
TL;DR
An enterprise AI maturity model should show what the organization can govern safely and decide responsibly next. It should not reward the company for accumulating pilots, licenses, policies, or strategy documents without ownership, controls, evidence, and a repeatable review process.
A useful AI maturity assessment examines six operating capabilities: visibility and ownership, governance and security, workflow selection, sanctioned adoption, impact measurement, and portfolio decisions. Each rating should link to evidence and an accountable next action.
The practical sequence is:
- Map AI tools, agents, use cases, costs, and owners.
- Apply governance and controls according to intended use and risk.
- Select workflows with a defined unit of work and completion event.
- Separate assigned access from repeat adoption in those workflows.
- Compare completed work, outcomes, quality, and cost against a baseline.
- Use that evidence to expand, repair, consolidate, restrict, or stop investments.
An AI readiness assessment checks whether the prerequisites exist. An AI maturity assessment checks whether the governance operating model works repeatedly. Oximy spans the evidence chain from AI inventory and ownership through sanctioned adoption, spend, completed work, outcomes, and portfolio decisions. It also enforces AI policy on employees' Windows and Mac devices, and complements systems responsible for model evaluation and regulatory records.
What is an AI maturity model?
An AI maturity model is a framework for evaluating how consistently an organization selects, governs, deploys, adopts, measures, and improves AI. It turns a broad transformation goal into observable operating capabilities.
Maturity is not the number of AI projects. A company can run dozens of pilots while lacking owners, controls, baselines, or stop decisions. Another company can manage a smaller portfolio with clear governance and defensible evidence.
A useful model should answer:
- What AI exists, and who owns it?
- Which uses are approved, restricted, or unknown?
- Which workflows have a defined business problem and baseline?
- Where has AI reached repeat use rather than occasional activity?
- Which completed-work records can support outcome measurement?
- Which investments deserve expansion, intervention, consolidation, or closure?
If the assessment cannot lead to a decision, it is a diagnostic exercise without an operating consequence.
AI readiness assessment versus AI maturity assessment
An ai readiness assessment asks whether the enterprise has enough foundation to begin or scale a specific AI effort. It usually examines leadership alignment, governance, data, infrastructure, skills, workflow suitability, and change capacity.
An ai maturity assessment asks whether those capabilities work repeatedly across real investments. It should inspect evidence from deployed tools, agents, workflows, controls, usage, completed work, and portfolio reviews.
| Question | Readiness assessment | Maturity assessment |
|---|---|---|
| Core purpose | Determine whether prerequisites exist | Determine whether the operating model works repeatedly |
| Typical timing | Before a major deployment or expansion | During recurring program and portfolio reviews |
| Main evidence | Plans, ownership, data availability, controls, skills | Operating records, adoption, completed work, outcomes, decision history |
| Main output | Gaps to address before proceeding | Capabilities to improve and investments to expand, repair, or stop |
| Common failure | Treating intention as capability | Treating activity or scale as proof of value |
Use both when needed. Readiness can prevent a weak launch. Maturity can show why a live program is still failing to produce reliable decisions.
A six-level enterprise AI maturity model
The six-level model below is an Oximy framework, not an industry standard, certification, or benchmark. It gives enterprise teams a practical sequence from visibility to repeatable investment management.
| Level | Operating state | Evidence expected | Next decision |
|---|---|---|---|
| 0. Unmapped | AI use and spend are fragmented or unknown | Partial invoices, disconnected tool lists, unregistered use | Establish scope, ownership, and discovery methods |
| 1. Visible | Material tools, agents, use cases, costs, and owners are recorded | Inventory, contracts, accounts, owners, lifecycle state | Classify intended use and risk |
| 2. Governed | Policy, controls, approvals, exceptions, and review dates exist | Governance records linked to each material AI system | Deploy or continue with monitoring and baselines |
| 3. Adopted | AI returns inside named workflows | Repeat use by team, task, period, and workflow | Connect activity to completed work |
| 4. Measured | Comparable completed work shows outcome movement and limits | Baseline, completion, quality, cost, and outcome records | Expand, repair, consolidate, restrict, or stop |
| 5. Managed | Portfolio decisions repeat on a defined cadence | Decision history, accountable owners, confidence states, follow-up actions | Improve capital allocation and the measurement system |
Do not average these levels into a flattering company-wide score. A mature engineering workflow and an unmapped finance workflow can exist in the same enterprise. Score by capability and workflow, then summarize the portfolio honestly.
What an AI maturity assessment should measure
1. Visibility and ownership
Can the enterprise identify each material model, agent, application, vendor, embedded feature, workflow, cost center, and owner? Does each record have a lifecycle state and review date?
A partial inventory can still be useful if its coverage and gaps are visible. A complete-looking inventory with unknown discovery coverage is less trustworthy.
Evidence examples include contracts, identity records, expense data, cloud and model billing, endpoint or network findings where authorized, application inventories, and owner attestations.
2. Governance and control
Can teams document intended use, affected parties, data, risk, policy, controls, approvals, exceptions, monitoring, and escalation?
NIST AI RMF provides a voluntary structure through Govern, Map, Measure, and Manage. ISO/IEC 42001 specifies requirements for an AI management system and continual improvement. Neither source creates a universal maturity score for a company.
The assessment should test whether governance records are used in decisions, not merely whether templates exist.
3. Workflow selection
Has the organization named the workflow, unit of work, completion event, owner, baseline, outcome, quality guardrail, and measurement period?
Goals such as improve productivity or use AI more are not measurement definitions. A workflow should be specific enough that another reviewer can identify what starts, what finishes, and what evidence remains.
4. Adoption
Can the team distinguish assigned access, observed activity, repeat use in a named workflow, and completed work?
