Techné AI · Free reference · Edition 3.0.0
AI Governance Maturity: An Illustrative Planning Framework
Six illustrative seven-stage planning frameworks for AI governance, safety, trust, responsibility, risk and compliance—not a validated assessment score.
On this page
This handbook offers six illustrative, author-created planning frameworks, each organised into seven stages. They are discussion aids for examining practices and choosing improvements, not validated benchmarks, empirical maturity scores, certification criteria or legal conclusions. NIST and ISO have not endorsed these stages. They cover:
- AI Governance Maturity — organisational governance capability.
- AI Safety Maturity — technical safety and reliability.
- AI Trust & Transparency Maturity — stakeholder trust and transparency.
- Responsible AI Maturity — ethics and social responsibility.
- AI Risk Management Maturity — holistic risk management.
- AI Compliance Maturity — processes for identifying and evidencing applicable obligations.
Use the descriptions to discuss the current state and plan improvements within a defined scope. Different systems and teams may fit different descriptions, and there is no proven time interval for moving between stages. Do not average the stage numbers, compare organisations without a common validated method, or infer that “Stage 7” means an AI system is safe or legally compliant. A low-risk use may need simpler controls than a high-impact use; more automation and more paperwork are not necessarily better governance.
Legal duties are minimum requirements when they apply, not achievements to postpone until a later stage. Certification, voluntary code signatures and public recognition are separate facts to verify; none is required to use this planning aid or sufficient to establish a stage. The stage headings below are shorthand for discussion, not findings about an organisation’s legal status or reputation.
Figure: This handbook's illustrative progression. Stage labels organise discussion; they do not measure compliance, certify safety or prescribe a timetable.
1. AI Governance Maturity Stages
Stage 1: Ad Hoc & Chaotic
No formal AI governance. AI projects in silos with little oversight. Decisions on ethics or risk left to individual teams. No leadership awareness of AI-specific risk.
Assessment: No dedicated AI policies or roles exist.
Challenge: Lack of coordination — ethical or compliance breaches go unnoticed.
Best practice: Begin awareness building — basic AI risk workshop, inventory existing AI projects.
Stage 2: Aware (Initial Awareness & Planning)
The organisation has recognised the need for AI governance and is planning. Working groups form. Policies in draft. A champion may be advocating internally.
Assessment: Initial AI governance framework document; ethics committee formed (even without authority).
Challenge: Moving from talk to action.
Best practice: Roadmap with concrete milestones — publish AI ethics policy, assign roles, pilot procedures on one project.
Stage 3: Fragmented (Basic Policies, Inconsistent Adoption)
Basic policies exist; adoption is spotty. Some teams comply, others don't. Reviews for high-profile projects; many projects slip through.
Assessment: Policies on paper; some training delivered.
Challenge: Enforcement and coverage; viewed as box-ticking.
Best practice: Integrate governance into project lifecycle (sign-off gates); communicate success stories.
Stage 4: Defined & Implemented
Formal AI governance in place and functioning. Central committee or officer. Policies refined and communicated. Most projects follow required steps. AI governance is part of standard operating procedure.
Assessment: High percentage of AI initiatives follow the process; governance artefacts (risk assessments, model cards) exist per project. May target ISO/IEC 42001 alignment.
Challenge: Maintaining quality of execution; avoiding "compliance theatre."
Best practice: Internal reviews; investment in tooling that enforces process; named accountable executive.
Stage 5: Managed & Measured
Governance is measured and managed with metrics. KPIs are tracked (e.g., percentage of high-risk systems with completed FRIA, number of incidents, review findings closed). Process is refined based on data.
Assessment: Operational dashboards; regular reporting to executive leadership; tracked remediation pipelines.
Challenge: Avoiding metric overload; ensuring metrics reflect outcomes rather than activity.
Best practice: Tie incentives to governance outcomes; quarterly governance reviews with the board.
Stage 6: Integrated & Optimised
AI governance is integrated with quality, security, privacy and risk management. Changes in one function trigger reviews in the others. External certification may be relevant to a particular scope but is not a stage requirement.
Assessment: Evidence of cross-functional decisions, change management and completed corrective actions.
Challenge: Sustaining maturity through organisational change.
Best practice: Share findings externally; participate in standards bodies.
Stage 7: Adaptive Practice & Shared Learning
The organisation tests whether its governance remains effective as systems and risks change, and shares findings where appropriate.
Assessment: Independent challenge, documented adjustments after failures and evidence that findings influence later decisions.
Challenge: Avoiding complacency; staying ahead of evolving practice.
Best practice: Open-source governance tooling; publish a transparency report; mentor industry peers.
2. AI Safety Maturity Stages
Stage 1: Safety Practices Not Established
No deliberate safety practice. Models deployed without testing for adversarial inputs, drift, or failure modes.
