Module · Built · ISO 42001 Lead Auditor

AI governance. Built by a lead auditor.

AI governance maturity across 10 specialist domains, practitioner-authored. Aligned to ISO/IEC 42001:2023 (AI Management Systems), the EU AI Act (Regulation 2024/1689), Vietnam's Law on Artificial Intelligence (Law No. 134/2025/QH15) and Malaysia's National Guidelines on AI Governance and Ethics (2024) - score once, produce conformity evidence against multiple frameworks. Built by an ISO/IEC 42001 Lead Auditor.

AI Governance
AI governance
Built
AI
AI Governance
10
Specialist domains
ISO 42001
EU AI Act
Vietnam · Malaysia
Standards aligned
4
Add-ons live
0–4
Maturity scale
🇦🇺🇳🇿🇭🇰🇻🇳🇲🇾🇹🇼🇦🇪🇸🇦🇶🇦🇵🇰
01What it covers

Ten domains. One unified score.

Each domain is practitioner-authored, mapped to ISO 42001 and the EU AI Act, and weighted into the cross-domain cascade. Together they cover the full AI governance lifecycle - from board-level strategy through engineering and MLOps to independent audit.

01.1
Strategy & Business Alignment
AI strategy, board oversight, executive sponsorship, ROI metrics, long-term budget.
01.2
Governance & Accountability
AI governance charter, RACI, decision rights, escalation paths, committee cadence.
01.3
Policy & Procedures
AI use policy, prohibited and high-risk uses, AUP, third-party AI controls.
01.4
Risk Management & Impact
AI risk taxonomy, impact assessment, fairness/bias risk, model risk register.
01.5
Data Governance & Quality
Training data lineage, classification, quality controls, provenance, consent.
01.6
Engineering, MLOps & XAI
Model lifecycle, explainability, versioning, deployment controls, monitoring.
01.7
Security & Adversarial Defence
Model theft, prompt injection, adversarial examples, supply-chain attacks.
01.8
Regulatory & Legal Compliance
EU AI Act tier classification, ISO 42001 conformity, jurisdictional obligations.
01.9
Human Factors & Literacy
Workforce AI literacy, human oversight, escalation, training, change management.
01.10
Monitoring & Independent Audit
Continuous model monitoring, drift detection, internal audit, third-line independence.
02How it scores

Five levels. One unified scale.

Every AI governance domain is scored on the 0–4 maturity scale - the same scale every other MaturityOne module uses, so AI maturity reconciles with Cyber, Data Governance, Privacy and the rest of the platform without translation.

0
Not Established
No capability
1
Ad Hoc
Reactive · undocumented
2
Defined
Documented · inconsistent
3
Managed
Measured · consistent
4
Optimised
Continuous improvement
How a score is calculated. Each question carries a 1–5 input scale that maps deterministically to the 0–4 output. Domain scores aggregate the practitioner-weighted question scores; module score aggregates domain scores. Reviewer adjustment is captured at every level - the cascade engine uses the reviewer-signed score, never the assessor draft.
03Regulatory add-ons

Score once. Map to many.

Every regulatory add-on is a clause-level mapping from the maturity score to a specific AI governance framework. Run the assessment once; produce conformity evidence against multiple regulations. Four add-ons are live today - covering Europe, ASEAN's two newest AI laws, and the world's first AI management system standard.

ISO/IEC 42001:2023
AI management system
Live
Full clause mapping plus Annex A controls. The world's first AI management system standard. The maturity assessment maps directly to ISO/IEC 42001 clauses 4–10 plus the 38 Annex A controls covering AI policies, internal organisation, resources, AI system lifecycle, data, third-party use and end-user disclosure. Built by an ISO/IEC 42001 Lead Auditor.
Clauses 4–1038 Annex A controls
EU AI Act
Regulation (EU) 2024/1689
Live
Risk-tier classification plus obligation mapping. The world's first comprehensive AI law. The maturity assessment classifies AI systems against the EU AI Act's four risk tiers (unacceptable, high-risk, limited-risk, minimal-risk) and maps obligations for high-risk systems including risk management, data governance, transparency, human oversight and conformity assessment.
4 risk tiersGPAI obligations
Vietnam Law on Artificial Intelligence
Law No. 134/2025/QH15 · Vietnam
Live
The first comprehensive AI law in Southeast Asia. Passed by Vietnam's National Assembly on 10 December 2025, in force from 1 March 2026. Risk-based three-tier classification (high, medium, low) with mandatory pre-market conformity assessment for high-risk systems, transparency requirements for AI-generated content, and incident reporting through Vietnam's National AI Single-Window Portal. Mapping covers all 35 articles.
35 articles · 3 risk tiersIn force 1 March 2026
Malaysia National Guidelines on AI Governance and Ethics
MOSTI · AIGE 2024 · Malaysia
Live
Malaysia's national AI governance framework, launched September 2024. Issued by the Ministry of Science, Technology and Innovation (MOSTI) under the National Artificial Intelligence Roadmap 2021–2025. Built on seven principles - fairness, reliability, privacy, inclusiveness, transparency, accountability, and the pursuit of human benefit. Aligned with UNESCO and OECD AI principles. Mapping covers all three stakeholder tracks (users, policymakers, developers).
7 principles · 3 stakeholder tracksUNESCO + OECD aligned
NIST AI Risk Management Framework
National Institute of Standards and Technology · United States
Next
The United States National Institute of Standards and Technology AI Risk Management Framework. Coming next - widely adopted across US federal agencies and increasingly referenced in private-sector AI governance. Maps the AI module to the four NIST AI RMF functions: Govern, Map, Measure, Manage.
Coming next4 functions · Generative AI Profile
Australia Voluntary AI Safety Standard
Department of Industry, Science and Resources · Australia
Next
Australia's voluntary AI safety standard. The Australian Government Department of Industry, Science and Resources framework with ten guardrails for safe and responsible AI. Coming next - particularly relevant for organisations preparing for Australia's mandatory AI guardrails for high-risk settings.
Coming next10 guardrails · Australia
NZISM New Zealand
New Zealand Information Security Manual
Roadmap
Mapping to the New Zealand Information Security Manual (NZISM) for AI governance controls. Particularly relevant for New Zealand government agencies and regulated industries. Mapping in development.
Roadmap · 2026NZISM · New Zealand
United Arab Emirates AI Charter
Federal AI Office · UAE
Roadmap
The United Arab Emirates Federal AI Office's charter for responsible AI deployment. Particularly relevant for organisations operating across the Gulf Cooperation Council region where UAE-led AI governance is increasingly the regional reference. Mapping in development.
Roadmap · 2026GCC · UAE Federal scope
04Cross-domain integration

AI risk is never just AI risk.

Every AI deployment touches data, cyber, third-party, privacy and compliance. Most AI governance tools assess these as a single bundle - MaturityOne integrates AI Governance with the specialist modules that already cover those exposures. When a high-risk AI deployment is identified here, the relevant cyber, privacy, third-party and compliance modules respond. When the board sets AI risk appetite, this module's targets move with it.

- Appetite cascades in
From Enterprise Risk to AI targets
When the board sets "moderate" appetite for AI risk in Enterprise Risk, this module's target maturity moves automatically across all 10 AI Governance domains - model lifecycle, data lineage, security, transparency, accountability. Compliance findings on AI regulatory exposure (EU AI Act, ISO 42001) refine the targets further.
- Findings cascade out
From AI assessments to residual risk
Findings here - high-risk model classifications, governance gaps, transparency failures - flow back into Enterprise Risk as residual risk signals. Findings on vendor models flow into Third Party Risk for re-tier. Findings on personal data use flow into Privacy and Compliance.
- Triggers fire sideways
High-risk deployments trigger sideways
A high-risk AI deployment classification automatically triggers: Privacy review (if personal data is in scope), Cyber assessment refresh (security and adversarial defence), Third Party Risk re-tier (if vendor model), and Compliance review (regulatory applicability). Five modules respond to one classification decision.
What this looks like in practice. A team classifies a new generative AI deployment as high-risk. Within minutes: a Privacy assessment opens (personal data in training corpus); a Cyber refresh opens (model security and adversarial defence); a Third Party re-tier opens (vendor model with offshore residency); a Compliance review opens (EU AI Act high-risk classification triggers). One AI classification. Four downstream reviews. No follow-up email needed.
Pulls from
Enterprise RiskAppetite
ComplianceRegulatory exposure
Data GovernanceLineage
Cyber SecuritySecurity control
AI
- AI governance
Feeds
Enterprise RiskResidual risk
PrivacyPersonal data trigger
Third Party RiskVendor model
ComplianceEU AI Act trigger
05Sample output

Two views. One source of truth.

The assessor sees granular detail across all 10 domains. The executive sees a single score, the cascade impact, and a board-ready narrative. Both views derive from the same signed-off data - there's no "executive summary" that diverges from the underlying numbers.

Assessor viewCapture · evidence

Per-domain breakdown with weighted markers.

2.4/ 4Defined → Managed
Strategy & Business Alignment
Governance & Accountability
Risk Management & Impact
Data Governance & Quality
Engineering, MLOps & XAI
Security & Adversarial Defence

Assessor sees per-question scores, evidence references, reviewer comments, and the gap-to-target for every domain. Drillable to source.

Executive viewRead-only · board

Single score with cascade impact.

2.4/ 4Defined → Managed
→ Privacy impact
→ Compliance impact
→ Third Party AI impact
ISO 42001 conformity
EU AI Act tier readiness

Executive sees a single number, downstream cascade, regulatory conformity, and a plain-English board narrative - generated automatically from the signed-off assessor data.

06See it work

Thirty minutes. A practitioner.

A walkthrough of the AI Governance module isn't a product demo. It's an ISO/IEC 42001 Lead Auditor showing you how the 10 domains score, how ISO/IEC 42001, EU AI Act, Vietnam and Malaysia frameworks map clause-by-clause, how the cascade actually moves when scores change, and the honest picture of what it can and can't do. If we're not the right fit, we'll tell you.