Reading Time: 11 minutes

PwC surveyed 4,454 chief executives across 95 countries and territories between 30 September and 10 November 2025. Only 12 per cent said AI had delivered both cost and revenue benefits over the previous year. A further 33 per cent reported gains in one or the other, and the remaining 56 per cent reported no significant financial benefit at all. The same research found that chief executives whose organisations had established strong AI foundations were three times more likely to report meaningful financial returns. Foundations, unlike outcomes, can be measured before the money is committed.

Quick Answer: An AI maturity assessment is a structured review that rates how capably an organisation uses AI, scored across dimensions such as strategy, data, governance, people and technology, and mapped to a set of maturity stages. It differs from a scorecard, which is the output that gets tracked over time, and from a readiness check, which asks whether an organisation should start at all. A credible assessment rests on observable evidence rather than opinion.

What an AI maturity assessment actually is

An AI maturity assessment is an exercise rather than a document. It gathers evidence about how an organisation currently builds and uses AI, rates that evidence against a defined scale, and produces two things: a position, and a list of the gaps between where the organisation sits today and where it intends to be.

Three terms tend to get used interchangeably. Separating them makes the whole process easier to run.

Assessment, model and scorecard

These are three different objects that are designed to work together.

  • The scale. The maturity model sets out the stages an organisation can occupy and describes what each one looks like in practice.
  • The measurement. The assessment is the act of rating an organisation against that scale. It is a piece of work with a scope, participants, evidence and a date.
  • The artefact. The AI scorecard carries the score, the trend and any benchmark, and it is what leadership looks at between assessments.

A model with no assessment behind it is only a diagram.

How maturity differs from readiness

The two questions point in opposite directions in time.

  • An AI readiness assessment looks forward and asks whether an organisation is in a position to begin.
  • Maturity looks at the present and asks how far it has already travelled.

An organisation can be mature in one function while another is not yet ready to start.

Why self-assessment alone falls short

Self-assessment is a sensible place to begin. It is quick, costs nothing, and can be repeated at will. The difficulty is that self-perception and measured performance diverge in a consistent direction.

IDC’s 2026 MaturityScape Benchmark scored 1,900 organisations across 20 markets on four dimensions: strategy, governance, people and technology. Respondents were also asked to characterise their own approach to AI. Of those who identified themselves as thrivers, only around one in six reached the managed or optimised stages once scored against IDC’s methodology.

The wider distribution supplies context. IDC placed 3.1 per cent of organisations at the optimised stage and found 61.3 per cent still in the two least mature stages.

Where the gap tends to sit

The divergence is not spread evenly. IDC found it concentrated in the areas that are hardest to demonstrate at scale:

  • Governance that has been formalised into enforceable controls rather than stated as intent.
  • Data and platform foundations capable of supporting production rather than pilots.
  • A workforce that has actually been brought along.

The NIST AI Risk Management Framework addresses the same problem structurally. Under its measure function, NIST suggests involving internal experts who did not serve as front-line developers, or independent assessors, in regular assessments, on the basis that this reduces internal bias and potential conflicts of interest.

What gets scored, and how

Almost every published AI maturity framework is built the same way. A set of dimensions runs down one axis, a set of levels runs across the other, and the assessment places the organisation somewhere on that grid for each dimension in turn.

The variation sits in the detail rather than the shape. Dimension counts range from four to seven across widely used frameworks, while level counts cluster tightly on five. The idea is older than the technology: CMMI, which began at Carnegie Mellon’s Software Engineering Institute in the 1980s, has rated organisations across maturity levels for decades.

Check the coverage as well as the count. Frameworks written before agentic AI reached production may score generative tools thoroughly and barely register AI agents that act on their own.

Dimensions and levels in practice

Two published tools show how differently the same structure can be applied.

  • MITRE’s assessment tool asks one multiple-choice question per dimension, across 20 dimensions grouped into six pillars. The answer selected sets the maturity level recorded for that dimension, and the tool generates a score and a visualisation once every question is answered.
  • The UK Department for Science, Innovation and Technology’s AI Management Essentials tool asks what proportion of AI systems are documented, whether an AI policy is accessible to all employees, and how frequently each process is reviewed. Its answer options are graduated rather than binary.

The second approach scores things that can be evidenced. A team can dispute whether its governance is mature. It cannot easily dispute whether its record of AI systems was updated in the last twelve months.

FrameworkStructureAccessPublished by
MITRE AI Maturity ModelSix pillars, 20 dimensions, five levelsFree download, tool on requestMITRE
OWASP AIMAFive domains, from strategy to governanceFree document and toolkitOWASP Foundation
AI Management EssentialsTen sections across process, risk and communicationFree self-assessmentDSIT, United Kingdom
NIST AI RMFFour functions: govern, map, measure, manageFree, voluntary, not certifiableNIST
ISO/IEC 42001Requirements for an AI management systemCertification via independent bodiesISO and IEC
Gartner AI Maturity AssessmentSeven pillars, five stagesClient accessGartner
CMMISix maturity levels across defined practice areasAppraisal via licensed partnersISACA
GrowthNationInterview-led evidence gathering with a score tracked over timeProductGrowthNation

How to run an AI maturity assessment

The sequence below applies whether the assessment is run internally, guided, or carried out by a third party. The steps most often skipped are the first and the last.

Before you start

Two decisions taken early determine how usable the result will be.

  • 1. Fix the scope. A maturity model can be applied across an entire enterprise or to a single function such as finance or marketing. A function already running AI agents in business needs different questions from one that has not begun.
  • 2. Choose the framework first. Selecting the framework before gathering anything ensures the evidence collected matches the questions that will be asked of it. Several capable frameworks are free to download, so cost is rarely the constraint.

Gathering the evidence

This is the stage where most of the difference between a defensible score and a flattering one is decided.

  • 3. Decide who answers. A view drawn only from executive sponsors produces the perception gap described above. Coverage across seniority and across functions is what makes a result hold up when it is challenged. GrowthNation approaches this by interviewing every team directly rather than surveying leadership alone.
  • 4. Collect artefacts, not opinions. Ask for the record of AI systems in use, the written AI policy, completed impact and risk assessments, and monitoring records. That record should separate generative and agentic AI, because the two carry different oversight requirements.

Turning answers into a position

The final two steps convert a set of answers into something the organisation can act on.

  • 5. Score each dimension separately. Report the gap between current and target for every dimension rather than collapsing everything into one composite number. A single figure hides exactly the weakness the exercise exists to find.
  • 6. Set the re-run date now. Fix the next assessment date at the moment the first result is published. A maturity score with no second reading is a position, not a direction of travel.

Five tests of a trustworthy maturity score

A score is only as useful as the process that produced it, and scores arrive from internal exercises, free frameworks, consultancies and vendor questionnaires alike. These five questions apply to any of them.

  • The evidence test. Could someone outside the team verify each rating from a document, a log or a system, rather than from a conversation?
  • The coverage test. Did the answers come from the people who do the work, or only from the people who sponsor it?
  • The comparability test. Was the same instrument applied in the same way across every team, so that the scores can be read side by side?
  • The ceiling test. Does the weakest dimension carry proper weight, or does a healthy average conceal a foundation that cannot support production?
  • The repeat test. Is there a date in the diary to run it again, and would the method produce a similar answer if somebody else ran it?

A score that fails the evidence and coverage tests is measuring confidence rather than capability, which is worth knowing before it reaches a board pack.

Choosing a target level

Maturity models are often read as a ladder to the top, which is not how their authors describe them. MITRE states that not every organisation will need or want to reach the highest level in every pillar, and that the appropriate target is a function of mission, resources and business practices.

The practical consequence is that the useful output of an assessment is the gap between current and target, not the headline number. A deliberate decision to stay at a middle level in one dimension is a legitimate result. An accidental one is not.

How the assessment is run also shapes what the result can be used for.

 Self-assessmentGuided assessmentIndependent assessment
Who scores itThe team scores itselfA facilitator runs the process, the organisation answersA third party gathers evidence and scores it
Typical basisStated practiceStated practice tested in discussionDocumented evidence and artefacts
Main strengthFast, free, repeatable at willSurfaces disagreement between functionsLeast exposed to internal bias
Main limitationExposed to the perception gapDepends on who is in the roomCost and elapsed time
Suited toEstablishing a first baselineAligning leadership and delivery teamsProcurement, assurance and board reporting

Where AI maturity assessments go wrong

Most failed assessments fail in one of five recognisable ways.

  • Treating the score as the deliverable. The gap list is the part that changes anything.
  • Surveying leadership only, which reproduces the perception gap in miniature.
  • Changing the instrument between rounds, which destroys the comparison the second round exists to provide.
  • Averaging away a weak foundation. IDC found technology to be the least mature dimension overall, held back by persistent gaps in data quality and integration.
  • Running it once. Without a second reading there is no trend, and without a trend there is nothing to defend at renewal.

If you want evidence gathered from every team rather than assembled from leadership opinion, GrowthNation interviews each team directly, turns the repeatable work into agents the organisation owns, and tracks the result as a maturity score over time. See how the process works.

Frequently asked questions

What is an AI maturity assessment?

It is a structured review that rates how capably an organisation uses AI across a set of dimensions, then places it on a defined scale of maturity stages. The output is a current position and a list of gaps against a target.

How is it different from an AI readiness assessment?

An AI readiness assessment asks whether an organisation is in a position to begin using AI. A maturity assessment asks how far it has already progressed and how well established its practices are. Readiness looks forward, maturity measures the present.

How long does an AI maturity assessment take?

Published frameworks do not set a fixed duration, because scope drives it. Assessing a single function against a free framework is a much shorter exercise than an enterprise-wide assessment involving evidence collection across every team.

Are there free AI maturity assessment frameworks?

Yes. The MITRE AI Maturity Model, the OWASP AI Maturity Assessment and the UK government’s AI Management Essentials tool are all available at no cost. The NIST AI Risk Management Framework is also free, although it addresses risk rather than maturity directly.

How often should an organisation reassess?

Frequently enough to produce a trend rather than a series of unrelated snapshots. Review frequency is itself a scored dimension in AI Management Essentials, where reviewing a process at least twice a year scores higher than reviewing it annually.