Best practice: Establish minimum testing baseline; document known failure modes.
Stage 2: Reactive Safety Fixes
Safety issues addressed after they manifest. No proactive testing.
Best practice: Build incident response playbook; track recurring failure patterns.
Stage 3: Basic Testing & Validation
Standardised validation tests for new models. Some adversarial testing. Documented evaluation suites.
Best practice: Adopt NIST AI 600-1 GenAI Profile threat categories where applicable.
Stage 4: Proactive Risk Assessment & Mitigation
Risk assessment is standard for every AI project. Mitigations documented and tracked. Operating-domain documentation produced.
Best practice: Align with ISO/IEC 23894; produce model cards per system.
Stage 5: Advanced Technical Safeguards
Adversarial training, ensemble methods, guardian systems, formal verification of safety-critical components.
Best practice: Red-teaming as a standing practice; published evaluation results.
Stage 6: Continuous Safety Management
Continuous monitoring in production; drift detection; automated rollback. Safety incidents trigger root-cause analysis and feedback loops.
Best practice: Integrate safety telemetry into engineering dashboards; quarterly safety reviews.
Stage 7: Safety as a Differentiator
Safety arguments are challenged and updated as evidence changes. Evaluations include realistic failures and the limits of safeguards; absence of reported incidents is not proof of safety.
Best practice: Publish appropriately bounded safety findings and seek independent technical challenge where proportionate.
3. AI Trust & Transparency Maturity Stages
Stage 1: Limited Transparency
AI systems are black boxes; users have no information about how decisions are made.
Best practice: Begin publishing basic system descriptions; identify where transparency is legally required.
Stage 2: Basic Disclosures
Some disclosures — users informed they're interacting with AI; minimal information provided.
Best practice: Identify applicable disclosure and labelling duties, including EU AI Act Article 50 where in scope. Do not wait for a maturity stage to meet a legal deadline.
Stage 3: Explainability for Internal Use
Engineering teams use interpretability tooling (SHAP, LIME, saliency maps). Internal reviews of model decisions.
Best practice: Produce model cards; document operating domains.
Stage 4: User-Facing Explainability
End-users receive plain-language explanations of consequential AI decisions; appeals process available.
Best practice: Review applicable GDPR information and automated-decision safeguards; provide useful reasons and meaningful recourse where required.
Stage 5: Interactive Transparency & Engagement
Users can query AI decisions, provide feedback, and influence outcomes. Public transparency reports published.
Best practice: Consider content provenance measures and publish training-data summaries where required. Provenance does not establish that content is true.
Stage 6: Trusted AI Ecosystem
Transparency practices are informed by user feedback and tested for usefulness. Independent reviews may inform improvements; publication and certification do not automatically create trust.
Best practice: Engage with downstream stakeholders; publish responsible AI use cases.
Stage 7: Industry Transparency Leader
The organisation shares tested transparency practices and revises them in response to stakeholder challenge.
Best practice: Contribute to international standards (ISO, IEEE, C2PA); open-source tooling.
4. Responsible AI Maturity Stages
Stage 1: Responsibility Practices Not Established
No articulated ethics or responsibility principles. AI deployed without consideration of societal impact.
Best practice: Begin articulating principles; appoint ethics owner.
Stage 2: Articulated Principles (on Paper)
Ethics principles published; not yet operationalised. Risk of "ethics washing" without enforcement.
Best practice: Move from principles to processes; assign accountability.
Stage 3: Procedures and Training for Ethics
Ethics training rolled out; review procedures established; ethics escalation path defined.
Best practice: Make ethics review a default gate for AI projects.
Stage 4: Integrated Responsible AI Practices
Responsible AI practices integrated into product development. Bias mitigation, fairness checks, FRIA-style assessments standard.
Best practice: Conduct Article 27 FRIAs where the deployer and use are covered; use proportionate impact assessments elsewhere. ISO/IEC 42005 is a guidance resource, not a substitute for the applicable legal test.
Stage 5: External Accountability and Review
External reviews of ethics and responsibility. Independent ethics board with real authority. Public ethics commitments.
Best practice: Engage civil society; respond to external concerns.
Stage 6: Culture of Responsibility & Empowerment
Responsible AI is part of organisational culture. Employees feel empowered to raise concerns. Whistleblower protections in place (cf. California SB 53).
Best practice: Reward responsible decisions; protect whistleblowers; act on internal escalations.
Stage 7: Social Stewardship and Advocacy
The organisation actively advocates for responsible AI in the broader ecosystem. Funds research; supports public-interest initiatives (e.g., Current AI, ROOST).
Best practice: Sponsor open-source safety work; contribute to multilateral processes.
5. AI Risk Management Maturity Stages
Stage 1: No AI-specific Risk Management
AI risks not distinguished from general enterprise risks. No AI risk register.
Best practice: Create an AI risk register; inventory AI systems.
Stage 2: Qualitative Acknowledgment of AI Risks
AI risks identified at a high level. Documented but not quantified or mitigated systematically.
Best practice: Adopt NIST AI RMF as a starting framework.
Stage 3: Structured Risk Assessment Process
Standard process for risk assessment per AI project. NIST RMF Map and Measure functions implemented.
Best practice: Use NIST trustworthiness characteristics (privacy, accuracy, safety, fairness, etc.) as risk categories.
Stage 4: Risk Mitigation and Control Implementation
Risks have documented controls. NIST RMF Manage function implemented. Aligned with ISO/IEC 23894.
Best practice: Map controls to ISO/IEC 23894 risk treatment options.
Stage 5: Integrated Risk Management & Monitoring
AI risk integrated with enterprise risk management. Real-time monitoring of risk indicators. Cross-functional risk reviews.
Best practice: Quarterly AI risk reviews at executive level; aggregate dashboards.
Stage 6: Advanced Quantitative Risk Analysis
Quantitative risk models for AI — scenario analysis, sensitivity testing, financial risk modelling for AI-related losses.
Best practice: Choose quantitative methods only where data and assumptions support them; include uncertainty and qualitative scenarios rather than manufacturing precise loss estimates.
Stage 7: Adaptive and Resilient Risk Posture
Continuous improvement of risk practice. Resilience tested via tabletop exercises and red-team scenarios. Risk posture adapts to new threats (e.g., novel attacks against frontier models).
Best practice: Industry-leading incident-response drills; contribute to threat-intelligence sharing.
6. AI Compliance Maturity Stages
Stage 1: Obligations Not Mapped
The organisation lacks a documented view of applicable obligations. This label does not determine whether a legal violation has occurred.
Best practice: Review the current AI footprint against applicable regulations (EU AI Act, US state laws, sector rules).
Stage 2: Aware of Regulations
Aware of applicable rules but not yet implementing controls.
Best practice: Map regulations to AI systems; prioritise high-risk gaps.
Stage 3: Implementing Policies and Controls for Compliance
Policies and controls are being implemented against a defined obligations register. Evidence and unresolved gaps are tracked; implementation alone is not a compliance determination.
Best practice: Use ISO/IEC 42001 as architecture; close gaps systematically.
Stage 4: Comprehensive Compliance Management System
End-to-end compliance management. ISO/IEC 42001 aligned. Documented evidence per regulation.
Best practice: Integrate compliance evidence collection into engineering workflow.
Stage 5: Evidence Readiness and Independent Review
Evidence is organised for appropriately scoped external review. If certification is pursued, verify the certification body's accreditation and scope; ISO/IEC 42006 sets requirements for bodies certifying AI management systems, rather than itself accrediting them.
Best practice: Keep evidence current; choose independent review frequency according to obligations, risk and the applicable certification scheme.
Stage 6: Compliance as Business Enabler
Procurement and release decisions use a current, supportable account of obligations, controls, evidence and open gaps.
Best practice: Describe credentials accurately, including scope and validity; do not market certification or a code signature as regulatory approval.
Stage 7: Thought Leader and Shaper in AI Compliance
The organisation contributes experience to rule development and tests its own practices against new requirements and external challenge.
Best practice: Participate in standards development; contribute to regulator working groups.
How to use these frameworks
- Scope and evidence. Name the systems, teams and date being considered. Record practices observed, documents examined, missing evidence and dissent; “not assessed” is a valid result.
- Prioritise. Identify the framework where progress matters most for your organisation’s strategy and risk — often Compliance for regulated industries, Safety for frontier developers, Responsible AI for consumer-facing deployments.
- Plan. Identify the specific practices needed to move to the next stage. Refer to relevant chapters: Legal & Regulatory, Technical Safety, Privacy, Data & Security, Frontier Models.
- Measure control effectiveness. Track whether controls work, remediation is timely and affected people receive recourse. Counts of reviews or documents alone are activity measures; fewer reported incidents may reflect weaker detection.
- Reassess on change. Review after material releases, incidents or legal changes and at a risk-appropriate interval. Do not assign a numerical score or promise an advancement timetable from these descriptions.
Relationship to established frameworks
The NIST AI RMF supplies a voluntary risk-management structure. ISO/IEC 42001 specifies an AI management system; ISO/IEC 42006 addresses certification bodies. Those resources informed the topics discussed here, not the seven-stage scale. Consult their actual requirements and current editions for implementation; the handbook does not reproduce or validate their full criteria.
This free handbook is a dated educational reference, not a determination of your organization's obligations. Check the source, jurisdiction and role before applying a requirement. For working documents, see TalentSight Intelligence and BoardSight Intelligence.