AI Control Maturity Assessment Template

This template is used to assess the maturity of an organization’s AI Control Architecture across the ten control pillars.

The purpose of this template is to help an enterprise understand its current state, target state, gaps, priorities, and improvement roadmap.

This assessment can be used at enterprise level, business unit level, platform level, or for a portfolio of AI use cases.


1. Assessment Information

Assessment Name

[Enter assessment name]

Assessment Date

[Enter date]

Assessment Scope

Select one:

[ ] Enterprise-wide
[ ] Business unit
[ ] Function
[ ] Platform
[ ] Product line
[ ] AI use case portfolio
[ ] Specific AI programme
[ ] Other

Scope Description

[Describe what is included and excluded from the assessment]

Assessment Owner

Name:
Function:
Email:

Participants

Name Function Role in Assessment
[Name] [Function] [Role]

2. Maturity Rating Scale

Use the following maturity scale.

Level Name Description
1 Ad Hoc AI controls are informal, inconsistent, undocumented, or reactive.
2 Visible AI use and risks are visible, but controls are still basic or manual.
3 Integrated AI controls are integrated into enterprise processes and ownership is defined.
4 Measurable AI controls are measured, tested, evidenced, and reported.
5 Adaptive AI controls continuously improve based on risk, monitoring, incidents, and change.

3. Overall Maturity Summary

Current Overall Maturity

Select one:

[ ] Level 1: Ad Hoc
[ ] Level 2: Visible
[ ] Level 3: Integrated
[ ] Level 4: Measurable
[ ] Level 5: Adaptive

Target Overall Maturity

Select one:

[ ] Level 1: Ad Hoc
[ ] Level 2: Visible
[ ] Level 3: Integrated
[ ] Level 4: Measurable
[ ] Level 5: Adaptive

Executive Summary

[Summarize current maturity, major strengths, major gaps, and priority improvements]

4. Pillar Maturity Overview

Pillar Current Level Target Level Gap Priority
AI inventory and classification [1-5] [1-5] [Gap] [Low/Medium/High/Critical]
AI identity and access control [1-5] [1-5] [Gap] [Low/Medium/High/Critical]
Data boundary control [1-5] [1-5] [Gap] [Low/Medium/High/Critical]
Prompt and input control [1-5] [1-5] [Gap] [Low/Medium/High/Critical]
Output and decision control [1-5] [1-5] [Gap] [Low/Medium/High/Critical]
Tool and action control [1-5] [1-5] [Gap] [Low/Medium/High/Critical]
Human accountability model [1-5] [1-5] [Gap] [Low/Medium/High/Critical]
AI assurance and testing [1-5] [1-5] [Gap] [Low/Medium/High/Critical]
Monitoring, logging, and evidence [1-5] [1-5] [Gap] [Low/Medium/High/Critical]
Incident containment and recovery [1-5] [1-5] [Gap] [Low/Medium/High/Critical]

5. Pillar 1: AI Inventory and Classification

Current Maturity

Select one:

[ ] Level 1: Ad Hoc
[ ] Level 2: Visible
[ ] Level 3: Integrated
[ ] Level 4: Measurable
[ ] Level 5: Adaptive

Assessment Questions

Question Response
Is there an AI inventory? [Yes/No/Partial]
Are AI use cases registered? [Yes/No/Partial]
Are AI owners assigned? [Yes/No/Partial]
Are AI patterns classified? [Yes/No/Partial]
Are risk tiers assigned? [Yes/No/Partial]
Is embedded vendor AI tracked? [Yes/No/Partial]
Is shadow AI discovery performed? [Yes/No/Partial]
Is inventory reviewed periodically? [Yes/No/Partial]
Does risk tier drive required controls? [Yes/No/Partial]

Evidence Reviewed

[Reference evidence reviewed]

Strengths

[Describe strengths]

Gaps

[Describe gaps]

Target Maturity

[Describe target maturity for this pillar]

Improvement Actions

Action Owner Due Date Priority
[Action] [Owner] [Date] [Priority]

6. Pillar 2: AI Identity and Access Control

Current Maturity

Select one:

[ ] Level 1: Ad Hoc
[ ] Level 2: Visible
[ ] Level 3: Integrated
[ ] Level 4: Measurable
[ ] Level 5: Adaptive

