What maturity model best describes the evolution of governance capabilities for…

What maturity model best describes the evolution of governance capabilities for Artificial Intelligence (AI) and low-code in enterprises?

2026-04-26 · governance-policy security-risk ai-architecture · medium · source → · wiki →
key claims
  1. Existing public frameworks divide into staged benchmark models, governance-system baselines, and assurance toolkits, so the most defensible enterprise maturity model is a composite rather than an unchanged adoption of any one external frameworkCMMI (n.d.)Microsoft (n.d.)NIST (n.d.)International (2023)Responsible (n.d.)British (n.d.)
  2. CMMI is a useful scaffold for the hybrid model because it provides public benchmark levels and appraisal mechanics, but its public material is too generic to serve alone as an AI and low-code governance maturity modelCMMI (n.d.)CMMI (n.d.)
  3. Microsoft's current public agentic AI maturity model is a useful AI-specific reference because it describes five levels, explicit anti-patterns, and progression actions across governance, technology, business-process, and cultural pillars, even though its framing remains vendor-shapedMicrosoft (n.d.)Microsoft (n.d.)Microsoft (n.d.)Microsoft (n.d.)
  4. NIST AI RMF and ISO/IEC 42001 should define the baseline control content for each stage, but they are not sufficient on their own because they specify governance functions and management-system requirements rather than explicit maturity thresholdsNational (n.d.)NIST (n.d.)International (2023)
  5. The maturity model must explicitly gate progression on the weakest mandatory control surfaces, especially decision rights, identity and access, enforcement, lifecycle, and regulatory alignment, because failure on those surfaces invalidates claims of enterprise maturity elsewhereGithub (n.d.)Github (n.d.)Github (n.d.)Github (n.d.)Github (n.d.)
  6. Behavioural maturity should cap structural maturity because teams that routinely bypass the sanctioned path remain effectively immature even when control documents, councils, and review workflows formally existGithub (n.d.)Microsoft (n.d.)
  7. The supported progression pathway runs from policy, literacy, and inventory, to basic guardrails and tiering, to standardised shared controls, then to automated risk-tiered operations and finally to adaptive assurance, because value appears only after foundations become reusable and measurableDevOps (2025)DORA (n.d.)MIT (n.d.)
  8. A credible assessment mechanism must require evidence artefacts, operating evidence, and assurance evidence for every scored dimension, because governance maturity cannot be validated by interviews or questionnaires aloneCMMI (n.d.)NIST (n.d.)International (2023)Github (n.d.)

Research Question

What maturity model best describes the evolution of governance capabilities for AI and low-code in enterprises, specifically, what are the clearly defined maturity stages, capability benchmarks, and progression pathways that allow an organisation to assess its current governance capability state and plan incremental improvements across all governance dimensions?

Findings

Executive Summary

Key Findings

  1. High confidence. Existing public frameworks divide into staged benchmark models, governance-system baselines, and assurance toolkits, so the most defensible enterprise maturity model is a composite rather than an unchanged adoption of any one external framework.
  2. Medium confidence. CMMI is a useful scaffold for the hybrid model because it provides public benchmark levels and appraisal mechanics, but its public material is too generic to serve alone as an AI and low-code governance maturity model.
  3. Medium confidence. Microsoft's current public agentic AI maturity model is a useful AI-specific reference because it describes five levels, explicit anti-patterns, and progression actions across governance, technology, business-process, and cultural pillars, even though its framing remains vendor-shaped.
  4. High confidence. NIST AI RMF and ISO/IEC 42001 should define the baseline control content for each stage, but they are not sufficient on their own because they specify governance functions and management-system requirements rather than explicit maturity thresholds.
  5. Medium confidence. The maturity model must explicitly gate progression on the weakest mandatory control surfaces, especially decision rights, identity and access, enforcement, lifecycle, and regulatory alignment, because failure on those surfaces invalidates claims of enterprise maturity elsewhere.
  6. Medium confidence. Behavioural maturity should cap structural maturity because teams that routinely bypass the sanctioned path remain effectively immature even when control documents, councils, and review workflows formally exist.
  7. High confidence. The supported progression pathway runs from policy, literacy, and inventory, to basic guardrails and tiering, to standardised shared controls, then to automated risk-tiered operations and finally to adaptive assurance, because value appears only after foundations become reusable and measurable.
  8. High confidence. A credible assessment mechanism must require evidence artefacts, operating evidence, and assurance evidence for every scored dimension, because governance maturity cannot be validated by interviews or questionnaires alone.

