AI Governance Maturity Model: The 5 Levels

An AI governance maturity model is a staged framework that describes how an organisation's controls over AI systems progress from ad hoc oversight to continuous, board-level assurance, so leaders can benchmark where they are today and plan the next credible step. It gives a board a shared language for a question that otherwise gets fuzzy answers: how well do we actually govern the AI we've deployed, and what would "better" look like?
Most organisations start automating with rule-based robotic process automation (RPA), then bolt on machine learning, then find themselves running autonomous AI systems they never governed as AI. A maturity model turns that drift into a plan. It maps the distance between where your oversight sits now and where regulators, buyers, and your own risk appetite need it to be.
The five levels of AI governance maturity
Maturity models borrow their shape from the software world's Capability Maturity Model: five levels, each a recognisable operating state rather than a score you invent. Here's how the levels read for AI governance.
| Level | Name | What it looks like |
|---|---|---|
| 1 | Ad hoc | No AI-specific policy. Automation is treated as an IT project. Oversight is reactive and depends on individuals. |
| 2 | Aware | Leaders acknowledge AI risk. Some documentation and impact notes exist, but coverage is patchy and inconsistent. |
| 3 | Defined | A written AI governance policy exists. Roles, risk tiers, and review gates are documented and applied to new systems. |
| 4 | Managed | Controls are measured. Bias testing, explainability checks, and human oversight run on a schedule with evidence retained. |
| 5 | Adaptive | Governance is continuous and reported to the board. Controls adjust as models, regulation, and risk change. |
The jump that matters most is Level 2 to Level 3. That's where governance stops being a set of good intentions and becomes something you can audit. A board can ask for the policy, the risk register, and the last review, and someone can produce them.
Why the RPA-to-AI path breaks governance
The trouble starts because RPA and AI feel like the same thing to the business but behave nothing alike under scrutiny.
Rule-based automation is deterministic. It does what the rules say, every time, and standard IT change management covers it well enough. Machine learning is different. It infers, it drifts, and it can be wrong in ways nobody wrote a rule for. When a procurement bot that once just moved invoices starts scoring vendor risk with a model, the governance built for the bot no longer fits the model.
Treat the whole system as one thing and you either over-govern the boring parts or under-govern the risky ones. Neither is defensible in front of a regulator.
Assessing your current maturity
You don't need a consultant in the room to get a first read. Five questions expose the level honestly.
- Policy. Is there a written AI governance policy that a new project must follow, or is oversight decided case by case?
- Inventory. Can you produce a current list of every AI and automated system in use, including what data each one touches?
- Risk tiering. Do you classify systems by risk, so a credit-scoring model gets more scrutiny than a meeting-notes summariser?
- Testing. Do you test deployed models for bias, accuracy, and drift on a schedule, and keep the evidence?
- Oversight. Is there a named human accountable for each higher-risk system, with real authority to pause it?
Mostly "no" puts you at Level 1 or 2. Mostly "yes, and we keep records" is Level 3 or above. The gaps you just found are your roadmap.
Anchor the model to real standards, not a homemade scale
A maturity model earns its board credibility by mapping to recognised frameworks rather than inventing private jargon. Four are worth building around.
- NIST AI Risk Management Framework. A voluntary US framework structured around four functions: Govern, Map, Measure, and Manage. It's the clearest operational backbone for what "good" looks like at each maturity level.
- ISO/IEC 42001. The first international standard for an AI management system. It sets out requirements for establishing, running, and improving governance, and it's certifiable, which matters when a buyer or regulator wants proof rather than a promise.
- EU AI Act. The EU's risk-based law. It sorts AI into unacceptable, high, limited, and minimal risk, with the heaviest obligations on high-risk systems. If you sell into or operate in the EU, its timeline sets hard deadlines. We've mapped those dates in the EU AI Act complete timeline.
- OECD AI Principles. A set of values-based principles adopted by dozens of governments and updated in 2024. They're less prescriptive than the others but useful for setting the tone at the top. The OECD AI Principles guide breaks them down.
Mapping each maturity level to these frameworks does two jobs. It stops you reinventing controls that already exist in standard form, and it gives your board a defensible answer when someone asks which framework you follow.