Assessment Questions

Question Response
Are AI identity models defined? [Yes/No/Partial]
Are AI actors identified? [Yes/No/Partial]
Is delegated authority documented? [Yes/No/Partial]
Is AI access approved? [Yes/No/Partial]
Is AI access least privilege? [Yes/No/Partial]
Is privileged AI access controlled? [Yes/No/Partial]
Are AI access reviews performed? [Yes/No/Partial]
Can AI access be revoked? [Yes/No/Partial]
Is AI-mediated activity attributable? [Yes/No/Partial]

Evidence Reviewed

[Reference evidence reviewed]

Strengths

[Describe strengths]

Gaps

[Describe gaps]

Target Maturity

[Describe target maturity for this pillar]

Improvement Actions

Action Owner Due Date Priority
[Action] [Owner] [Date] [Priority]

7. Pillar 3: Data Boundary Control

Current Maturity

Select one:

[ ] Level 1: Ad Hoc
[ ] Level 2: Visible
[ ] Level 3: Integrated
[ ] Level 4: Measurable
[ ] Level 5: Adaptive

Assessment Questions

Question Response
Are AI data sources mapped? [Yes/No/Partial]
Is data classification applied to AI use cases? [Yes/No/Partial]
Are retrieval boundaries defined? [Yes/No/Partial]
Are sensitive data exposures approved? [Yes/No/Partial]
Are training and reuse restrictions defined? [Yes/No/Partial]
Are retention rules defined for AI data? [Yes/No/Partial]
Is output sensitivity handled? [Yes/No/Partial]
Are data leakage tests performed? [Yes/No/Partial]
Is data access logged for high-risk AI? [Yes/No/Partial]

Evidence Reviewed

[Reference evidence reviewed]

Strengths

[Describe strengths]

Gaps

[Describe gaps]

Target Maturity

[Describe target maturity for this pillar]

Improvement Actions

Action Owner Due Date Priority
[Action] [Owner] [Date] [Priority]

8. Pillar 4: Prompt and Input Control

Current Maturity

Select one:

[ ] Level 1: Ad Hoc
[ ] Level 2: Visible
[ ] Level 3: Integrated
[ ] Level 4: Measurable
[ ] Level 5: Adaptive

Assessment Questions

Question Response
Are allowed inputs defined? [Yes/No/Partial]
Are prohibited inputs defined? [Yes/No/Partial]
Are sensitive data input restrictions defined? [Yes/No/Partial]
Are system prompts protected? [Yes/No/Partial]
Are prompt changes versioned and reviewed? [Yes/No/Partial]
Is prompt injection risk assessed? [Yes/No/Partial]
Is prompt injection testing performed? [Yes/No/Partial]
Is context isolation defined? [Yes/No/Partial]
Are input policy violations logged? [Yes/No/Partial]

Evidence Reviewed

[Reference evidence reviewed]

Strengths

[Describe strengths]

Gaps

[Describe gaps]

Target Maturity

[Describe target maturity for this pillar]

Improvement Actions

Action Owner Due Date Priority
[Action] [Owner] [Date] [Priority]

9. Pillar 5: Output and Decision Control

Current Maturity

Select one:

[ ] Level 1: Ad Hoc
[ ] Level 2: Visible
[ ] Level 3: Integrated
[ ] Level 4: Measurable
[ ] Level 5: Adaptive

Assessment Questions

Question Response
Are AI output types classified? [Yes/No/Partial]
Is decision impact classified? [Yes/No/Partial]
Are validation rules defined for high-impact outputs? [Yes/No/Partial]
Are AI recommendations separated from final decisions? [Yes/No/Partial]
Is human review defined where required? [Yes/No/Partial]
Are customer-facing outputs controlled? [Yes/No/Partial]
Are generated records governed? [Yes/No/Partial]
Is decision evidence retained? [Yes/No/Partial]
Are output quality metrics tracked? [Yes/No/Partial]

Evidence Reviewed

[Reference evidence reviewed]

Strengths

[Describe strengths]

Gaps

[Describe gaps]

Target Maturity

[Describe target maturity for this pillar]

Improvement Actions

Action Owner Due Date Priority
[Action] [Owner] [Date] [Priority]

10. Pillar 6: Tool and Action Control

Current Maturity

Select one:

[ ] Level 1: Ad Hoc
[ ] Level 2: Visible
[ ] Level 3: Integrated
[ ] Level 4: Measurable
[ ] Level 5: Adaptive