Assumptions

Analysis

Stage Name Proposed threshold Typical evidence Basis
1 Ad hoc experimentation [inference] Local pilots exist, but there is no enterprise inventory, no tiering, no AI-specific governance, and no repeatable maker or deployment path. [inference] Pilot demos, informal approvals, personal workspaces, fragmented logs MIT Center for Information Systems Research (MIT CISR) Enterprise AI Maturity Model
Microsoft agentic AI adoption maturity model overview
2 Guardrailed repeatability [inference] Basic policy, ownership, environment separation, intake, and low-risk guardrails exist, but enforcement is still partial and manual. [inference] Acceptable-use policy, named owners, dev-test-prod separation, simple intake form, first connector restrictions Microsoft governance, security, and operations maturity pillar
Responsible AI Toolkit
MIT Center for Information Systems Research (MIT CISR) Enterprise AI Maturity Model
3 Defined federated governance [inference] Enterprise standards, role clarity, risk tiers, approved build paths, lifecycle gates, registry, telemetry, and delegated low-risk execution exist under shared guardrails. [inference] Standard control library, risk-tier matrix, registry, approved reference architectures, lifecycle checklist, baseline dashboards Microsoft agentic AI adoption maturity model overview
Microsoft governance, security, and operations maturity pillar
davidamitchell.github.io
davidamitchell.github.io
4 Managed risk-tiered scale [inference] Controls are measured in production, approvals and enforcement are increasingly automated, and value, risk, and reliability are reviewed by tier. [inference] Automated policy checks, release gates, alerting, value dashboards, exception workflow, retirement reviews DevOps Research and Assessment (DORA) 2025 report announcement
Microsoft governance, security, and operations maturity pillar
davidamitchell.github.io
5 Adaptive assurance [inference] Governance, assurance, and optimisation adapt continuously using telemetry, incident learning, regulatory change, and predictive risk signals. [inference] Continuous compliance evidence, predictive risk analytics, automated remediation, cross-functional optimisation cadence, external assurance artefacts International Organization for Standardization (ISO) and International Electrotechnical Commission (IEC) 42001:2023 overview
Microsoft governance, security, and operations maturity pillar
NIST AI RMF overview
Dimension Stage 2 threshold Stage 3 threshold Stage 4 threshold Stage 5 threshold Basis
Decision rights and accountability [inference] Named owner per use case [inference] Responsibility-assignment matrix and escalation by agent class [inference] Delegated approvals by risk tier [inference] Dynamic decision rights reviewed by telemetry and incidents davidamitchell.github.io
Microsoft organisation and culture maturity pillar
Identity and access [inference] Basic role-based access control and approved identities [inference] Machine and human identities governed with least privilege [inference] Policy-driven identity enforcement and periodic access review [inference] Continuous identity assurance and anomaly-driven remediation davidamitchell.github.io
NIST AI RMF overview
Enforcement architecture [inference] Basic connector and action restrictions [inference] Standard enforcement points defined across gateways, connectors, and runtimes [inference] Automated multi-layer enforcement with exception workflow [inference] Adaptive policy tuning and cross-layer consistency checks davidamitchell.github.io
Microsoft governance, security, and operations maturity pillar
Observability and telemetry [inference] Usage logs captured for shared systems [inference] Standard dashboards, alerts, and audit trails by class [inference] Production reliability, safety, and compliance metrics reviewed routinely [inference] Predictive analytics and automated anomaly response davidamitchell.github.io
Microsoft governance, security, and operations maturity pillar
Risk tiering [inference] Initial low-medium-high use-case categorisation [inference] Tier-specific controls, approvals, and deployment paths [inference] Tier-specific service levels and automated policy selection [inference] Dynamic re-tiering based on behaviour, incidents, and context davidamitchell.github.io
NIST AI RMF Playbook
Data governance [inference] Approved data sources and basic separation [inference] Data classification, approved retrieval patterns, and connector policy [inference] Data lineage, sensitive-data controls, and monitored exceptions [inference] Continuous data-policy verification and adaptive protection davidamitchell.github.io
International Organization for Standardization (ISO) and International Electrotechnical Commission (IEC) 42001:2023 overview
Lifecycle management [inference] Manual review before production [inference] Standard build-test-release-retire gates by class [inference] Automated release gates, periodic recertification, retirement triggers [inference] Continuous lifecycle optimisation with policy and model refresh davidamitchell.github.io
Microsoft governance, security, and operations maturity pillar
Business value and cost governance [inference] Basic success criteria and owner [inference] Baselines, key metrics, and portfolio visibility [inference] Value and cost reviewed by risk tier and lifecycle status [inference] Real-time value-risk optimisation and retirement discipline davidamitchell.github.io
Microsoft business strategy maturity pillar
Human oversight [inference] Human approval for sensitive actions [inference] Defined human-in-the-loop patterns by risk tier [inference] Escalation logic and auditability for overrides [inference] Dynamic oversight calibrated by confidence and incident learning davidamitchell.github.io
Microsoft business strategy maturity pillar
SDLC and platform engineering [inference] Shared repository and basic environment separation [inference] Reference architectures, templates, and approved build paths [inference] Automated testing, policy-as-code, and platform self-service with guardrails [inference] Platform continuously evolves from telemetry and failure analysis davidamitchell.github.io
DevOps Research and Assessment (DORA) 2025 report announcement
Vendor and platform constraints [inference] Known platform limits recorded for major tools [inference] Compensating controls documented and approved [inference] Constraint monitoring and standard fallback patterns [inference] Constraint-aware routing and automatic policy adaptation davidamitchell.github.io
International Organization for Standardization (ISO) and International Electrotechnical Commission (IEC) 42001:2023 overview
Failure-mode management [inference] Incident logging and basic postmortems [inference] Failure taxonomy and standard mitigations [inference] Near-miss tracking, control testing, and scenario drills [inference] Predictive prevention and closed-loop remediation davidamitchell.github.io
Microsoft governance, security, and operations maturity pillar
Culture and incentives [inference] Basic training and sponsorship [inference] Sanctioned-path norms, champions, and clear expectations [inference] Incentives reinforce responsible use and escalation [inference] Responsible autonomy is normalised and measured davidamitchell.github.io
Microsoft organisation and culture maturity pillar
Regulatory alignment [inference] Baseline legal and compliance review [inference] Mapped obligations by use-case tier [inference] Evidence pack and review cadence aligned to material regulations [inference] Continuous compliance monitoring and external assurance readiness davidamitchell.github.io
NIST AI RMF overview
International Organization for Standardization (ISO) and International Electrotechnical Commission (IEC) 42001:2023 overview
  1. Establish AI literacy, acceptable-use policy, ownership, and a minimum inventory before scaling pilots.
  2. Introduce guardrails, intake, environment separation, basic risk tiers, and reviewable evidence for shared or production use cases.
  3. Standardise the sanctioned build path with identity, data, lifecycle, and deployment controls embedded into reusable enterprise patterns.
  4. Move to measured scale by automating policy checks, release gates, telemetry, exception handling, and value-risk reviews by tier.
  5. Reach adaptive assurance only after the organisation can continuously update controls, assurance, and operating patterns from incidents, telemetry, and regulatory change.
  1. Score each dimension only when evidence is present in three forms: design evidence, operating evidence, and assurance evidence.
  2. Determine overall maturity using the lowest common stage across mandatory control dimensions rather than the average of all dimensions.
  3. Apply a behavioural cap so that if culture and incentives are more than one stage below structural controls, effective maturity is capped at the behavioural stage.
  4. Reassess quarterly, after major incidents, and before materially increasing autonomy, because maturity is an operating condition rather than a one-time certification.
  5. Treat a maturity claim as credible only when the organisation can show that higher control rigor is improving stability, delivery quality, or measurable governance outcomes rather than adding untracked friction.
  6. A four-stage model was considered but rejected because it collapses the distinction between basic repeatability and measured enterprise scale that Microsoft's five-level ladder and CMMI-style staged benchmarking keep separate.
  7. Weighted-dimension scoring was considered but rejected because it would let strong scores on non-critical dimensions mask failure on identity, enforcement, or regulatory controls.
  8. Separate structural and behavioural scores were considered, but a behavioural cap was chosen for the headline maturity rating because publishing a high structural score beside a low behavioural score would still overstate effective maturity in practice.

Risks, Gaps, and Uncertainties

Open Questions


sources

Starting points, papers, articles, standards, and guidance. Every source includes a Uniform Resource Locator (URL).

Connected items

Loading…

View full knowledge graph →