AI Readiness Maturity Model: Measuring Your Progress
Document Type: Maturity model Target Audience: CDOs, CIOs, VP Digital Transformation, AI Program Managers Industries: Life sciences, manufacturing, industrial equipment, insurance, financial services, energy Date Created: January 2020 Version: 2 | Last Updated: August 2026
A maturity model only earns its keep if two people scoring the same organization land on the same number. This assessment breaks AI readiness into four domains and seventeen factors, each scored on one consistent five-level scale, so a 3 means the same thing in Knowledge Accessibility as it does in Security and Compliance. Score all seventeen factors and the points sum to a composite out of 370. That composite is what Framework 4, The AI Readiness Maturity Model, on the Earley AI Frameworks page reports as a single Readiness Level: Not Ready, Early Stage, Developing, Ready to Scale, or Optimized. This page is the diagnostic behind that composite. Score each factor on its own evidence, not on a general impression of the organization.
The Five-Level Scale
Every factor below uses the same five levels. Learn this scale once and it applies everywhere in this assessment.
- Not in place: We haven't started this or it doesn't exist.
- Minimal: We've discussed but taken no meaningful action.
- Developing: Early stages of implementation; partial coverage.
- Established: In place and working reasonably well.
- Optimized: Mature, measured, and continuously improving.
Each factor section restates these same five levels in language specific to that factor, so a factor's Level 3 description stands on its own. You should not need to hold this generic scale in mind while reading it; a retrieval system pulling that one paragraph out of context should not need to either.
Frequently Asked Questions
What is the AI Readiness Maturity Model?
The AI Readiness Maturity Model is Earley Information Science's diagnostic instrument for measuring how prepared an organization's knowledge, operations, technology, and governance are for reliable AI systems. It scores four domains, Knowledge Readiness, Operational Readiness, Technical Readiness, and Governance Readiness, across seventeen factors, each on a five-level scale, then combines those scores into a single composite Readiness Level.
Why does this assessment use the same five-level scale for every factor instead of a scale tailored to each factor?
A single, consistent five-level scale, Not in place, Minimal, Developing, Established, Optimized, lets a score mean the same thing regardless of which factor it describes, so a 3 in Knowledge Accessibility indicates the same maturity as a 3 in Security & Compliance. Each factor restates the scale in its own language so a single level's description stays self-contained and understandable without the generic scale in view.
What is the maximum possible score on the AI Readiness Assessment?
The maximum possible score is 370 points, the sum of all four domain maximums: Knowledge Readiness at 90 points, Operational Readiness at 100 points, Technical Readiness at 85 points, and Governance Readiness at 95 points. An organization's total score divided by 370 produces the percentage that determines its composite Readiness Level, from Not Ready to Optimized.
What does Earley Information Science mean by "Readiness Level" versus a "factor score"?
A factor score rates one specific capability, such as Knowledge Accessibility or Drift Monitoring, on the one-to-five scale from Not in place to Optimized. A Readiness Level is the single composite label, Not Ready, Early Stage, Developing, Ready to Scale, or Optimized, produced by summing all seventeen factor scores and dividing by the 370-point maximum. One measures a part; the other summarizes the whole.
Why do the composite Readiness Level names differ from the per-factor level names, even though both use a five-level scale?
The two scales serve different purposes and are named accordingly. Individual factors use Not in place, Minimal, Developing, Established, and Optimized. The composite score that sums all seventeen factors uses Not Ready, Early Stage, Developing, Ready to Scale, and Optimized instead. Only levels 3 and 5, Developing and Optimized, share the same name across both scales; levels 1, 2, and 4 do not.
Can an organization score differently across the four domains, and is there a separate Readiness Level per domain?
Yes, an organization's domain scores can differ. Knowledge Readiness, Operational Readiness, Technical Readiness, and Governance Readiness are each scored from their own factors before being summed into one 370-point composite. The assessment defines Readiness Levels only for that composite score, not separately for each domain, so an organization can be strong in one domain and weak in another while still receiving a single overall Readiness Level.
Who is this AI Readiness Maturity Model assessment designed for?