Assessment Questions

Question Response
Are AI-accessible tools inventoried? [Yes/No/Partial]
Are AI actions classified by risk? [Yes/No/Partial]
Is tool access approved? [Yes/No/Partial]
Are action boundaries defined? [Yes/No/Partial]
Are approval gates defined for high-risk actions? [Yes/No/Partial]
Are blast-radius limits defined? [Yes/No/Partial]
Are tool calls and actions logged? [Yes/No/Partial]
Are kill switches defined and tested? [Yes/No/Partial]
Are rollback or compensation paths defined? [Yes/No/Partial]

Evidence Reviewed

[Reference evidence reviewed]

Strengths

[Describe strengths]

Gaps

[Describe gaps]

Target Maturity

[Describe target maturity for this pillar]

Improvement Actions

Action Owner Due Date Priority
[Action] [Owner] [Date] [Priority]

11. Pillar 7: Human Accountability Model

Current Maturity

Select one:

[ ] Level 1: Ad Hoc
[ ] Level 2: Visible
[ ] Level 3: Integrated
[ ] Level 4: Measurable
[ ] Level 5: Adaptive

Assessment Questions

Question Response
Are business owners assigned? [Yes/No/Partial]
Are technical owners assigned where required? [Yes/No/Partial]
Are decision owners assigned where required? [Yes/No/Partial]
Are human review models defined? [Yes/No/Partial]
Are approval responsibilities defined? [Yes/No/Partial]
Are escalation paths defined? [Yes/No/Partial]
Are override rights defined? [Yes/No/Partial]
Are exceptions owned and time-bound? [Yes/No/Partial]
Is accountability evidence retained? [Yes/No/Partial]

Evidence Reviewed

[Reference evidence reviewed]

Strengths

[Describe strengths]

Gaps

[Describe gaps]

Target Maturity

[Describe target maturity for this pillar]

Improvement Actions

Action Owner Due Date Priority
[Action] [Owner] [Date] [Priority]

12. Pillar 8: AI Assurance and Testing

Current Maturity

Select one:

[ ] Level 1: Ad Hoc
[ ] Level 2: Visible
[ ] Level 3: Integrated
[ ] Level 4: Measurable
[ ] Level 5: Adaptive

Assessment Questions

Question Response
Are assurance requirements defined by risk tier? [Yes/No/Partial]
Is pre-deployment testing performed? [Yes/No/Partial]
Is prompt injection testing performed where required? [Yes/No/Partial]
Is data leakage testing performed where required? [Yes/No/Partial]
Is output validation testing performed where required? [Yes/No/Partial]
Is tool/action testing performed where required? [Yes/No/Partial]
Is regression testing performed after material change? [Yes/No/Partial]
Are findings tracked to closure? [Yes/No/Partial]
Is assurance evidence retained? [Yes/No/Partial]

Evidence Reviewed

[Reference evidence reviewed]

Strengths

[Describe strengths]

Gaps

[Describe gaps]

Target Maturity

[Describe target maturity for this pillar]

Improvement Actions

Action Owner Due Date Priority
[Action] [Owner] [Date] [Priority]

13. Pillar 9: Monitoring, Logging, and Evidence

Current Maturity

Select one:

[ ] Level 1: Ad Hoc
[ ] Level 2: Visible
[ ] Level 3: Integrated
[ ] Level 4: Measurable
[ ] Level 5: Adaptive

Assessment Questions

Question Response
Are logging requirements defined by risk tier? [Yes/No/Partial]
Is an AI event taxonomy defined? [Yes/No/Partial]
Are high-risk AI interactions logged? [Yes/No/Partial]
Are AI data access events logged? [Yes/No/Partial]
Are tool calls and actions logged? [Yes/No/Partial]
Are approvals and exceptions logged? [Yes/No/Partial]
Are AI policy violations detected? [Yes/No/Partial]
Are logs protected and retained? [Yes/No/Partial]
Can AI activity be reconstructed? [Yes/No/Partial]

Evidence Reviewed

[Reference evidence reviewed]

Strengths

[Describe strengths]

Gaps

[Describe gaps]

Target Maturity

[Describe target maturity for this pillar]

Improvement Actions

Action Owner Due Date Priority
[Action] [Owner] [Date] [Priority]

14. Pillar 10: Incident Containment and Recovery

Current Maturity

Select one:

[ ] Level 1: Ad Hoc
[ ] Level 2: Visible
[ ] Level 3: Integrated
[ ] Level 4: Measurable
[ ] Level 5: Adaptive