Oximy's AI adoption approach separates these stages because each supports a different intervention. Unused access may require license cleanup. Activity without repeat use may require enablement or workflow redesign. Repeat use without completed-work evidence may expose a measurement gap.
5. Impact measurement
Can the team compare similar completed work over a consistent time window? Are cost, quality, risk, rework, and attribution limits visible?
The assessment should distinguish observed data from estimates, surveys, targets, and unknowns. Time saved should not be converted automatically into cash. It may become capacity, better service, lower cost, lower risk, or no measurable outcome.
6. Portfolio management
Does every material AI investment have an owner, decision date, evidence state, and proposed action? Can executives see what to renew, expand, repair, consolidate, restrict, or stop?
Oximy's AI investment review approach focuses on connecting commitments, repeat use, completed work, measured results, and the next decision. Mature programs do not preserve every pilot by default.
AI maturity assessment tools compared
An AI maturity assessment tool can be a worksheet, survey platform, governance system, analytics product, BI environment, or value-measurement platform. The right format depends on the decision and evidence required.
| Tool type | Best use | Main strength | Main limitation |
|---|---|---|---|
| Questionnaire or workshop | Establish shared language and expose known gaps | Fast, accessible, useful for leadership alignment | Self-reported answers can overstate capability |
| Governance platform | Assess inventory, ownership, policy, risk, controls, and review processes | Preserves governance evidence and accountability | May not connect cost and adoption to completed work and outcomes |
| Native AI analytics | Assess access, activity, and adoption inside one product ecosystem | Uses direct product telemetry | Does not represent the full AI portfolio or prove ROI |
| BI platform | Combine assessment and operating data from several systems | Flexible reporting and heatmaps | Requires reliable definitions, joins, maintenance, and decision workflow |
| Oximy | Enforce AI policy on devices and assess investment, adoption, completed work, impact, and portfolio decisions | Connects later maturity stages to management action | Risk, model-evaluation, and compliance systems remain authoritative for their records |
The best AI maturity assessment tool links each rating to evidence, an owner, and a next action. A polished score without those links is not operational maturity.
A practical enterprise AI maturity assessment
Run the assessment on three to five material AI investments rather than asking leaders to score the company from memory. Include one investment leadership expects to expand, one that appears stalled, and one whose value is disputed.
For each investment:
- Identify the tool, model, agent, vendor, workflow, owners, cost boundary, and decision date.
- Review the six capabilities using linked evidence.
- Mark each answer as observed, documented, self-reported, estimated, missing, or not applicable.
- Find the earliest broken stage in the maturity sequence.
- Assign one corrective action, one owner, and one review date.
- Reassess after the operating change, not after more activity alone.
Use a heatmap instead of one aggregate score:
| Capability | Evidence question | Suggested status |
|---|---|---|
| Visibility | Are material AI systems, costs, workflows, and owners recorded? | Missing, partial, repeatable |
| Governance | Are intended use, risk, controls, approvals, and exceptions current? | Missing, partial, repeatable |
| Workflow | Is the unit of work, completion event, baseline, and outcome defined? | Missing, partial, repeatable |
| Adoption | Can the team distinguish access, activity, repeat use, and completed work? | Missing, partial, repeatable |
| Impact | Can comparable work show outcome movement with quality and attribution limits? | Missing, partial, repeatable |
| Portfolio | Does evidence produce an owned investment decision on a defined date? | Missing, partial, repeatable |
Do not treat unknown as zero or average it away. Unknown is an evidence state that should produce a research or instrumentation action.
How to score maturity without false precision
A maturity assessment needs enough structure to support comparison, but a numerical score can create confidence the evidence does not deserve. A team that assigns 4.2 out of 5 to governance may still be unable to show which systems were reviewed, which controls apply, or when the next review occurs.
Use three evidence states for each capability:
- Missing: the organization cannot provide the required record or owner.
- Partial: some workflows or investments have evidence, but coverage, definitions, or repeatability remain inconsistent.
- Repeatable: the organization can produce the record, owner, definition, and decision history for the assessed scope.
Add two qualifiers where necessary: unknown when the evidence has not been collected, and not applicable when the requirement genuinely does not apply. Require a note and source link for every rating.
The maturity result should identify the earliest broken stage. For example:
- Strong governance with weak workflow definition means the company can control AI but cannot measure impact credibly.
- High activity with weak completed-work evidence means adoption remains uncertain.
- Good outcome data with an unclear cost boundary weakens the investment case.
- A reliable measurement process without recurring portfolio decisions means insight is not changing allocation.
This approach prevents a strong score in one area from hiding a blocking gap elsewhere.
Who should participate in the assessment?
The assessment should include the people who own the relevant records and decisions. That may include the AI program lead, governance or risk owner, security and privacy representatives, finance or procurement, data and analytics, the workflow owner, and someone responsible for implementation.
Do not ask every participant to score every dimension. Finance may own cost boundaries, security may own specific control evidence, and the workflow owner may define completion and quality. The final assessment should show where owners agree, where definitions conflict, and which evidence remains missing.
The output is not a consensus score. It is a documented decision about what the enterprise can prove and what it must fix next.
Common maturity-model mistakes
- Scoring the organization based on executive opinion without checking operating records.
- Awarding maturity for the number of pilots, tools, licenses, or policy documents.
- Combining governance, adoption, and ROI into one opaque score.
- Treating assigned access or prompt counts as workflow adoption.
- Treating estimated time savings as realized financial value.
- Ignoring quality, risk, rework, and displaced work.
- Producing recommendations without owners, dates, or evidence requirements.
The assessment should make disagreement visible. If finance, governance, and a workflow owner rate the same investment differently, inspect the records and definitions instead of averaging the opinions.