This assessment is designed for CDOs, CIOs, VP Digital Transformation, and AI Program Managers evaluating whether their organization's knowledge, operations, technology, and governance are ready to support reliable AI systems. It applies across industries with complex or regulated content, including life sciences, manufacturing, industrial equipment, insurance, financial services, and energy.
Domain 1: Knowledge Readiness
Knowledge Readiness measures whether your content, terminology, and procedures carry enough structure for a retrieval system to find the right segment and trust what it finds.
1.1 Knowledge Accessibility
Centralization and findability of content across the organization. Worth 20 of the 90 points in Knowledge Readiness.
Level 1: Not in place
Knowledge is scattered across disconnected systems (shared drives, emails, individual computers, SME memory). No central repository exists. Finding information requires knowing who to ask.
Level 2: Minimal
Some content has been centralized, but access is inconsistent. Multiple repositories exist with no clear hierarchy. SMEs are still required to locate and interpret most information.
Level 3: Developing
Most critical knowledge is centralized in a primary repository. Content is tagged and searchable, but results require human interpretation. Some content remains siloed.
Level 4: Established
Centralized repository contains validated, structured content with standardized metadata. SMEs validate content but are not the primary source for routine queries.
Level 5: Optimized
Knowledge repository is fully integrated with AI systems. Retrieval is consistent, complete, and governed. Content is automatically indexed and updated.
1.2 Knowledge Organization
Content structure and semantic governance (terminology, taxonomy, metadata). Worth 30 of the 90 points in Knowledge Readiness.
Level 1: Not in place
Knowledge exists as long-form, unstructured documents. No consistent templates. Terminology varies by team. No metadata schema exists.
Level 2: Minimal
Some documents follow templates, but adoption is inconsistent. Basic glossary may exist but is not enforced. Metadata is applied sporadically.
Level 3: Developing
Structured templates are used but unevenly adopted. Agreed terminology is emerging. Metadata schema is defined but inconsistently applied.
Level 4: Established
Knowledge is fully structured into reusable components with consistent metadata. Semantic architecture governs terms and definitions. Content tagging exceeds 80%.
Level 5: Optimized
Knowledge engineering is routine. All content exists as modular components aligned with retrieval logic. Semantic governance is automated and audited.
1.3 Procedural Accuracy
Documentation quality, completeness, and exception handling. Worth 20 of the 90 points in Knowledge Readiness.
Level 1: Not in place
Procedures are outdated or non-existent. Steps, logic, and exceptions are undocumented. Tribal knowledge governs how work gets done.
Level 2: Minimal
Some procedures have been updated, but they lack clarity and exception handling. Documentation is incomplete or inaccurate.
Level 3: Developing
Procedures are mostly accurate with defined decision points. Hazards and warnings are inconsistently documented. Some exception handling exists.
Level 4: Established
Procedures are fully documented including decision trees, exceptions, hazards, and STOP conditions. Content reflects actual practice and is regularly validated.
Level 5: Optimized
Procedures are continuously validated against actual practice. Integration with retrieval logic ensures AI surfaces appropriate warnings. Feedback loops trigger updates.
1.4 Applicability Mapping
Context definitions, constraints, and exclusions for content. Worth 20 of the 90 points in Knowledge Readiness.
Level 1: Not in place
Content lacks any indication of when or where it applies. No constraints or exclusions are documented. Users must determine applicability through experience.
Level 2: Minimal
Some documents indicate applicability, but inconsistently. Constraints are implied rather than explicit. No systematic approach to defining scope.
Level 3: Developing
Applicability is defined for major content areas but incomplete. Some constraints and exclusions documented. Content relationships are partially mapped.
Level 4: Established
All content components include applicability metadata, constraints, and exclusions. Context definitions specify products, regions, customer types, and scenarios.
Level 5: Optimized
Applicability is dynamically governed and enforced during retrieval. AI systems automatically filter content based on user context. Governance ensures metadata stays current.
Frequently Asked Questions
How many factors make up Knowledge Readiness, and how many points is each worth?
Knowledge Readiness includes four factors worth 90 points total: Knowledge Accessibility (20 points), Knowledge Organization (30 points), Procedural Accuracy (20 points), and Applicability Mapping (20 points). Knowledge Organization carries the largest weight of the four, reflecting its role in governing terminology, taxonomy, and metadata across all of an organization's content.
What is the difference between Knowledge Accessibility and Knowledge Organization?
Knowledge Accessibility measures whether content is centralized and findable, whether an employee or AI system can locate the right document at all. Knowledge Organization measures whether that content, once found, is structured with consistent terminology, taxonomy, and metadata. An organization can centralize its content, scoring well on Accessibility, while that content remains unstructured prose, scoring poorly on Organization.
What separates a "Minimal" Knowledge Accessibility organization from a "Developing" one?
At Level 2, Minimal, some content has been centralized, but access is inconsistent across multiple repositories with no clear hierarchy, and subject matter experts are still needed to locate and interpret most information. At Level 3, Developing, most critical knowledge sits in one primary repository that is tagged and searchable, though results still require human interpretation and some content remains siloed.
What changes between a Level 3, Developing, and a Level 5, Optimized, Knowledge Accessibility organization?
At Level 3, Developing, most critical knowledge is centralized and searchable, but results still require human interpretation and some content remains siloed. At Level 5, Optimized, the knowledge repository is fully integrated with AI systems, so retrieval is consistent, complete, and governed, with content automatically indexed and updated rather than depending on people to interpret search results.
What is Applicability Mapping, and why does it matter for AI retrieval?
Applicability Mapping defines when, where, and under what conditions a piece of content applies, including its constraints and exclusions. It matters for AI retrieval because at its highest maturity level, an AI system uses that applicability metadata to automatically filter content by user context, so a retrieval system surfaces only the content that is actually relevant and valid for that specific query.
How does Procedural Accuracy differ from Knowledge Organization?
Knowledge Organization measures whether content is structured with consistent terminology and metadata. Procedural Accuracy measures something different: whether the procedures themselves are correct, complete, and account for exceptions, hazards, and decision points. An organization can score well on Knowledge Organization while its procedures remain outdated or incomplete, since well-structured content and accurate content are separate capabilities this assessment scores independently.
Domain 2: Operational Readiness
Operational Readiness measures whether the people and processes around your content, SME workflows, content lifecycle, drift monitoring, keep pace once an AI system is live rather than static.
2.1 SME Workflow Integration
How subject matter experts collaborate with AI and content systems. Worth 20 of the 100 points in Operational Readiness.
Level 1: Not in place
SMEs generate all knowledge ad hoc. No structured process for capturing expertise. AI systems rely entirely on SME input for each query.
Level 2: Minimal
SMEs occasionally review content but remain primary authors. No defined workflow for SME contribution. SMEs are bottlenecks for information access.
Level 3: Developing
SMEs validate structured content but still rewrite significant portions. Workflow exists but is informal. Some content can be accessed without SME involvement.
Level 4: Established
SMEs validate components through controlled workflows; knowledge engineering manages structure. Clear roles define when SME input is required.
Level 5: Optimized
SMEs act solely as validators; structured knowledge flows independently. Workflow automation routes content for review. AI handles routine queries.
2.2 Lifecycle Management
Content update, review, and retirement processes. Worth 20 of the 100 points in Operational Readiness.
Level 1: Not in place
No systematic content updates or review cycles exist. Content is created and forgotten. Updates happen only when errors cause problems.
Level 2: Minimal
Updates are triggered informally by failures or SME requests. No scheduled review cycles. Some version tracking exists but is inconsistent.
Level 3: Developing
Periodic reviews exist but are unevenly applied. Some content has defined review cycles. Version control is in place for critical content.
Level 4: Established
Lifecycle workflows are formalized with version control and governance approvals. All content has defined review cycles and owners.
Level 5: Optimized
Lifecycle operations are automated. Changes propagate across related components. Analytics identify content needing review. Full audit trail maintained.
2.3 Drift Monitoring
AI performance tracking, error categorization, and issue resolution. Worth 20 of the 100 points in Operational Readiness.
Level 1: Not in place
AI drift is unmonitored. Errors are unnoticed until users complain. No categorization of error types. No feedback mechanism exists.
Level 2: Minimal
Errors are tracked informally with no categorization. Issues are logged but not analyzed. Resolution is reactive and ad hoc.
Level 3: Developing
Drift is tracked manually with basic categorization. Root causes are unclear. Some error patterns identified but not systematically addressed.
Level 4: Established
Formal drift monitoring identifies, categorizes, and resolves issues. Error taxonomy distinguishes content gaps, retrieval failures, and AI limitations.
Level 5: Optimized
Drift monitoring is automated with real-time alerting. Insights drive governance and lifecycle decisions. Predictive analytics identify issues before impact.
2.4 Retrieval Performance
Query accuracy, consistency, and retrieval optimization. Worth 20 of the 100 points in Operational Readiness.
Level 1: Not in place
Retrieval is unpredictable. Chunking is arbitrary. Similar queries return different results. No measurement of retrieval quality.
Level 2: Minimal
Prompt tuning has been attempted but results remain unstable. Basic search exists but relevance is poor. User complaints drive ad hoc fixes.
Level 3: Developing
Metadata improves retrieval consistency but gaps remain. Some queries work well; others fail. Retrieval metrics exist but are not actively managed.
Level 4: Established
Retrieval is governed using metadata-driven constraints and filters. Consistent results for similar queries. Performance metrics are tracked.
Level 5: Optimized
Retrieval performance is continuously monitored and optimized. A/B testing validates improvements. High confidence in retrieval accuracy.
2.5 Operational Maturity
Enterprise integration, risk management, and operational scale. Worth 20 of the 100 points in Operational Readiness.
Level 1: Not in place
AI is used only for experimental pilots. No operational integration. Results are not trusted for real decisions. No risk controls.
Level 2: Minimal
AI is used for limited internal experiments. Some operational awareness but no integration. Manual oversight required for all AI outputs.
Level 3: Developing
AI supports narrow workflows with SME oversight. Some integration with operational systems. Basic risk controls exist.
Level 4: Established
AI is embedded in workflows with risk controls and escalation paths. Integration with core systems. Human oversight focused on exceptions.
Level 5: Optimized
AI is integrated into core processes with enterprise monitoring. Full operational scalability. AI-assisted tools support content operations.
Frequently Asked Questions
How many factors make up Operational Readiness, and how many points is each worth?
Operational Readiness includes five factors, each worth 20 points, for a domain total of 100: SME Workflow Integration, Lifecycle Management, Drift Monitoring, Retrieval Performance, and Operational Maturity. Unlike Knowledge Readiness, where one factor carries more weight than the others, all five Operational Readiness factors are weighted equally.
What is the difference between SME Workflow Integration and Lifecycle Management?
SME Workflow Integration measures how much subject matter experts are still required to author or rewrite content versus simply validating it. Lifecycle Management measures a separate concern: whether content gets updated, reviewed, and retired on a defined schedule rather than aging indefinitely. An organization can have a mature SME workflow while still lacking any systematic process for reviewing or retiring old content.
What is the difference between Drift Monitoring and Retrieval Performance?
Drift Monitoring tracks whether AI outputs are degrading over time by identifying, categorizing, and resolving errors as they emerge. Retrieval Performance measures a related but distinct capability: how accurately and consistently a system pulls the right content for a given query in the first place. An organization can retrieve accurately today, scoring well on Retrieval Performance, while still lacking any process to detect if that accuracy degrades tomorrow.
How does SME involvement change from a Level 1 to a Level 5 SME Workflow Integration organization?
At Level 1, subject matter experts generate all knowledge ad hoc, and AI systems rely entirely on their input for every query. At Level 5, that relationship reverses: SMEs act solely as validators of structured knowledge that flows independently through automated workflows, and AI systems handle routine queries without needing an SME involved at all.
What is Operational Maturity, and how is it different from the Operational Readiness domain itself?
Operational Maturity is one of five factors inside the Operational Readiness domain, not the domain itself. It specifically measures how deeply AI is embedded into an organization's actual business processes, from experimental pilots at Level 1 to enterprise-wide integration with full risk controls at Level 5. The domain, Operational Readiness, is the sum of all five factors, including this one plus SME Workflow Integration, Lifecycle Management, Drift Monitoring, and Retrieval Performance.
What separates a Level 3, Developing, from a Level 4, Established, Operational Maturity organization?
At Level 3, Developing, AI supports narrow workflows with subject matter expert oversight and only basic risk controls exist. At Level 4, Established, AI is embedded directly into workflows with defined risk controls and escalation paths, integrated with core systems, and human oversight is focused specifically on exceptions rather than on every output.