Assessment Questions

Question Response
Are AI incident scenarios defined? [Yes/No/Partial]
Is AI incident severity defined? [Yes/No/Partial]
Are AI incident owners defined? [Yes/No/Partial]
Are AI access revocation paths defined? [Yes/No/Partial]
Are agent and tool kill switches defined where required? [Yes/No/Partial]
Is AI incident evidence preservation defined? [Yes/No/Partial]
Are escalation paths defined? [Yes/No/Partial]
Are recovery or correction actions defined? [Yes/No/Partial]
Are vendor AI incident processes defined? [Yes/No/Partial]
Are post-incident reviews used to improve controls? [Yes/No/Partial]

Evidence Reviewed

[Reference evidence reviewed]

Strengths

[Describe strengths]

Gaps

[Describe gaps]

Target Maturity

[Describe target maturity for this pillar]

Improvement Actions

Action Owner Due Date Priority
[Action] [Owner] [Date] [Priority]

15. Cross-Pillar Findings

Major Strengths

[Summarize the strongest areas across the AI Control Architecture]

Major Gaps

[Summarize the most important maturity gaps]

Highest-Risk Gaps

Gap ID Pillar Gap Description Risk Priority Owner
[Gap ID] [Pillar] [Description] [Low/Medium/High/Critical] [Priority] [Owner]

Dependencies

[Describe dependencies that affect maturity improvement]

16. Target State

Target Maturity Statement

[Describe the desired future state for AI Control Architecture maturity]

Target Capabilities

Select all that apply:

[ ] Complete AI inventory
[ ] Risk-tier-driven controls
[ ] AI identity and access governance
[ ] Data classification-driven AI boundaries
[ ] Prompt and input controls
[ ] Output and decision validation
[ ] Tool and action governance
[ ] Human accountability model
[ ] Repeatable AI assurance
[ ] AI monitoring and evidence
[ ] AI incident response
[ ] Vendor AI governance
[ ] GRC integration
[ ] SIEM/SOC integration
[ ] Continuous improvement loop

Target State Notes

[Describe target-state design, operating model, and control expectations]

17. Improvement Roadmap

30-Day Actions

Action Pillar Owner Outcome
[Action] [Pillar] [Owner] [Outcome]

60-Day Actions

Action Pillar Owner Outcome
[Action] [Pillar] [Owner] [Outcome]

90-Day Actions

Action Pillar Owner Outcome
[Action] [Pillar] [Owner] [Outcome]

6-Month Actions

Action Pillar Owner Outcome
[Action] [Pillar] [Owner] [Outcome]

12-Month Actions

Action Pillar Owner Outcome
[Action] [Pillar] [Owner] [Outcome]

18. Metrics

Metric Current Target Owner Reporting Frequency
Number of AI use cases inventoried [Value] [Target] [Owner] [Frequency]
Percentage of AI use cases with owners [Value] [Target] [Owner] [Frequency]
Percentage of AI use cases risk-tiered [Value] [Target] [Owner] [Frequency]
Percentage of high-risk AI reviewed [Value] [Target] [Owner] [Frequency]
Percentage with defined identity model [Value] [Target] [Owner] [Frequency]
Percentage with data boundaries defined [Value] [Target] [Owner] [Frequency]
Percentage with logging requirements implemented [Value] [Target] [Owner] [Frequency]
Number of open AI exceptions [Value] [Target] [Owner] [Frequency]
Number of AI assurance findings [Value] [Target] [Owner] [Frequency]
Number of AI incidents or near misses [Value] [Target] [Owner] [Frequency]
Percentage of agents with kill switches [Value] [Target] [Owner] [Frequency]
Evidence package completeness [Value] [Target] [Owner] [Frequency]

19. Approval and Review

Assessment Completed By

Name:
Function:
Date:

Reviewed By

Name Function Decision Date
[Name] [Function] [Approved/Rejected/Conditional] [Date]

Final Assessment Decision

Select one:

[ ] Accepted
[ ] Accepted with actions
[ ] Requires remediation plan
[ ] Requires executive review
[ ] Deferred

Next Assessment Date

[Enter date]

20. Summary

Assessment scope:
Current overall maturity:
Target overall maturity:
Strongest pillars:
Weakest pillars:
Highest-risk gaps:
Priority actions:
Roadmap owner:
Next review date: