Assessment hub, not another generic explainer
AI Governance Maturity Model
Most AI governance maturity content either repeats the same five-stage template with no framework grounding, or is enterprise content marketing from a single vendor. This hub organizes the real, named frameworks a program is actually measured against, cites them directly, and gives a concrete next step for each stage - it does not claim to certify or guarantee anything.
Not a compliance guarantee. Working through this page does not mean your program satisfies NIST AI RMF, ISO/IEC 42001, or any regulator. Use it to orient, then verify against the issuing bodies directly - see frameworks.
The five stages
Ad hoc
No documented AI inventory, no assigned governance owner, policy decisions made case by case.
Next step: Start with a documented AI system inventory and name a single accountable owner before adopting any framework formally.
Defined
A written AI policy exists and maps loosely to a named framework, but it is not consistently applied across teams or systems.
Next step: Pick one framework as your primary reference (most US-based programs start with NIST AI RMF) and map every in-scope system against its functions.
Managed
Governance is applied consistently, with defined roles, a risk register, and periodic review, but has not been independently tested.
Next step: Commission an independent AI governance audit against your primary framework before claiming the program is operating as designed.
Measured
The program has been independently audited, findings are tracked to closure, and metrics feed back into the risk register.
Next step: Formalize a recurring audit cadence and consider a second framework (e.g. ISO/IEC 42001 certification) if your buyers or regulators require it.
Optimizing
Multiple frameworks are cross-mapped, audit findings drive measurable process change, and the program is a genuine input to product/AI risk decisions.
Next step: Maintain independent verification cadence and keep the framework mapping current as NIST, ISO, and sector-specific frameworks evolve.
Named frameworks
What this hub is organized around
Model Governance Index cites these frameworks directly rather than paraphrasing them. Read the source, not a summary, before making a program decision.
Artificial Intelligence Risk Management Framework (AI RMF 1.0)
The NIST AI RMF provides voluntary guidance to help organizations that design, develop, deploy, or use AI systems manage risks to individuals, organizations, and society. It is intended for use across sectors, use cases, and organization sizes, and is not tied to any specific technology. The framework organizes AI risk management around four functions, Govern, Map, Measure, and Manage, oriented toward seven characteristics of trustworthy AI: valid and reliable, safe, secure and resilient, accountable and transparent, explainable and interpretable, privacy-enhanced, and fair with harmful bias managed.
ISO 42001ISO/IEC 42001:2023 - Information technology - Artificial intelligence - Management system
ISO/IEC 42001:2023 specifies requirements, with guidance, for establishing, implementing, maintaining, and continually improving an AI management system (AIMS) within an organization. It is the first international management-system standard written specifically for AI and is designed for any organization, of any size or sector, that provides or uses AI-based products or services. It addresses AI-specific concerns such as algorithmic bias, transparency, and lifecycle impacts rather than treating AI as generic IT.
EU AI ActRegulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act)
The EU AI Act is a binding EU regulation establishing harmonised rules for the development, placing on the market, and use of AI systems across the European Union. It applies a risk-based approach: it bans certain 'unacceptable risk' AI practices, imposes detailed obligations on 'high-risk' AI systems, sets lighter transparency duties on limited-risk systems, and adds separate obligations for providers of general-purpose AI (GPAI) models. It applies to providers and deployers of AI systems placed on the EU market or whose AI output is used within the EU, regardless of where the provider is established.
IIA AI Auditing FrameworkThe IIA's Artificial Intelligence Auditing Framework
The IIA's AI Auditing Framework gives internal auditors principles-based guidance for assessing an organization's AI governance, risk management, and controls. It covers AI risk from strategy and governance through model development, deployment, and monitoring, including generative AI and large language models. It is intended for internal audit functions, chief audit executives, and audit committees performing assurance or advisory engagements on AI use, and it is explicitly structured around the IIA's Three Lines Model.
Three Lines ModelThe IIA's Three Lines Model
The IIA's Three Lines Model is a governance and risk-management model that assigns distinct roles to a governing body, management (split into first-line and second-line roles), and an independent internal audit function, the third line. Internal audit practitioners and the IIA apply this same structure to AI governance: first-line roles build, deploy, and operate AI systems and own the resulting risk; second-line roles provide AI-specific risk expertise, monitoring, and challenge; and internal audit provides independent assurance that AI risk is being governed and managed effectively. It is a principles-based model meant to be adapted to an organization's structure rather than a prescriptive control checklist.
Ready to move a stage
Get an independent read on where you stand
Self-assessment against this page is a starting point, not a substitute for an independent audit. See our audit methodology guide, or request AI governance consultants directly.
Related guides
Frequently asked questions
Is this an official maturity model from NIST, ISO, or the IIA?
No. This is an independent assessment hub that organizes and cites those real, named frameworks - it is not published or endorsed by NIST, ISO, or the IIA. Always verify framework alignment directly against the issuing body's own current text.
Does reaching a stage mean I am compliant with a framework?
No. No stage on this page is a compliance guarantee. Frameworks like NIST AI RMF are voluntary guidance, not certifications; ISO/IEC 42001 is a certifiable standard but requires a real, independent certification audit, not a self-assessment against this page.
How do I move from one stage to the next?
Each stage above lists a concrete next step. Most programs benefit from an independent audit (see our AI governance audit guide) before claiming a higher maturity stage, since self-assessment alone under-catches gaps a real audit finds.