Does Lifecycle Management include retiring outdated content, or only updating it?
Lifecycle Management covers both. The factor explicitly measures an organization's content update, review, and retirement processes, not just how content gets refreshed. At its highest maturity level, these operations are automated end to end: changes propagate across related components, analytics identify content that needs review, and a full audit trail is maintained throughout the content's lifecycle.
Domain 3: Technical Readiness
Technical Readiness measures whether your retrieval architecture, system integration, and monitoring can support AI in production, not just in a demo.
3.1 Technical Foundation
Repository architecture and RAG implementation. Worth 25 of the 85 points in Technical Readiness.
Level 1: Not in place
Knowledge resides in unindexed repositories with no vectorization strategy. If RAG exists, it's naive with irrelevant content frequently retrieved.
Level 2: Minimal
Content is partially centralized but unoptimized for retrieval. Heuristic chunking and basic filters yield unstable outputs.
Level 3: Developing
Repository is structured with embeddings that support retrieval inconsistently. Chunking and metadata provide moderate stability.
Level 4: Established
Engineered content is indexed and optimized for retrieval. RAG architecture uses metadata-driven constraints. Chunking aligns with content structure.
Level 5: Optimized
Embeddings, metadata, and components form a cohesive retrieval system. Architecture is fully engineered, monitored, and optimized.
3.2 Integration & Orchestration
System connectivity, workflow automation, and data flow. Worth 20 of the 85 points in Technical Readiness.
Level 1: Not in place
AI operates in isolation with no workflow integration. No API connectivity to enterprise systems. AI outputs must be manually transferred.
Level 2: Minimal
Basic API experiments exist without operational connectivity. Limited proof-of-concept integrations. Data flows are manual or semi-automated.
Level 3: Developing
Some integrations exist with systems of record. API infrastructure is developing. Data flows are partially documented.
Level 4: Established
AI outputs flow into workflows with full auditability. Documented integrations with CRM, ERP, knowledge bases. Data flows are governed.
Level 5: Optimized
AI is orchestrated across processes with deterministic reliability. Full enterprise integration achieved. Real-time data flows.
3.3 Monitoring & Telemetry
Performance dashboards, diagnostics, and observability. Worth 20 of the 85 points in Technical Readiness.
Level 1: Not in place
No monitoring exists. Errors are known only through user complaints. No visibility into AI system performance. No logging.
Level 2: Minimal
Manual logs track some anomalies. Ad hoc investigation when problems are reported. Basic metrics may exist but are not reviewed.
Level 3: Developing
Basic metrics exist with limited diagnostics. Some automated alerting is in place. Dashboards provide partial visibility.
Level 4: Established
Dashboards provide detailed telemetry on AI performance, usage, and errors. Proactive monitoring catches issues. Metrics reviewed regularly.
Level 5: Optimized
Automated monitoring drives lifecycle improvements. Real-time alerting with intelligent triage. Predictive analytics identify issues before they occur.
3.4 Security & Compliance
Risk controls, data protection, and regulatory compliance. Worth 20 of the 85 points in Technical Readiness.
Level 1: Not in place
No controls exist for provenance or sensitive content. AI operates without security governance. No audit capability.
Level 2: Minimal
Some access controls exist but are not AI-specific. Security team is aware but not engaged. Compliance gaps are known but not addressed.
Level 3: Developing
Basic risk controls are inconsistently applied. Some audit capability exists but gaps remain. Compliance requirements are partially addressed.
Level 4: Established
Security and provenance are enforced via governance. AI-specific policies implemented. Access controls enforced in AI retrieval. Audit trails exist.
Level 5: Optimized
Risk management is continuous, auditable, and regulation-aligned. Security is embedded in the AI lifecycle. Automated compliance checking.
Frequently Asked Questions
How many factors make up Technical Readiness, and how many points is each worth?
Technical Readiness includes four factors worth 85 points total: Technical Foundation (25 points), Integration & Orchestration (20 points), Monitoring & Telemetry (20 points), and Security & Compliance (20 points). Technical Foundation carries the most weight, reflecting its role as the repository architecture and retrieval-augmented generation implementation that the other three factors depend on.
What is the difference between Technical Foundation and Integration & Orchestration?
Technical Foundation measures the retrieval architecture itself: how content is indexed, embedded, and structured for retrieval-augmented generation. Integration & Orchestration measures something separate: how well that AI capability connects to the rest of the enterprise, including workflow automation and data flow with other systems. An organization can build a strong technical foundation and still fail to integrate it into daily operations.
What is the difference between Monitoring & Telemetry and Drift Monitoring?
Monitoring & Telemetry, a Technical Readiness factor, covers the dashboards, diagnostics, and observability infrastructure that make AI system performance visible at all. Drift Monitoring, a separate factor under Operational Readiness, is the process built on top of that visibility: identifying, categorizing, and resolving specific errors as AI performance changes over time. One provides the instrumentation; the other is the response process that uses it.
What does "naive RAG" mean in Technical Foundation's Level 1 description?
In this assessment, naive RAG describes retrieval-augmented generation implemented without engineering or structure, where knowledge sits in unindexed repositories with no vectorization strategy. The Level 1 description states that this produces irrelevant content being retrieved frequently, which is the practical symptom of naive RAG: the AI system pulls back content that does not actually answer the query it was given.
What separates a Level 3, Developing, from a Level 4, Established, Security & Compliance organization?
At Level 3, Developing, basic risk controls are applied inconsistently, some audit capability exists, but real gaps remain and compliance requirements are only partially addressed. At Level 4, Established, security and provenance controls are enforced through governance, AI-specific policies are implemented, access controls apply directly to AI retrieval, and audit trails actually exist rather than being only partially in place.
Domain 4: Governance Readiness
Governance Readiness measures whether ownership, cross-functional alignment, and executive investment are in place to sustain AI readiness after the initial build.
4.1 Governance Structure
Ownership, accountability, and governance processes. Worth 25 of the 95 points in Governance Readiness.
Level 1: Not in place
No ownership exists for knowledge, terminology, or AI quality. No governance processes. Decisions are made ad hoc.
Level 2: Minimal
Emerging ownership with gaps and overlaps. Some informal governance exists in pockets. Responsibilities are unclear.
Level 3: Developing
Roles are defined but inconsistently applied. Governance committee may exist but lacks authority. Some policies exist but enforcement is weak.
Level 4: Established
Governance model clearly assigns ownership for knowledge, terminology, and AI quality. Documented roles. Policies enforced through workflow.
Level 5: Optimized
Cross-functional, accountable ownership is embedded in operations. Governance integrated with lifecycle management. Decisions are data-driven.
4.2 Cross-Functional Alignment
Collaboration across IT, business units, legal, and content owners. Worth 20 of the 95 points in Governance Readiness.
Level 1: Not in place
AI efforts are siloed with no coordinated collaboration. Each department pursues independent initiatives. Competing priorities create conflict.
Level 2: Minimal
Early collaboration exists but is inconsistent. Some departments are engaged; others are resistant. Coordination is through informal relationships.
Level 3: Developing
Coordination exists but priorities diverge. Cross-functional team may exist but lacks authority. Some alignment on terminology and standards.
Level 4: Established
Alignment exists across SMEs, engineering, operations, legal, and business units. Regular collaboration through defined processes.
Level 5: Optimized
Organization operates as a unified AI ecosystem. Cross-functional collaboration is routine. Shared ownership of outcomes.
4.3 Culture & Adoption
User trust, training, and organizational readiness. Worth 25 of the 95 points in Governance Readiness.
Level 1: Not in place
Teams distrust AI with minimal adoption. Resistance to AI initiatives. No training or change management. AI is seen as a threat.
Level 2: Minimal
Interest in AI exists but resistance remains. Some early adopters but majority skeptical. Limited training available. Trust is low.
Level 3: Developing
Training improves adoption in some areas. Pockets of successful use. Understanding of AI capabilities is growing. Adoption is uneven.
Level 4: Established
AI is trusted and used in governed workflows. Majority of target users trained and engaged. Resistance addressed proactively.
Level 5: Optimized
AI is embraced as a trusted decision partner. High adoption rates. Continuous learning culture. Users advocate for AI capabilities.
4.4 Strategy & Investment
Leadership commitment, funding, and long-term planning. Worth 25 of the 95 points in Governance Readiness.
Level 1: Not in place
AI is funded inconsistently and reactively. No strategic commitment. No roadmap. AI is viewed as experimental or optional.
Level 2: Minimal
Funding supports pilots only. Some executive awareness but not active sponsorship. Budget is uncertain. No long-term planning.
Level 3: Developing
AI roadmap exists but lacks enterprise commitment. Budget is allocated but may be at risk. Executive sponsor engagement is limited.
Level 4: Established
Leadership actively supports enterprise-scale AI investment. Multi-year roadmap with milestones. Success metrics are defined and tracked.
Level 5: Optimized
AI is treated as a strategic capability with sustained investment. Executive sponsorship is visible and active. AI strategy integrated with business strategy.
Frequently Asked Questions
How many factors make up Governance Readiness, and how many points is each worth?
Governance Readiness includes four factors worth 95 points total: Governance Structure (25 points), Cross-Functional Alignment (20 points), Culture & Adoption (25 points), and Strategy & Investment (25 points). Three of the four factors are weighted equally at 25 points, with only Cross-Functional Alignment weighted slightly lower at 20.
What is the difference between Governance Structure and Cross-Functional Alignment?
Governance Structure measures whether ownership, accountability, and decision-making processes for AI and content exist at all. Cross-Functional Alignment measures a related but separate capability: whether IT, business units, legal, and content owners actually collaborate once that structure is in place. An organization can define clear ownership on paper while its departments still work in silos, scoring well on one factor and poorly on the other.
What is the difference between Culture & Adoption and Cross-Functional Alignment?
Cross-Functional Alignment measures collaboration between departments and teams, a structural, group-level capability. Culture & Adoption measures something more individual: whether the people actually using AI trust it, have been trained on it, and are willing to rely on its outputs. Departments can be well aligned on paper while individual users still distrust or avoid the AI tools that alignment was meant to support.
What separates a Level 2, Minimal, from a Level 4, Established, Culture & Adoption organization?
At Level 2, Minimal, interest in AI exists but resistance remains, only a few early adopters have engaged, training is limited, and trust is low across the organization. At Level 4, Established, AI is trusted and used inside governed workflows, the majority of target users are trained and engaged, and resistance is addressed proactively rather than left to resolve itself.
What does Strategy & Investment measure that Governance Structure does not?
Governance Structure measures ownership, accountability, and process for AI and content. Strategy & Investment measures a different capability entirely: leadership commitment, funding, and long-term planning for AI at the enterprise level. An organization can have clearly assigned ownership under Governance Structure while AI investment remains reactive, pilot-only, and without executive sponsorship under Strategy & Investment.
Does having a governance committee automatically mean an organization scores well on Governance Structure?
No. The assessment's Level 3, Developing, description for Governance Structure explicitly notes that a governance committee may exist but still lack real authority, with policies that exist on paper but weak enforcement. Reaching Level 4, Established, or Level 5, Optimized, requires that governance model to carry documented roles and enforced policies, not just a committee that exists in name.
From Factor Scores to a Composite Readiness Level
Score every factor, sum the seventeen scores, and divide by 370, the total of all four domain maximums: Knowledge Readiness (90 points across four factors), Operational Readiness (100 points across five factors), Technical Readiness (85 points across four factors), and Governance Readiness (95 points across four factors). The resulting percentage maps to one of five Readiness Levels.
- Not Ready, below 40 percent: Significant foundational gaps. Start with basics.
- Early Stage, 40 to 60 percent: Some foundation exists, but major gaps remain.
- Developing, 60 to 80 percent: Good progress, but coverage is inconsistent across domains.
- Ready to Scale, 80 to 90 percent: A strong foundation with minor gaps.
- Optimized, 90 to 100 percent: Mature practices. The work shifts to continuous improvement.
This is the same scale Framework 4 reports on the Earley AI Frameworks page. The two pages describe one instrument at two levels of detail: this page for the factor-by-factor diagnostic, Framework 4 for the single number a CDO or CIO tracks over time.
Related Concepts
The Earley AI Frameworks (see Framework 4: The AI Readiness Maturity Model) · IAD-RAG · The GEO Pillar Model · Knowledge Engineering · Content Governance · Drift Monitoring
