AI governance maturity is not about how many policy documents the organisation has produced. It is about whether the controls that exist actually reflect how AI is being used, whether they are followed in practice, and whether they would hold up under scrutiny from a board, a regulator, or a customer asking difficult questions.
Most organisations, if they are honest, are somewhere between “we wrote a policy last year” and “we have a governance programme that functions operationally”. The gap between those two positions is substantial. It tends to become visible at moments that are difficult to manage – during an incident, under regulatory scrutiny, or when a significant client starts asking questions that nobody prepared for.
Understanding your real AI governance maturity is a more useful exercise than most organisations realise. Not because governance needs to be perfect, but because the honest picture tells you what needs to change and in what order.
The questions that reveal your real AI governance maturity
There is a small number of questions that tend to surface the operational picture quickly. Not the theoretical governance position, but the reality of what is working and what is not.
Can you list every AI tool currently in use across the organisation? Not the approved list. The actual list, including tools that teams have adopted without formal approval.
Do you know what data is reaching those systems? Specifically – which categories of data, from which teams, through which workflows, under what supplier terms.
Have you read the data handling terms of your key AI suppliers? Not a summary, not a sales deck assurance – the actual terms, including what they say about retention, training data usage, and jurisdictional processing.
Is there a clear, functioning process for staff to get a new AI tool assessed and approved, and is it fast enough that people actually use it rather than working around it?
If a customer or regulator asked you tomorrow to demonstrate your AI governance with evidence, could you do it? Not describe it – demonstrate it.
If the honest answers to most of those are “no” or “not really”, that is useful information. It tells you where your AI governance maturity work needs to start. Our AI Governance Maturity Scorecard walks through this in around three minutes and gives you a structured starting picture.
What the AI governance maturity levels look like in practice
It helps to think about AI governance maturity as a progression through distinct levels, each of which has recognisable characteristics.
At the lowest level, governance is essentially absent. There may be a general expectation that staff will exercise common sense, but no formal structure, no visibility of what tools are in use, and no accountability for AI-related decisions. This is more common than many organisations would publicly acknowledge, particularly in faster-moving commercial environments where the pressure to adopt AI has outpaced the pressure to govern it.
The documentation level is where most organisations currently sit. A policy exists. There may be an approved tool list. Some awareness communication has gone out. But the documentation was produced without a full picture of actual usage, nobody is actively monitoring compliance, and the policy has not been tested against the reality of how people work. It satisfies a basic audit question. It does not constitute genuine governance.
A managed governance programme goes meaningfully further. There is real visibility of AI usage across the organisation. Tools go through an assessment process before approval. Supplier relationships are reviewed. Someone owns AI governance and is accountable for it. There is a functioning process for handling new tool requests, and it is used in practice rather than being bypassed as a matter of habit.
Defensible governance – which is the realistic and appropriate aspiration for most organisations rather than some theoretical ideal of perfection – is where governance is operationally embedded and demonstrable with evidence. Controls are proportionate, documented, and followed. The organisation can respond to a board, customer, or regulatory query without significant advance preparation. When something goes wrong, the governance structures help contain it rather than making the situation worse.
Why most AI governance maturity self-assessments overstate reality
Self-assessed maturity is almost always higher than independently assessed maturity. This is not unique to AI governance – it is a consistent pattern across security, compliance, and risk management. The people assessing their own governance are the same people who designed and implemented it, who have invested professional credibility in it, and who are not naturally inclined to identify its weaknesses.
The most common form of overstatement is mistaking documentation for governance. The policy exists, so governance exists. The process is documented, so it is followed. The risk register was created, so risks are being managed. None of these things are necessarily true.
A reliable assessment of AI governance maturity needs to test whether controls are functioning operationally, not just whether they exist on paper. That means looking at whether staff know about the policies and processes that govern their behaviour, whether approval processes are followed in practice, whether the people nominally responsible for governance are actually exercising that responsibility, and whether the documented controls would produce the right outcomes under realistic conditions. Working through our AI Governance Gap Assessment alongside the scorecard gives a more complete picture than either alone.
Where most organisations need to start
The majority of organisations engaging seriously with AI governance right now are at the documentation level and want to reach managed or defensible. The path there is generally more achievable than it feels from the inside – but it requires building on an honest assessment of current reality rather than a theoretical baseline.
The organisations that try to skip the visibility and assessment stage – jumping straight to framework implementation or policy redesign without first understanding what they are actually governing – typically produce governance that looks complete and fails under operational scrutiny. That visibility stage is what an AI exposure review is built to provide, and it is the same starting point that underpins most shadow AI risk reduction work.
Starting honestly is not a weakness. It is the only foundation that produces governance which actually works.
Black Chili’s AI Exposure Review gives you an independent, structured baseline – what is actually in use, what the real exposure is, and a prioritised picture of what governance work is most urgent.
If you are not sure what AI tools are in use inside your organisation, an AI Exposure Review gives you a clear, independent picture - what is being used, what data it touches, and where the real risks are.