Four principles for governance that scales
Moving up the levels isn't about buying a tool. It's about applying a few principles consistently as your automation gets smarter.
Govern by component, not by label
Break systems into functional parts and govern each on what it actually does. A workflow that routes invoices needs documentation and monitoring. A model that decides which vendors are risky needs bias testing, explainability, and human review. Same system, two very different control sets.
Match oversight to risk
Tiered controls beat one-size-fits-all every time. Low-risk, rule-based processes need light-touch documentation. High-stakes automated decisions, anything affecting credit, hiring, health, or safety, trigger the full set: testing, explainability, a human who can intervene, and a clear audit trail.
Keep one source of truth
Maintain a single inventory of every automated and AI system, what data it uses, and which controls apply. Scattered documentation is how systems slip through governance unnoticed. One register, kept current, is the difference between an audit you pass and one you scramble through.
Reassess when capability changes
Governance set once and forgotten goes stale the moment a model is retrained or a new feature ships. Trigger a fresh review whenever a system's capability changes. Adding document understanding to a simple RPA bot should automatically prompt the question: does this now need AI-grade controls?
An opinion worth stating plainly
Most maturity models are too flattering. They let a company that's written one policy call itself "Level 3" and stop. That's a mistake. The honest test of maturity isn't whether the policy exists. It's whether, if a regulator walked in tomorrow, you could show the evidence that the policy is actually followed on every system in your inventory. Governance you can't evidence isn't Level 3. It's Level 2 with better PowerPoint.
The organisations that get this right treat maturity as a moving target. Regulation tightens, models change, and the bar for "responsible" keeps rising. Standing still is falling behind.
Frequently asked questions
What is an AI governance maturity model?
It's a staged framework, usually five levels, that describes how an organisation's control over its AI systems develops from ad hoc and reactive to continuous and board-assured. It lets leaders benchmark their current state honestly and plan the next practical improvement, rather than guessing whether their oversight is adequate.
What are the levels of AI governance maturity?
A common structure runs from Level 1 (ad hoc, no AI-specific policy) through Aware, Defined, and Managed, to Level 5 (adaptive, continuous, board-reported). Each level is a recognisable operating state defined by what controls exist and whether you can produce evidence they work, not by a self-assigned score.
How is an AI governance maturity model different from an RPA governance model?
RPA governance assumes deterministic, rule-based automation that behaves the same way every time, so standard IT change management covers it. AI governance has to handle systems that learn, drift, and produce outcomes nobody wrote a rule for. A maturity model bridges the two, applying stronger controls to the parts of a system that genuinely use AI.
Which frameworks should an AI governance maturity model map to?
The four most useful reference points are the NIST AI Risk Management Framework, ISO/IEC 42001, the EU AI Act, and the OECD AI Principles. Mapping your maturity levels to recognised frameworks gives your board a defensible answer about which standards you follow and stops you reinventing controls that already exist.
How do we assess our current AI governance maturity?
Start with five questions: do you have a written AI policy, a current inventory of AI systems, risk tiering, scheduled testing with retained evidence, and a named accountable human for each higher-risk system? Mostly "no" answers place you at the lower levels. The gaps those questions expose become your improvement roadmap.
How long does it take to move up a maturity level?
There's no fixed timeline, because it depends on how many systems you run and how much documentation already exists. The reliable pattern is to fix the biggest evidence gap first, usually a missing inventory or the absence of a written policy, then build out testing and oversight. Progress is measured by what you can prove, not by how many tools you've bought.
Getting from a self-assigned level to one you can defend in front of a regulator is where most organisations need help. If you want an honest read on where your controls actually sit and a roadmap to the next level, our AI governance and compliance advisory is built for exactly that.

Sotiris Spyrou
Sotiris Spyrou is the founder of VerityAI, a Responsible AI advisory for boards and AI-deploying businesses. With 27 years across agencies, global in-house roles, and the C-suite, he advises leaders on AI governance and risk, and on answer-engine visibility engineered without the dark patterns the rest of the industry is getting penalised for. He is the author of TRANSFORM, AI Moats, and Ethical AI.
Founder at VerityAI
Areas of Expertise: