Skip to main content

AI governance

AI Governance Maturity Assessment: A Board Self-Assessment

A complete board-level AI governance maturity self-assessment, published in full: five maturity levels, eight domains, the questions directors should be able to answer, how to score the result and what to fix in the next quarter.

The BoardServe team16 min read
A boardroom table with a printed AI risk assessment marked up in pencil, a laptop showing a maturity scoring grid and a director's reading glasses beside a cup of coffee

Most boards can tell you artificial intelligence is on the risk register. Far fewer can say, without sending management away to check, how many AI systems the organisation uses, which touch a decision about a person, and who signed them off. An AI governance maturity assessment closes that gap, turning a vague sense of exposure into a scored position the board can act on.

This page publishes the assessment in full: five maturity levels, eight domains, the questions a board should be able to answer in each, and what a weak and a strong answer look like. Copy it into a board paper, run it with your executive, and take the result to the audit or risk committee.

What is an AI governance maturity assessment?

A board-level AI maturity assessment scores how well an organisation directs, controls and evidences its use of artificial intelligence, domain by domain, against defined levels. It is completed by management and challenged by the board, and its output is a scored position and a gap list rather than a pass or a fail.

A compliance checklist asks whether a control exists. A maturity model asks whether it is defined, operating, measured and improving, which is what a board needs before telling an auditor or an investor that oversight is real. It is the logic boards already apply to internal control and to a board skills matrix audit: capability sits on a scale, not a binary.

Two instruments give the scale its content. ISO/IEC 42001:2023, the first certifiable management-system standard for artificial intelligence, published in December 2023, supplies the structure: context, leadership, planning, support, operation, performance evaluation and improvement, with controls in Annex A grouped under nine objectives. The EU AI Act supplies the obligations and the dates. Our companion piece on AI governance and board oversight under ISO 42001 and the EU AI Act sets out how the two fit together; this page is the diagnostic underneath it.

Who this is for

Company secretaries preparing an AI item for a board or audit committee, AI governance leads who need a defensible baseline, and chairs of UK organisations using AI in a material process. It applies whether or not you intend to certify to ISO/IEC 42001, and whether or not the EU AI Act reaches you. Nothing here requires technical knowledge of models.

What the board needs to decide

  • Whether there is a single, current inventory of AI uses, and who owns it.
  • Which executive is accountable for AI risk, and which committee holds them to account.
  • Whether any AI use is in scope of the EU AI Act, and when each obligation bites.
  • Whether AI affecting individuals has documented human oversight and a route to challenge.
  • What assurance the board will accept: management assertion, internal audit, or certification.
  • Which two gaps get fixed this quarter, with a named owner and a date.

The five maturity levels

The levels below are deliberately plain. A board arguing about whether it sits at 2 or 3 is having a useful argument.

Level Name What it looks like in practice
1 Unaware No inventory, no named owner. AI arrives through individual tools and departmental purchases. Not discussed by the board in 12 months.
2 Reactive AI is acknowledged, usually after an incident or a customer question. Ownership is informal and evidence is anecdotal.
3 Defined Policy, inventory, a named executive owner and a periodic committee report all exist. Controls are written down but not consistently tested.
4 Managed Controls operate and are evidenced. Impact assessments precede deployment, third-party AI is assessed at procurement, and metrics reach the board on a set cadence.
5 Assured Independent assurance confirms the controls operate, findings are tracked to closure, and the board can evidence its own oversight in the minutes.

Level 3 is the floor where AI touches a decision about a person, a payment or a public statement. Level 5 is not a target for everyone: for a small charity with two AI tools, Level 4 with proportionate documentation is a sound place to rest.

The eight domains

Each domain carries the questions a board should be able to answer, with a Level 1 and a Level 5 answer. Score each question and take the lowest as the domain score. Averaging within a domain flatters: an inventory that is complete but unowned is not a functioning control.

1. Accountability and board oversight

Question the board should answer Level 1 Level 5
Who is the named executive accountable for AI risk? Nobody, or "IT" A named individual with a written remit, distinct from those building or buying the systems
Which committee holds AI oversight, and how often does it report? No committee holds it Audit or risk committee, on a stated cadence, findings and actions minuted
Can the board evidence its own oversight? AI is absent from the minutes Minutes record the questions asked, the answers given and the decisions taken

2. AI inventory and risk classification

Question the board should answer Level 1 Level 5
How many AI systems are in use, including features embedded in bought software? Unknown A current register with owner, purpose, data used and date of last review
Which uses affect a decision about an individual? Not identified Each use classified by impact, with higher-impact uses named to the board
How does a new AI use get onto the register? It does not A gate in procurement and change management, with a named approver

Staff adopt assistants inside tools the organisation already licences, so the honest first question is not "what did we buy" but "what did we switch on".

3. Policy and controls aligned to ISO/IEC 42001

Question the board should answer Level 1 Level 5
Is there an approved AI policy, and when was it last reviewed? No policy Board-approved, reviewed annually, with scope and exclusions stated
Are risk and impact assessments completed before deployment? Never Completed, documented and revisited when the system or its use changes
Which ISO/IEC 42001 controls apply, and which are excluded? Not considered A Statement of Applicability recording each inclusion and exclusion with a reason

ISO/IEC 42001 is useful to a board because it converts a fast-moving topic into recognisable hooks: policy, risk assessment, internal audit, management review. Certification is optional; the structure is worth adopting regardless. The Statement of Applicability is the most useful artefact, because it forces management to say out loud what it has decided not to do.

4. Regulatory obligations mapping

Question the board should answer Level 1 Level 5
Is any AI use in scope of the EU AI Act? Not assessed Each use mapped to prohibited, high-risk, transparency-only or minimal, with reasoning recorded
What is the date each applicable obligation bites? Unknown A dated compliance plan per system, refreshed against published amendments
How do UK duties apply, whatever the EU position? Assumed not to apply UK GDPR, sector regulator expectations and the UK principles mapped alongside

The dates moved this year, so state them precisely. Prohibited practices and the AI literacy duty have applied since 2 February 2025, and obligations for general-purpose AI models since 2 August 2025. The Article 50 transparency duties, including telling people they are interacting with an AI system, applied from 2 August 2026. On 29 June 2026 the Council gave final approval to the AI omnibus regulation, which entered into force on 27 July 2026 and moved the high-risk regime for standalone Annex III systems to 2 December 2027, and for high-risk AI embedded in regulated products under Annex I to 2 August 2028. The Commission's regulatory framework page carries those dates. All dates checked on 3 September 2026.

The Act reaches UK organisations placing a system on the EU market, or whose system outputs are used in the EU. The deferral is time, not relief: the duties on risk management, data governance, logging, human oversight and conformity assessment are unchanged.

The UK's position is different in kind. The government's white paper A pro-innovation approach to AI regulation, presented to Parliament on 29 March 2023, set out five cross-sectoral principles issued on a non-statutory basis and applied by existing regulators: safety, security and resilience; appropriate transparency and explainability; fairness; accountability and governance; and contestability and redress. There is no single UK AI statute, so a UK board cannot point at a certificate and stop. The Department for Science, Innovation and Technology's AI Management Essentials tool is the closest thing to an official baseline: a self-assessment covering internal processes, managing risks and communication. It is lighter than ISO/IEC 42001 and a reasonable target for a smaller organisation that will never certify.

5. Data, model and lifecycle governance

Question the board should answer Level 1 Level 5
Where does the training or prompt data come from, and is its use lawful? Not established Sources documented, lawful basis recorded, data protection assessments completed where required
How is the system tested for accuracy and unfair outcomes? Not tested Pre-deployment testing plus periodic re-testing, with thresholds and results reported
Who can override or switch off an automated decision? Nobody has tried Named human oversight, exercised in practice, with the override rate reported

The Information Commissioner's Office has been consistent that existing data protection law already applies to AI, including duties on fairness, transparency and explainability. No board need wait for AI-specific legislation to ask these questions.

6. Third-party and procured AI

Question the board should answer Level 1 Level 5
Do supplier contracts address AI use, data handling and model change? Standard terms only Clauses covering training-data use, notice of material model change, audit rights and exit
What assurance do suppliers provide? None requested Certifications, test results or attestations reviewed and refreshed on renewal
Is a supplier's AI feature assessed before it is switched on? Switched on by default Approved through the same gate as an in-house deployment

7. Assurance, monitoring and incident response

Question the board should answer Level 1 Level 5
What monitoring runs after deployment? None Performance, drift and complaint indicators tracked, with thresholds that trigger a review
What happens when an AI system produces a harmful or wrong output? Handled informally A defined incident route: logged, investigated, reported to the committee, closed
Who provides independent assurance? Nobody Internal audit or an external reviewer, with findings tracked to closure

Level 5 here is not about volume of reporting. It is whether an incident last quarter would have reached the board, and whether anyone could reconstruct what the system did and why.

8. Skills and culture

Question the board should answer Level 1 Level 5
Do directors understand enough to challenge management on AI? No induction or briefing AI capability assessed in the skills matrix, with briefings and, where needed, external advice
Do staff know what they may and may not use? No guidance issued Role-appropriate training, recorded, with a route to ask
Can staff raise a concern about an AI output without career risk? No route An open route, used, with concerns reported in aggregate to the committee

The EU AI Act's AI literacy duty has applied since 2 February 2025, but the board-level case is simpler: a board that cannot ask a second question after management's first answer is not exercising oversight.

How to score the assessment

Score every question 1 to 5 against the level descriptions and take the lowest as the domain score. Record all eight scores with the evidence relied on for each, because an unevidenced 4 is a 2. Do not average them for the board pack: a mean of 3.4 conceals the domain at Level 1 doing all the damage.

Present the result as three lines: the lowest two domains, the evidence gaps, and the actions proposed for the coming quarter. Have the committee test three answers at random against the underlying documents. That test is what makes it governance rather than a survey.

Run it annually as a minimum, and again whenever AI is deployed in a materially new way. Where AI generates or influences a material control, the result feeds the internal-control declaration in Provision 29 of the UK Corporate Governance Code 2024, which applies for financial years beginning on or after 1 January 2026. Our company secretary's guide to the 2024 Code sets out that reporting picture.

What a typical first result looks like

A mid-sized UK housing association, roughly 400 staff, ran the assessment ahead of its audit and risk committee. Management expected a Level 3. The result, anonymised and lightly simplified, was this:

Domain Score The finding behind it
Accountability and board oversight 2 AI risk sat informally with the director of IT. No committee held it, and AI appeared once in 14 months of minutes.
AI inventory and risk classification 2 Eleven AI uses were known. Nine more surfaced, all features switched on inside existing software, including a repairs-triage assistant.
Policy and controls 3 An acceptable-use policy existed and was current, but no impact assessments had been completed.
Regulatory obligations mapping 2 No EU AI Act scoping had been done. The conclusion, correctly, was out of scope, but nobody had recorded the reasoning.
Data, model and lifecycle governance 2 The repairs-triage assistant influenced how quickly a repair was seen. No fairness testing, no override log.
Third-party and procured AI 1 No supplier contract mentioned AI. Two suppliers had added AI features without notice.
Assurance, monitoring and incident response 1 No monitoring, no incident route, no independent review.
Skills and culture 2 No director briefing. Staff had asked what they were allowed to use and received no answer.

The uncomfortable finding was not the scores. It was the repairs-triage assistant: a bought feature, switched on by a well-meaning operations team, ordering the queue in which residents were seen. Nobody had assessed it, nobody was monitoring it, and no resident could have challenged it. That single line changed the committee's view of the exercise, which is what a first assessment is for.

For a faster starting point before running all eight domains, the Governance Quick Check gives a short diagnostic across the wider governance picture, including AI oversight, with a written result you can take to a committee.

What to do in the next quarter

A short list, not a twelve-point plan that gets reported on twice and then quietly stops.

  1. Name the owner and the committee. One executive accountable for AI risk, one committee receiving a report on a stated cadence, both minuted. This is a decision, not a project, and it can be taken at the next meeting.
  2. Complete the inventory, including switched-on features. Ask every function what AI is running inside the software they already use. Set a six-week deadline and expect the number to double.
  3. Classify what touches a person. From the inventory, identify every use affecting a decision about an individual and require an impact assessment for each before the following meeting.
  4. Fix the procurement gate. No new AI use, bought or built, goes live without passing the same assessment. That stops the inventory going stale the week after you complete it.

Certification, testing and independent assurance are Level 4 and 5 conversations: right in a year, wrong before anybody owns the register.

This page is maintained as guidance changes, and is checked at the annual update against the EU AI Act timetable, ISO/IEC 42001 and UK regulator expectations.

Common mistakes

  • Scoring the policy rather than the practice. A policy nobody applies is Level 2 evidence presented as Level 3. Ask when a control was last exercised, not when it was written.
  • Treating the EU AI Act deferral as a reason to wait. The high-risk dates moved to 2 December 2027 and 2 August 2028. The obligations did not, and classification takes longer than the time saved.
  • Leaving bought AI out of scope. Features switched on inside existing software are where most organisations find their highest-impact uses.
  • Averaging the domains. A single number is comfortable and useless. Report the lowest two.
  • Running it once. A one-off assessment ages within two quarters, because the inventory changes faster than the policy.

FAQ

How long does a board AI maturity assessment take?

Management can usually complete a first pass in two to three weeks, most of it spent building the inventory rather than answering questions. Committee challenge adds one meeting. Organisations with many bought AI features should expect the inventory step to run long.

Do we need ISO/IEC 42001 certification?

No. Certification is optional, and for many UK organisations the cost is not justified. The standard's structure of policy, risk assessment, lifecycle control, internal audit and management review is useful either way. Smaller organisations may find the DSIT AI Management Essentials tool better proportioned.

Does the EU AI Act apply to a UK-only organisation?

Often not, but record the answer rather than assume it. The Act reaches organisations that place an AI system on the EU market, or whose system outputs are used in the EU, whatever their base. A short documented scoping conclusion protects the board better than an untested assumption.

Who should complete the assessment, management or the board?

Management completes it and the board or committee challenges it. A board that scores itself produces flattering results; one that receives only a summary cannot test anything. The value sits in the challenge, so pick three answers at random and ask for the evidence.

What score should we be aiming for?

Level 3 is the floor where AI touches a decision about a person, a payment or a public statement. Level 4 suits most mid-sized organisations. Level 5, with independent assurance, suits regulated firms and any organisation whose AI use is material to its financial reporting or its licence to operate.

Bring this into your boardroom.

See how BoardServe turns governance practice into evidence.

Book a demo