Frameworks

Two frameworks, one citation trail.

AIssure assesses AI governance two ways: a 96-question maturity baseline, and a 275-question ISO Standards Deep Dive. Same knowledge graph, same board pack — different depth. Here is how each works, and when to choose which.

Two ways to assess AI governance

There are two questions a regulated firm asks about its AI governance, and they are not the same question. The first — how good is our governance, and where does it fall short? — wants a defensible baseline across the whole estate. The second — can we evidence a management system a certification body will accredit? — wants depth against a named standard. AIssure runs a framework for each.

The AI Governance Maturity Assessment is the foothold: 96 questions across eight governance domains, scored 0–5, producing the maturity radar most board papers open on. The ISO Standards Deep Dive is the depth engagement: 275 questions across ISO/IEC 42001, 23894 and 38507, severity-weighted, for firms heading towards accredited certification.

What does not change between them is the discipline underneath. Both run over the same regulatory knowledge graph, both trace every finding to the primary provision it rests on, and both land as one board-ready document. You are choosing depth and purpose, not a different product.

Maturity Assessment ISO Standards Deep Dive
Questions 96 275
Structured by Eight governance domains Three ISO standards — 42001, 23894, 38507
Scoring Integer average, 0–5 per domain, then across domains Severity-weighted compliance %, critical controls weighted highest
When to pick it A defensible baseline — the foothold most firms start from Heading towards accredited ISO/IEC 42001 certification
Output Maturity radar, domain × jurisdiction heatmap, ranked remediation Per-standard compliance breakdown, gap register, certification-ready evidence base

How scoring works

The two frameworks answer to two different scoring engines, because they are measuring two different things.

Maturity is an average. Each of the 96 questions is scored on a 0–5 scale. Those scores are averaged within each of the eight domains, and the domain scores are then averaged into one overall figure. The result is a single maturity number and the eight it is built from — the shape a board reads at a glance, and the shape that is comparable when the assessment is re-performed a year later.

ISO is severity-weighted. A deep dive is not asking how mature but how compliant, and not every control carries the same weight. Critical controls are weighted highest, so a gap against a load-bearing requirement moves the score more than a gap against a peripheral one. The output is a compliance percentage per standard, plus the overall — a truer picture of readiness than a flat pass rate, because it reflects where the regulation actually concentrates its expectations.

Certification-ready, not certified

Neither framework grants certification, and the ISO deep dive in particular is careful about the word. Accredited ISO/IEC 42001 certification is issued by accredited certification bodies — such as BSI, Schellman or A-LIGN. AIssure produces the evidence base and gap remediation a certification audit expects, which is why we say certification-ready, and never "certified."

FAQ

Choosing a framework — the questions we get.

What buyers, second-line teams and procurement ask when deciding how to assess their AI governance.

What's the difference between the Maturity Assessment and the ISO deep dive?

The AI Governance Maturity Assessment is 96 questions across eight governance domains, scored 0–5 — a defensible baseline of how well your firm governs its AI. The ISO Standards Deep Dive is 275 questions across ISO/IEC 42001, 23894 and 38507, severity-weighted, for firms heading towards accredited certification. Same knowledge graph, same citation trail, same shaped board pack — different depth and different purpose.

How many questions is each framework?

The Maturity Assessment is 96 questions across eight domains. The ISO Standards Deep Dive is 275 questions across three ISO standards — 42001 (AI management system), 23894 (AI risk management) and 38507 (governance implications of AI).

Which framework should we start with?

Most firms start with the Maturity Assessment. It is the foothold engagement — a defensible baseline that shows where governance stands across eight domains, usually before there is any appetite for accreditation. Firms already committed to ISO/IEC 42001 certification move to the deep dive, either straight away or once the baseline has ranked the gaps worth closing first.

Do both frameworks produce the same report?

Both produce a board-ready document in which every finding is traced to primary regulatory text. The Maturity Assessment centres on the maturity radar and a domain × jurisdiction heatmap; the ISO deep dive adds a per-standard compliance breakdown and a certification-ready evidence base. The scoring engine differs — a 0–5 average for maturity, severity-weighted compliance for ISO — but the citation discipline is identical.

Next step

Start with a thirty-minute read on your readiness.

A high-level, question-only session — 12 to 16 questions, no evidence to prepare — for an initial view of your AI governance maturity and readiness. It sets the scene for a full engagement: the audit platform deployed and evidence-based assessments run, self-serve or consultant-supported.