← Assessment
How to Score?

How to score the AI Altitude Assessment.

A reference for anyone completing an assessment. Read this first if you're new to the framework. It'll save you time and produce more useful results.

How to Approach the Assessment

01

Score what's true today, not what's planned.

The value of this exercise is the gap it surfaces. Aspirational scoring hides exactly the work the assessment is meant to expose. If a control is documented but not enforced, it is "Defined," not "Managed."

02

When in doubt, score lower.

If you're undecided between two adjacent levels, pick the lower one. Lower scores generate priority recommendations; higher scores get optimization advice. Underscoring produces useful output. Overscoring produces flattering noise.

03

Score the worst-case across the organization.

If a practice exists in one business unit but not another, it is not yet "Defined" at the organization level. The assessment measures the floor of practice, not the ceiling. Pockets of excellence are valuable but they are not enterprise governance.

04

Use the notes field generously.

Every question accepts a free-text note. Capture the "yes, but…": what evidence supports the score, what's in flight, who owns it, when does it ship. The notes carry through to the exported report and turn a maturity number into an actionable record.

The 0–5 Maturity Scale

Used for every question in the assessment
0
Not Addressed
No formal recognition of this practice.

The organization has no documented approach, no named owner, and no controls in place. Activities, if they occur at all, happen by accident or as side effects of other work. This score is honest, not embarrassing. Most organizations have several domains here when they baseline for the first time.

Look for:
  • No policy, standard, or procedure exists
  • No named owner or accountable party
  • No metrics, logs, or evidence collected
  • Conversations about this topic have not yet occurred at the leadership level
1
Ad-hoc
Reactive and inconsistent.

The practice exists in isolated cases, often triggered by an incident, an audit finding, or one motivated individual. There is no consistency across teams, projects, or business units. What happens once may not happen again, and there is no shared playbook.

Look for:
  • Individual heroics, tribal knowledge, or one-off projects
  • Reactive: addressed only when something goes wrong
  • Different teams handle it differently or not at all
  • No documentation that survives the people involved
2
Developing
Recognized as needed; uneven adoption.

The organization has acknowledged the gap and is beginning to act. Pilot programs are underway, some teams have moved further than others, and there is enough motion that leadership can point to it, but enforcement is light and coverage is partial.

Look for:
  • Pilot programs or proof-of-concepts in flight
  • Pockets of practice in advanced teams; gaps in others
  • Draft policies circulating but not yet ratified
  • Inconsistent enforcement: depends on who's watching
3
Defined
Documented, standardized, communicated.

The practice is documented in a written standard or policy, communicated to relevant teams, and broadly followed. Most teams comply because they know what's expected, though enforcement may rely on periodic checks rather than continuous controls. This is the threshold most regulators consider 'present.'

Look for:
  • Written policy or standard exists and is current
  • Most teams trained and following the standard
  • Periodic audits or reviews verify compliance
  • A named owner or governing committee maintains the standard
4
Managed
Measured, enforced, and continuously monitored.

The practice is enforced by automation or recurring review, with quantitative metrics that drive improvement. Deviations are detected quickly and trigger a defined response. Leadership sees the metrics on a regular cadence and uses them to make decisions.

Look for:
  • Continuous controls (automation, gateways, telemetry) enforce the standard
  • KPIs and dashboards are reported on a defined cadence
  • Defined SLAs and escalation paths for deviations
  • Leadership reviews metrics and acts on them
5
Optimized
Integrated, predictive, continuously improving.

The practice is woven into how the organization operates. Lessons learned drive an explicit improvement loop, controls are predictive rather than reactive, and the program benchmarks itself against industry peers. This level is rare: few organizations are here on more than one or two domains.

Look for:
  • Predictive analytics surface emerging risk before incidents
  • Self-healing or auto-remediating controls
  • External benchmarking against industry peers
  • Continuous improvement loop with documented iterations

Maturity Stage

Where overall and per-domain scores land you

After all questions are answered, the platform computes an overall score and a score per domain. Each percentage maps to one of five maturity stages (Foundational, Emerging, Established, Mature, Leading) that summarize where the program is and what to focus on next.

Foundational

0–20%

AI activity is happening, but the organization has very little visibility or control. Exposure is likely outpacing the controls in place. This is not a moral failing. It is the starting state for most organizations that have not yet treated AI as a governable surface area.

Stand up an AI governance program with named ownership, baseline an inventory of AI use, and publish a simple acceptable-use policy. The goal at this stage is to install the foundation, not to perfect anything yet.

Emerging

20–40%

Awareness is building and pockets of practice exist, but controls are inconsistent and enforcement is light. The organization is moving but has not yet committed.

Codify governance ownership, expand discovery to shadow AI, and start API key lifecycle management. Translate good intentions into written standards that survive personnel changes.

Established

40–60%

Programs are defined and most teams are following them. The work now is operationalization: turning policies into automated, measured controls.

Operationalize policies through gateways and identity layers, instrument both human and non-human identities, and start measuring adoption with hard metrics.

Mature

60–80%

Governance is mature and reportable. Controls are managed and metrics drive decisions. The frontier risks are agentic AI and MCP security, where mature governance does not automatically translate.

Tighten agentic AI guardrails, mature MCP security, and integrate AI events into existing IR workflows. Ensure your IR team can investigate an AI-driven incident with the same fluency they handle a human-driven one.

Leading

80–100%

AI governance is a competitive advantage. The organization is ahead of regulators and most peers. Risk is no longer the absence of controls: it's complacency.

Continuous improvement, threat-informed defense for agentic systems, external assurance, and benchmarking against industry peers. At this stage, the work is staying ahead.

What Happens to Your Score

Per-domain rollup

Each domain's score is the average of its answered questions, expressed as 0–100%. Unanswered questions are excluded so partial assessments still produce useful directional signal.

Overall score

The overall score is the mean of the per-domain percentages, with equal weighting across domains. This means weak domains pull the score down meaningfully, surfacing the priorities for investment.

Stage assignment

The overall score maps to a maturity stage. Each stage carries headline guidance and priority recommendations calibrated to where the program sits today.

Detailed recommendations

The three lowest-scoring domains receive structured recommendations: headline action, supporting context, and references to relevant frameworks (NIST AI RMF, ISO/IEC 42001, EU AI Act).

Trend tracking

Subsequent assessments for the same organization roll up into a trend report: a line chart of overall altitude over time, plus per-domain delta tables to show what improved and what regressed.

Ready to begin?

The assessment takes 30–45 minutes for someone familiar with the program. Your responses autosave as you go. There's no penalty for stepping away and returning.

Start an Assessment