What maturity model best describes the evolution of governance capabilities for…
What maturity model best describes the evolution of governance capabilities for Artificial Intelligence (AI) and low-code in enterprises?
key claims
- Existing public frameworks divide into staged benchmark models, governance-system baselines, and assurance toolkits, so the most defensible enterprise maturity model is a composite rather than an unchanged adoption of any one external frameworkCMMI (n.d.)Microsoft (n.d.)NIST (n.d.)International (2023)Responsible (n.d.)British (n.d.)
- CMMI is a useful scaffold for the hybrid model because it provides public benchmark levels and appraisal mechanics, but its public material is too generic to serve alone as an AI and low-code governance maturity modelCMMI (n.d.)CMMI (n.d.)
- Microsoft's current public agentic AI maturity model is a useful AI-specific reference because it describes five levels, explicit anti-patterns, and progression actions across governance, technology, business-process, and cultural pillars, even though its framing remains vendor-shapedMicrosoft (n.d.)Microsoft (n.d.)Microsoft (n.d.)Microsoft (n.d.)
- NIST AI RMF and ISO/IEC 42001 should define the baseline control content for each stage, but they are not sufficient on their own because they specify governance functions and management-system requirements rather than explicit maturity thresholdsNational (n.d.)NIST (n.d.)International (2023)
- The maturity model must explicitly gate progression on the weakest mandatory control surfaces, especially decision rights, identity and access, enforcement, lifecycle, and regulatory alignment, because failure on those surfaces invalidates claims of enterprise maturity elsewhereGithub (n.d.)Github (n.d.)Github (n.d.)Github (n.d.)Github (n.d.)
- Behavioural maturity should cap structural maturity because teams that routinely bypass the sanctioned path remain effectively immature even when control documents, councils, and review workflows formally existGithub (n.d.)Microsoft (n.d.)
- The supported progression pathway runs from policy, literacy, and inventory, to basic guardrails and tiering, to standardised shared controls, then to automated risk-tiered operations and finally to adaptive assurance, because value appears only after foundations become reusable and measurableDevOps (2025)DORA (n.d.)MIT (n.d.)
- A credible assessment mechanism must require evidence artefacts, operating evidence, and assurance evidence for every scored dimension, because governance maturity cannot be validated by interviews or questionnaires aloneCMMI (n.d.)NIST (n.d.)International (2023)Github (n.d.)
Research Question
What maturity model best describes the evolution of governance capabilities for AI and low-code in enterprises, specifically, what are the clearly defined maturity stages, capability benchmarks, and progression pathways that allow an organisation to assess its current governance capability state and plan incremental improvements across all governance dimensions?
Findings
Executive Summary
- The best maturity model for enterprise AI and low-code governance is a five-stage hybrid that combines CMMI-style staged appraisal, Microsoft-style AI-specific capability pillars, and NIST AI RMF plus ISO/IEC 42001 governance baselines, because no single public model simultaneously provides benchmarkable stages, AI-specific governance detail, and full multi-surface enterprise control coverage.
- The model should be evidence-based rather than questionnaire-based, using artefacts, operating metrics, and assurance records to determine whether a capability is merely documented, consistently exercised, measured in production, or continuously improved.
- Behavioural maturity must cap structural maturity, because organisations with policies, tools, and councils but with routine bypass behaviour are less mature in practice than their formal control inventory suggests.
- Progression should move from ad hoc experimentation to guarded repeatability, then to defined federated governance, measured risk-tiered scale, and finally adaptive assurance, because the public evidence consistently shows that shared foundations and disciplined scaling precede durable value.
Key Findings
- High confidence. Existing public frameworks divide into staged benchmark models, governance-system baselines, and assurance toolkits, so the most defensible enterprise maturity model is a composite rather than an unchanged adoption of any one external framework.
- Medium confidence. CMMI is a useful scaffold for the hybrid model because it provides public benchmark levels and appraisal mechanics, but its public material is too generic to serve alone as an AI and low-code governance maturity model.
- Medium confidence. Microsoft's current public agentic AI maturity model is a useful AI-specific reference because it describes five levels, explicit anti-patterns, and progression actions across governance, technology, business-process, and cultural pillars, even though its framing remains vendor-shaped.
- High confidence. NIST AI RMF and ISO/IEC 42001 should define the baseline control content for each stage, but they are not sufficient on their own because they specify governance functions and management-system requirements rather than explicit maturity thresholds.
- Medium confidence. The maturity model must explicitly gate progression on the weakest mandatory control surfaces, especially decision rights, identity and access, enforcement, lifecycle, and regulatory alignment, because failure on those surfaces invalidates claims of enterprise maturity elsewhere.
- Medium confidence. Behavioural maturity should cap structural maturity because teams that routinely bypass the sanctioned path remain effectively immature even when control documents, councils, and review workflows formally exist.
- High confidence. The supported progression pathway runs from policy, literacy, and inventory, to basic guardrails and tiering, to standardised shared controls, then to automated risk-tiered operations and finally to adaptive assurance, because value appears only after foundations become reusable and measurable.
- High confidence. A credible assessment mechanism must require evidence artefacts, operating evidence, and assurance evidence for every scored dimension, because governance maturity cannot be validated by interviews or questionnaires alone.
Assumptions
- The completed companion items are a sufficiently complete inventory of governance dimensions for this capstone model. Justification: the workflow intentionally sequenced this item after those companion items, and the remaining uncertainty is about staging and benchmarking, not about discovering wholly new governance surfaces.
- The inaccessible Gartner material and non-public details behind BSI offerings would refine the model more than overturn it. Justification: the public sources already agree on staged progression and governance-system foundations, so the missing material is more likely to add benchmarking nuance than to reverse the core conclusion.
Analysis
- The proposed model is a five-stage hybrid called the Enterprise AI and Low-Code Governance Maturity Model, and it uses CMMI-style appraisal logic, Microsoft's five-level AI-specific ladder, and NIST plus ISO governance baselines as its external backbone.
| Stage | Name | Proposed threshold | Typical evidence | Basis |
|---|---|---|---|---|
| 1 | Ad hoc experimentation | [inference] Local pilots exist, but there is no enterprise inventory, no tiering, no AI-specific governance, and no repeatable maker or deployment path. | [inference] Pilot demos, informal approvals, personal workspaces, fragmented logs | MIT Center for Information Systems Research (MIT CISR) Enterprise AI Maturity Model Microsoft agentic AI adoption maturity model overview |
| 2 | Guardrailed repeatability | [inference] Basic policy, ownership, environment separation, intake, and low-risk guardrails exist, but enforcement is still partial and manual. | [inference] Acceptable-use policy, named owners, dev-test-prod separation, simple intake form, first connector restrictions | Microsoft governance, security, and operations maturity pillar Responsible AI Toolkit MIT Center for Information Systems Research (MIT CISR) Enterprise AI Maturity Model |
| 3 | Defined federated governance | [inference] Enterprise standards, role clarity, risk tiers, approved build paths, lifecycle gates, registry, telemetry, and delegated low-risk execution exist under shared guardrails. | [inference] Standard control library, risk-tier matrix, registry, approved reference architectures, lifecycle checklist, baseline dashboards | Microsoft agentic AI adoption maturity model overview Microsoft governance, security, and operations maturity pillar davidamitchell.github.io davidamitchell.github.io |
| 4 | Managed risk-tiered scale | [inference] Controls are measured in production, approvals and enforcement are increasingly automated, and value, risk, and reliability are reviewed by tier. | [inference] Automated policy checks, release gates, alerting, value dashboards, exception workflow, retirement reviews | DevOps Research and Assessment (DORA) 2025 report announcement Microsoft governance, security, and operations maturity pillar davidamitchell.github.io |
| 5 | Adaptive assurance | [inference] Governance, assurance, and optimisation adapt continuously using telemetry, incident learning, regulatory change, and predictive risk signals. | [inference] Continuous compliance evidence, predictive risk analytics, automated remediation, cross-functional optimisation cadence, external assurance artefacts | International Organization for Standardization (ISO) and International Electrotechnical Commission (IEC) 42001:2023 overview Microsoft governance, security, and operations maturity pillar NIST AI RMF overview |
- The capability matrix below maps the companion governance dimensions to stage thresholds so organisations can see where maturity is constrained.
| Dimension | Stage 2 threshold | Stage 3 threshold | Stage 4 threshold | Stage 5 threshold | Basis |
|---|---|---|---|---|---|
| Decision rights and accountability | [inference] Named owner per use case | [inference] Responsibility-assignment matrix and escalation by agent class | [inference] Delegated approvals by risk tier | [inference] Dynamic decision rights reviewed by telemetry and incidents | davidamitchell.github.io Microsoft organisation and culture maturity pillar |
| Identity and access | [inference] Basic role-based access control and approved identities | [inference] Machine and human identities governed with least privilege | [inference] Policy-driven identity enforcement and periodic access review | [inference] Continuous identity assurance and anomaly-driven remediation | davidamitchell.github.io NIST AI RMF overview |
| Enforcement architecture | [inference] Basic connector and action restrictions | [inference] Standard enforcement points defined across gateways, connectors, and runtimes | [inference] Automated multi-layer enforcement with exception workflow | [inference] Adaptive policy tuning and cross-layer consistency checks | davidamitchell.github.io Microsoft governance, security, and operations maturity pillar |
| Observability and telemetry | [inference] Usage logs captured for shared systems | [inference] Standard dashboards, alerts, and audit trails by class | [inference] Production reliability, safety, and compliance metrics reviewed routinely | [inference] Predictive analytics and automated anomaly response | davidamitchell.github.io Microsoft governance, security, and operations maturity pillar |
| Risk tiering | [inference] Initial low-medium-high use-case categorisation | [inference] Tier-specific controls, approvals, and deployment paths | [inference] Tier-specific service levels and automated policy selection | [inference] Dynamic re-tiering based on behaviour, incidents, and context | davidamitchell.github.io NIST AI RMF Playbook |
| Data governance | [inference] Approved data sources and basic separation | [inference] Data classification, approved retrieval patterns, and connector policy | [inference] Data lineage, sensitive-data controls, and monitored exceptions | [inference] Continuous data-policy verification and adaptive protection | davidamitchell.github.io International Organization for Standardization (ISO) and International Electrotechnical Commission (IEC) 42001:2023 overview |
| Lifecycle management | [inference] Manual review before production | [inference] Standard build-test-release-retire gates by class | [inference] Automated release gates, periodic recertification, retirement triggers | [inference] Continuous lifecycle optimisation with policy and model refresh | davidamitchell.github.io Microsoft governance, security, and operations maturity pillar |
| Business value and cost governance | [inference] Basic success criteria and owner | [inference] Baselines, key metrics, and portfolio visibility | [inference] Value and cost reviewed by risk tier and lifecycle status | [inference] Real-time value-risk optimisation and retirement discipline | davidamitchell.github.io Microsoft business strategy maturity pillar |
| Human oversight | [inference] Human approval for sensitive actions | [inference] Defined human-in-the-loop patterns by risk tier | [inference] Escalation logic and auditability for overrides | [inference] Dynamic oversight calibrated by confidence and incident learning | davidamitchell.github.io Microsoft business strategy maturity pillar |
| SDLC and platform engineering | [inference] Shared repository and basic environment separation | [inference] Reference architectures, templates, and approved build paths | [inference] Automated testing, policy-as-code, and platform self-service with guardrails | [inference] Platform continuously evolves from telemetry and failure analysis | davidamitchell.github.io DevOps Research and Assessment (DORA) 2025 report announcement |
| Vendor and platform constraints | [inference] Known platform limits recorded for major tools | [inference] Compensating controls documented and approved | [inference] Constraint monitoring and standard fallback patterns | [inference] Constraint-aware routing and automatic policy adaptation | davidamitchell.github.io International Organization for Standardization (ISO) and International Electrotechnical Commission (IEC) 42001:2023 overview |
| Failure-mode management | [inference] Incident logging and basic postmortems | [inference] Failure taxonomy and standard mitigations | [inference] Near-miss tracking, control testing, and scenario drills | [inference] Predictive prevention and closed-loop remediation | davidamitchell.github.io Microsoft governance, security, and operations maturity pillar |
| Culture and incentives | [inference] Basic training and sponsorship | [inference] Sanctioned-path norms, champions, and clear expectations | [inference] Incentives reinforce responsible use and escalation | [inference] Responsible autonomy is normalised and measured | davidamitchell.github.io Microsoft organisation and culture maturity pillar |
| Regulatory alignment | [inference] Baseline legal and compliance review | [inference] Mapped obligations by use-case tier | [inference] Evidence pack and review cadence aligned to material regulations | [inference] Continuous compliance monitoring and external assurance readiness | davidamitchell.github.io NIST AI RMF overview International Organization for Standardization (ISO) and International Electrotechnical Commission (IEC) 42001:2023 overview |
- The recommended progression pathway is sequential rather than opportunistic.
- Establish AI literacy, acceptable-use policy, ownership, and a minimum inventory before scaling pilots.
- Introduce guardrails, intake, environment separation, basic risk tiers, and reviewable evidence for shared or production use cases.
- Standardise the sanctioned build path with identity, data, lifecycle, and deployment controls embedded into reusable enterprise patterns.
- Move to measured scale by automating policy checks, release gates, telemetry, exception handling, and value-risk reviews by tier.
- Reach adaptive assurance only after the organisation can continuously update controls, assurance, and operating patterns from incidents, telemetry, and regulatory change.
- The assessment mechanism should use the following rules.
- Score each dimension only when evidence is present in three forms: design evidence, operating evidence, and assurance evidence.
- Determine overall maturity using the lowest common stage across mandatory control dimensions rather than the average of all dimensions.
- Apply a behavioural cap so that if culture and incentives are more than one stage below structural controls, effective maturity is capped at the behavioural stage.
- Reassess quarterly, after major incidents, and before materially increasing autonomy, because maturity is an operating condition rather than a one-time certification.
- Treat a maturity claim as credible only when the organisation can show that higher control rigor is improving stability, delivery quality, or measurable governance outcomes rather than adding untracked friction.
- A four-stage model was considered but rejected because it collapses the distinction between basic repeatability and measured enterprise scale that Microsoft's five-level ladder and CMMI-style staged benchmarking keep separate.
- Weighted-dimension scoring was considered but rejected because it would let strong scores on non-critical dimensions mask failure on identity, enforcement, or regulatory controls.
- Separate structural and behavioural scores were considered, but a behavioural cap was chosen for the headline maturity rating because publishing a high structural score beside a low behavioural score would still overstate effective maturity in practice.
Risks, Gaps, and Uncertainties
- Paywalled Gartner material was unavailable, so the synthesis does not compare its analyst framing directly with the public hybrid model.
- The public DSIT and BSI materials are useful but high-level, which limits how much public evidence exists for externally benchmarked AI-governance maturity assessment mechanisms.
- Some dimension-specific thresholds rely partly on same-repository companion syntheses, so those rows are medium confidence until more public cross-enterprise benchmarking studies become accessible.
Open Questions
- How closely would analyst or proprietary assurance frameworks agree with the proposed gating rule and behavioural cap if their full scoring rubrics were accessible?
- Which sectors should require Stage 4 rather than Stage 3 as the minimum operating threshold for production generative or agentic use cases?
- Which telemetry and assurance signals are most predictive of a pending maturity downgrade before a major incident occurs?
sources
Starting points, papers, articles, standards, and guidance. Every source includes a Uniform Resource Locator (URL).
- [x] CMMI Institute overview — - public overview of CMMI as a staged capability-improvement and benchmarking model
- [x] CMMI model overview — - public description of CMMI domains, business-performance framing, and benchmarking logic
- [x] CMMI appraisal method — - public description of appraisal, benchmark maturity levels, and capability-level assessment
- [x] National Institute of Standards and Technology (NIST) Artificial Intelligence Risk Management Framework (AI RMF) 1.0 publication page — - primary framework publication record and citation
- [x] NIST AI RMF overview — - official NIST page covering framework purpose, profiles, and companion assets
- [x] NIST AI RMF Playbook — - official playbook page showing voluntary guidance and implementation support
- [x] International Organization for Standardization (ISO) and International Electrotechnical Commission (IEC) 42001:2023 overview — - official overview of the Artificial Intelligence Management System standard and continual-improvement framing
- [x] Responsible AI Toolkit — - current United Kingdom government toolkit collection for safe and responsible AI development and deployment
- [x] British Standards Institution (BSI) AI Foundation Framework — - official BSI page describing modular, stepwise AI trust and capability building
- [x] Microsoft agentic AI adoption maturity model overview — - current public five-level AI maturity model with five pillars
- [x] Microsoft governance, security, and operations maturity pillar — - detailed public stage descriptions for governance and lifecycle evolution
- [x] Microsoft technology and data maturity pillar — - public stage descriptions for technology, data, and Application Lifecycle Management (ALM) evolution
- [x] Microsoft organisation and culture maturity pillar — - public stage descriptions for behaviour, enablement, and cultural maturity
- [x] Microsoft business strategy maturity pillar — - public stage descriptions for business-process redesign and value realisation
- [x] MIT Sloan article on enterprise AI maturity — - practitioner summary of the MIT Center for Information Systems Research (MIT CISR) maturity model
- [x] MIT Center for Information Systems Research (MIT CISR) Enterprise AI Maturity Model — - research briefing linking four maturity stages to enterprise performance
- [x] DevOps Research and Assessment (DORA) 2025 report announcement — - public summary of foundational-capability findings
- [x] DORA AI capabilities model report page — - public summary of the seven foundational capabilities and platform findings
- [x] Gartner documents portal — - seeded analyst source, access-gated in this session and not used for downstream factual support