The Maturity Assessment — your defensible baseline.
Ninety-six questions across eight governance domains, scored 0–5, traced to primary regulatory text. It is the foothold engagement — the baseline a board reads first and a supervisor can be shown. Here is what it measures, how it scores, and what you get.
What the Maturity Assessment measures
The Maturity Assessment answers the question a board actually opens on: how well do we govern our AI, and where are we weakest? It works through 96 questions across eight governance domains, each scored on a 0–5 scale — from no meaningful control at one end to a repeatable, evidenced, independently assured practice at the other.
The eight domains span the governance lifecycle a supervisor expects to see — senior accountability, risk management, data and model governance, transparency and ongoing monitoring among them — so a weak domain shows up as a weak domain rather than being averaged into invisibility. Every question is tested against the primary regulatory provision behind it, not an assessor's recollection, which is what lets a maturity finding be pointed at rather than merely asserted.
How it's scored
The scoring is deliberately simple, because a baseline has to be reproducible. Each of the 96 questions carries an integer score from 0 to 5. Those scores are averaged within each domain to produce a domain score, and the eight domain scores are then averaged into one overall maturity figure.
The plainness is the point. A fixed integer average means the same evidence yields the same score whoever runs it and whenever it is run — so the baseline you set this year is the baseline you are measured against next year. Questions that do not apply to your firm — because of your sectors or the products you do not offer — are marked not-applicable and drop out of the average rather than dragging it down, so the score reflects the governance you actually need, not a generic checklist.
What you get
The deliverable is one board-ready document, and it centres on the maturity radar. Inside it:
- The maturity radar — the overall score and its eight domains on one figure, the shape a board reads at a glance and returns to at re-performance.
- A domain × jurisdiction heatmap — where the weakness concentrates, functionally and geographically, so attention lands where the risk is.
- A risk-weighted remediation plan — the gaps ranked by severity against the weight of the regulation behind each one, so the second line gets a defensible order of work rather than a flat to-do list.
- The citation trail — every finding addressable back to the primary provision it was tested against.
When to choose it
The Maturity Assessment is the foothold engagement — the one most firms start from. Choose it when you need a defensible, whole-estate baseline: before a procurement gate, ahead of a board or committee discussion, or when a supervisor has started asking how AI is governed and a credible answer has to exist on paper.
It is also the natural first step towards accreditation. The baseline shows where governance stands and ranks the gaps worth closing, which is exactly what tells you whether — and where — the deeper ISO Standards Deep Dive earns its place. Run as a first pilot, the full arc from scoping to board pack is typically scoped at around eight weeks; see how an engagement runs for the shape of the five-week assessment and the delivery models.
Related
ISO 42001 readiness
The 275-question deep dive for firms heading towards accreditation.
→ CompareBoth frameworks
Maturity versus ISO deep dive — questions, scoring and when to pick.
→ The categoryThe AI governance audit
What a productised, point-in-time assessment delivers.
→ ProcessHow an engagement runs
Roughly five weeks, three delivery models, one board pack.
→The Maturity Assessment — the questions we get.
What buyers and second-line teams ask about the 96-question baseline.
What does the AI Governance Maturity Assessment measure?
It measures how well a firm governs its AI across eight governance domains — 96 questions in total, each scored 0–5. The domains span the governance lifecycle a supervisor expects to see, from senior accountability and risk management through to data governance, transparency and ongoing monitoring. The result is one maturity number and the eight domain scores beneath it.
How is the maturity assessment scored?
Each of the 96 questions is scored on a 0–5 scale. Those scores are averaged within each domain to give a domain score, and the eight domain scores are averaged into one overall figure. Because the method is a fixed integer average, the same evidence produces the same score every time — which is what makes the baseline comparable when it is re-performed.
Is the Maturity Assessment enough for ISO 42001 certification?
No — it is the baseline, not the certification path. The Maturity Assessment shows where governance stands and where the gaps concentrate; firms heading towards accredited ISO/IEC 42001 certification move on to the ISO Standards Deep Dive, 275 questions across 42001, 23894 and 38507. AIssure prepares the evidence base, but accredited certification is issued by accredited certification bodies such as BSI, Schellman or A-LIGN.
When should we choose the Maturity Assessment over the ISO deep dive?
Choose the Maturity Assessment when you want a defensible, whole-estate baseline — before a procurement gate, ahead of a board discussion, or to rank remediation across the governance lifecycle. Choose the ISO deep dive when you are already committed to accreditation and need depth against a named standard. Many firms run the baseline first and let it point at where the deep dive earns its place.
Start with a thirty-minute read on your readiness.
A high-level, question-only session — 12 to 16 questions, no evidence to prepare — for an initial view of your AI governance maturity and readiness. It sets the scene for a full engagement: the audit platform deployed and evidence-based assessments run, self-serve or consultant-supported.