culture below 3 | Phase 5 · Embed across disciplines |
| Assurance & audit below 3 | Phase 6 · Assure & certify |
| Everything at 4 or above | Phase 7 · Adapt & extend |
Annually is the right default for a full assessment, aligned to management review. Reassess sooner when something material changes: a significant acquisition, a jump in adoption stage, the first autonomous agents entering production, or a new regulatory obligation taking effect.
Report position, movement and the gap against adoption — in that order of usefulness, reversed. Movement since the last assessment is what a board can act on; a static position tells them only that the last cycle produced no change, which is itself worth saying plainly.
| Evidence | What it demonstrates |
|---|---|
| Assessment scope statement | That the score means something specific |
| Scored assessment with evidence cited per dimension | That levels are earned |
| Independent challenge record | That self-assessment drift was checked |
| Gap analysis against the adoption stage | That the risk position is understood |
| Assessment history across cycles | That movement is tracked |
| Recorded next phase and its owner | That the assessment produced action |
Artefacts for this element
Governing AI you can prove means producing documents somebody can read back to you. These are the artefacts this element produces — the template is the starting point, not the answer.
XLSXAI Governance Maturity ScorecardThe scoring workbook itselfDownloadXLSXEvidence RegisterWhat each score must point atDownload| Role | Responsibility |
|---|---|
| AI governance lead | Runs the assessment and assembles the evidence |
| Risk & assurance lead | Provides the independent challenge |
| Accountable executive | Accepts the result and commits to the next phase |
| Board & governing body | Decides whether the gap against adoption is acceptable |
This framework, the maturity model and the implementation roadmap are the body of knowledge; the GAICC credentials are extracted from it, each examining a defined part. Listed here by the kind of work they suit — none of them is a prerequisite for anything above.
Extending the management system across sectors, borders and business unitsISO/IEC 42001 Senior Lead ImplementerProviding second-line assurance and running internal auditsISO/IEC 42001 Internal AuditorStanding up and running the AI management systemISO/IEC 42001 Lead ImplementerRelated standards. ISO/IEC 42001 clause 9 (performance evaluation and management review) · ISO 19011 · ISO/IEC 33001 family for assessment concepts · NIST AI RMF Playbook.
Related articles. The two axes · How to use the roadmap · The assurance rhythm · each of the five dimension articles
The maturity model measures two independent things: how far AI has moved into how the organisation works — AI-enabled, AI-first, AI-native — and how well that AI is governed, across five dimensions at five levels. They advance separately, and the gap between them is where risk lives.
Most maturity models measure one thing and imply the other. Ask an organisation how mature its AI is and you will get an answer about adoption — how many teams use it, how central it has become. Ask how mature its AI governance is and you often get the same answer restated, as though the two moved together.
They do not. Adoption is driven by competitive pressure, tooling and enthusiasm, and it can move very fast. Governance is driven by deliberate investment, and it moves at the speed of decisions. An organisation can go from a handful of pilots to AI in every function inside a year while its governance stays exactly where it was.
Separating the axes makes that gap visible and therefore manageable. It also produces a more useful conversation than a single score: the question stops being “are we mature?” and becomes “is our governance keeping pace with what we have actually deployed?”
Three stages describe how far AI has moved into how the organisation actually works. They are not a ranking of ambition — plenty of organisations should stop at the first.
| Stage | What it means | What governance has to do here |
|---|---|---|
| AI-enabled | AI features added to existing tools and workflows, people firmly in the loop. Value is real but localised. | Get the basics in place: policy, a full inventory, a first risk baseline. |
| AI-first | AI moves from the edges to the centre, shaping decisions and daily operations; teams reach for it first. | Shift from setting up to running: operate controls consistently, embed in every function. |
| AI-native | AI is the architecture, not an add-on. Autonomous agents act as first-line participants. | Run as a continuously-automated control plane: runtime guardrails, continuous assurance, bounded agents. |
Five dimensions, each scored on five levels. The dimensions are deliberately few and deliberately not weighted, because the useful signal is which one is lowest, not what they average to.
| Dimension | What it measures | Advanced by |
|---|---|---|
| Accountability & oversight | Whether someone is answerable and whether oversight actually happens | Phase 2 · Operating model & CoE |
| Risk, impact & trustworthiness | Whether risk and impact are assessed, treated and monitored | Phase 4 · Policy, risk & controls |
| Lifecycle control | Whether controls apply across the life of each system | Phase 3 · Scope & baseline |
| Assurance & audit | Whether anyone independent tests that controls work | Phase 6 · Assure & certify |
| Capability & culture | Whether the skill and the habits exist where the work happens | Phase 5 · Embed across disciplines |
Averaging the five dimensions produces a number that is easy to report and slightly misleading. Governance behaves more like a chain than a portfolio: a Managed lifecycle control capability sitting on top of an Initial accountability dimension does not deliver Managed outcomes, because there is nobody with the authority to enforce what the controls require.
This is why the roadmap is sequenced the way it is and why the self-assessment recommends the earliest gap rather than the biggest one. The dimension that is furthest behind is the one setting your effective level.
The danger zone — high adoption, low governance — is where most AI incidents are generated, and it is the most common position for organisations that adopted quickly. The characteristic symptom is an inventory nobody can complete: the organisation genuinely does not know what it is running.
Governed but not adopted is less discussed and not free. Control depth that exceeds the risk of the estate consumes capacity, slows delivery and, more damagingly, trains the organisation to treat governance as friction — which is expensive to undo later when the estate does grow.
The target is not the top-right corner in the abstract. It is governance that matches the adoption stage you are actually at, with enough margin to absorb the next one.
| Evidence | What it demonstrates |
|---|---|
| Recorded adoption stage with the reasoning | That the stage was assessed, not assumed |
| Scored assessment across all five dimensions | That governance was measured in the round |
| Evidence supporting each dimension score | That levels are earned rather than claimed |
| Gap analysis between the two axes | That the risk position is understood |
| Movement tracked across assessment cycles | That the model is used, not filed |
| Link from the lowest dimension to a roadmap phase | That assessment produced action |
Artefacts for this element
Governing AI you can prove means producing documents somebody can read back to you. These are the artefacts this element produces — the template is the starting point, not the answer.
XLSXAI Governance Maturity ScorecardScore both axes, five dimensions, evidence per levelDownload| Role | Responsibility |
|---|---|
| Accountable executive | Answers for the gap between adoption and governance |
| AI governance lead | Owns the assessment and the evidence behind each score |
| Risk & assurance lead | Independently challenges claimed levels |
| Board & governing body | Receives the position and decides whether the gap is acceptable |
This framework, the maturity model and the implementation roadmap are the body of knowledge; the GAICC credentials are extracted from it, each examining a defined part. Listed here by the kind of work they suit — none of them is a prerequisite for anything above.
Extending the management system across sectors, borders and business unitsISO/IEC 42001 Senior Lead ImplementerLeading audits that reach the annexes, maturity and cross-border scopeISO/IEC 42001 Senior Lead AuditorGoverning AI across an organisation — policy, risk, regulation and the operating modelCertified Professional in AI GovernanceRelated standards. ISO/IEC 42001 clauses 9 and 10 (evaluation and improvement) · ISO/IEC 33001 family for process assessment concepts · NIST AI RMF — the Govern function · ISO/IEC 38507.
Related articles. Run a maturity assessment · AI-enabled · AI-first · AI-native · How to use the roadmap