The Instrument, Published

How the assessment actually works

Most AI maturity tools will not tell you how they arrive at a number. This page publishes the method: five lifecycle stages mapped to ISO/IEC 42001, eight scored dimensions across two separate scores, the maturity anchors, and the evidence levels that decide what any given answer is actually worth. The question bank stays private. The method does not.

Scope of this work

This is a readiness assessment, not a compliance audit or legal advice. ISO/IEC 42001 certification can only be granted by a certification body accredited under ISO/IEC 42006. What this method produces is a readiness score, a maturity profile and prioritised findings — never a statement that an organisation is, or is not, compliant with any standard or regulation.

Start Here

What is an AI readiness assessment?

An AI readiness assessment is a structured review of how an organisation adopts, governs and oversees AI. It produces two scores, a maturity profile across eight dimensions, and prioritised findings — measured against ISO/IEC 42001, ISO/IEC 23894, the NIST AI Risk Management Framework and the EU AI Act.

The word readiness is doing real work there. It is not a synonym for compliance and it is not a technology audit. It asks a narrower and more useful question: if a customer, an insurer, an auditor or a regulator arrived tomorrow and asked how you use AI and who is accountable for it, what could you actually show them?

Two organisations can run the same AI tools and be in entirely different positions. The difference is rarely the technology. It is whether anyone owns it, whether anyone could stop it, and whether anything is written down.

Most assessments hand you a list of twenty things to fix. This one ends with a single recommended next step. A business given ten priorities has been given none.
Stage Model

The five stages, mapped to ISO/IEC 42001

Governance is a lifecycle, not a document. These five stages are the sequence I work through, and each one corresponds to specific clauses of ISO/IEC 42001 — so the work you do at any stage is work a certification body would later recognise, rather than work that has to be redone.

Stage 1

Assess — establish the position

ISO/IEC 42001 Cl. 4 (Context) · Cl. 6.1 (Actions to address risks and opportunities)
  • Scope the AI systems in use, including free and informally adopted tools.
  • Score the eight dimensions; produce the readiness and governance scores.
  • Identify interested parties, obligations and the regulators with a legitimate interest.
  • Output: scored profile, prioritised findings, one recommended next step.
Stage 2

Define — decide what you are willing to risk

ISO/IEC 42001 Cl. 5 (Leadership & policy) · Cl. 6.2 (Objectives) · ISO/IEC 23894
  • Name a single accountable owner, with the written authority to stop a tool being used.
  • Set the AI policy, the risk appetite and the objectives the policy exists to serve.
  • Define the approval gate a new AI tool must pass before anyone starts using it.
  • Output: AI policy, risk appetite statement, accountable owner, approval gate.
Stage 3

Build — put the controls in place

ISO/IEC 42001 Cl. 7 (Support) · Cl. 8 (Operation) · Annex A controls · ISO/IEC 42005
  • AI system inventory, data provenance records and supplier terms review.
  • AI risk register; impact assessments where AI-supported decisions affect individuals.
  • Statement of Applicability, human oversight points, and staff training with a record of it.
  • Output: an AI management system that exists in operation, not only on paper.
Stage 4

Review — test it independently

ISO/IEC 42001 Cl. 9 (Performance evaluation, internal audit, management review)
  • Internal audit against the standard, conducted the way a Lead Auditor would conduct it — or your own team trained to conduct it.
  • Evidence testing: not "is there a policy", but "can you produce the record".
  • Management review pack, so AI becomes a standing agenda item rather than an incident response.
  • Output: independent findings report, nonconformities graded by severity.
Stage 5

Improve — and, if you want it, get certification-ready

ISO/IEC 42001 Cl. 10 (Improvement) · certification under ISO/IEC 42006-accredited bodies
  • Corrective actions closed and evidenced; the loop back to Stage 1 on a defined cycle.
  • Gap assessment against ISO/IEC 42001 ahead of engaging an accredited certification body.
  • Support through the certification body's own assessment — as your side of the table.
  • Output: a system that survives an external audit. I do not certify, and cannot.
What Gets Measured

What do the eight dimensions measure?

Eight dimensions, scored separately, then combined into two scores rather than one. A single blended number hides the profile that matters most — an organisation adopting AI quickly while its governance stands still.

R

Readiness score

Can this organisation get value from AI, and does it know what it is running?

D1
Strategy & valueWhether the problem AI is meant to solve is named, written down, and measured against a number that existed beforehand.
D2
Leadership & accountabilityWhether one named person owns AI use, whether that sits in their role, and whether they could actually stop a tool.
D4
Data foundationsWhich tools can reach business and customer data, where that data comes from, and when it was last checked for accuracy.
D5
AI system inventory & lifecycleWhether a maintained list of every AI tool exists — free accounts included — and whether tool changes are reviewed before they take effect.
D7
People & skillsWhether the people using AI know what they are permitted to use it for, and whether anyone has been trained to use it safely.
G

Governance score

If someone asked you to account for how AI is used here, could you?

D3
Policy & oversightA written AI policy that is current and followed, an approval gate with a record, a stated risk appetite, and knowing which regulator has an interest.
D6
Trust, risk & human oversightOutput accuracy, the review point before AI output reaches a customer or a decision, personal-data handling under UK GDPR, fairness, explainability and supplier terms.
D8
Assurance & accountabilityWhether you could show how a specific AI-assisted decision was made — and whether anything that has already gone wrong produced a recorded change.
The single highest-priority finding

If AI output reaches a customer or a decision with no person able to review or override it, that finding outranks the entire scoring model. It is followed up regardless of how well the organisation scores elsewhere.

Scoring

How is a score turned into a band?

Each dimension is scored, weighted, and expressed as a percentage of the maximum available. The two scores are then placed in one of four bands. Bands are absolute, not comparative — they describe your position against the standards, not against other organisations.

0–25

Foundational

AI is in use and essentially unmanaged. Nothing is written down and no one owns it. The first step is small and obvious.

26–50

Developing

Awareness exists and some practice has formed informally, but almost nothing would survive being asked for evidence.

51–75

Established

Ownership, policy and records exist and are broadly followed. Gaps are specific rather than systemic.

76–100

Advanced

The management system operates, is reviewed on a cycle, and produces evidence on request. Certification is a realistic goal.

The 0–4 maturity scale, with a worked example

Every question carries anchor wording, so scoring is a matter of matching a description rather than forming an impression. Here is the full anchor set for one dimension — D3, policy and oversight — as it is actually written in the instrument.

LevelAnchor wording — "Is there a written policy on how AI can be used here?"What it means
0No.Absent. Nothing exists to point to.
1We have unwritten expectations.Implicit. Practice exists in people's heads and leaves with them.
2Something written exists, but it isn't really used.Documented but inert. It would fail on the first question about application.
3Yes — written, current, and people follow it.Operating. The ceiling for any self-reported answer.
4Operating, and demonstrated on examination.Evidenced. Reached only when the artefact has been produced and tested.

Weighted items — leadership ownership, policy, the approval gate, the regulator question, auditability, accuracy, human review and personal-data handling — count double, because a failure in any one of them changes the meaning of every other answer.

Evidence

Why is a self-assessment capped below the top band?

Because nothing has been examined. Every answer given without an examination is asserted, not evidenced — so it is capped at level 3 out of 4. That cap is deliberate, and it is the honest description of what a paid engagement adds.

LevelWhat it meansHow it is reached
E0Asserted. Someone believes this to be true.Any answer given without review.
E1Described. The practice can be explained coherently and consistently.Reviewed assessment — the answers are read and questioned by a person. Self-assessment ceiling.
E2Documented. The artefact exists and has been seen.Scan or audit — policies, registers, records and supplier terms examined.
E3Operating. The control was tested and found to work in practice.Full audit — sampling, walkthroughs, and testing against live records.

A free assessment is scored on what you tell me. A paid engagement examines the evidence behind your answers — which is why a top score is not available on a self-assessment. That is the difference you are paying for, stated plainly.

Grounding

Which standards is this built on?

The method is grounded in the standards below and structured around ISO/IEC 42001. It is built on the ISO/IEC 27001 Lead Auditor and Lead Implementer methodology I hold and use — extended into the AI-specific standards, which are newer and where my position is working knowledge and applied practice, not a held certification.

Standard or regulationWhat it is forWhere it lands in this method
ISO/IEC 42001AI management systems — the certifiable standard for how an organisation governs AI.The spine. All five stages map to its clauses; the Statement of Applicability and Annex A controls sit in Stage 3.
ISO/IEC 23894Guidance on AI risk management, aligned to ISO 31000.Stage 2 risk appetite and the Stage 3 AI risk register.
ISO/IEC 42005Guidance on AI system impact assessment.Stage 3, wherever AI-supported decisions directly affect individuals — hiring, pricing, credit, treatment.
ISO/IEC 27001Information security management — the held credential this method is built on.Data foundations, supplier terms, access, and the whole audit discipline in Stage 4.
NIST AI RMFA voluntary US framework: Govern, Map, Measure, Manage.Cross-checks the dimension set, particularly measurement and monitoring.
EU AI ActEU regulation, risk-tiered by use case, with extraterritorial reach.Scope and risk-tier classification per use case, from Stage 1 onward.
UK GDPRData protection where AI processes personal data.D6. Whether that use has been assessed, and by whom.
UK regulatorsSector-led supervision — ICO, MHRA, FCA, CQC, GDC and others.D3. The UK has no single AI statute; your regulator's expectations are the live obligation.
Regulatory position

EU AI Act GPAI obligations came into force on 2 August 2026. High-risk obligations were deferred to 2 December 2027 under the Digital Omnibus package. In the UK, the Artificial Intelligence (Regulation) Bill [HL] remains a private member's bill rather than government policy, and the UK approach is regulator-led. No UK AI statute does not mean no obligations — sector regulators are already active, and data protection law already applies.

Regulatory position verified: 3 September 2026
Frequently Asked

Questions about the method

What is the difference between AI readiness and AI compliance?

Readiness is a measure of your own position: what exists, what is documented, what is actually followed, and where the gaps are. Compliance is a determination made against a specific legal or certification requirement — and for ISO/IEC 42001 it can only be granted by a certification body accredited under ISO/IEC 42006. A readiness assessment tells you what a certification body or a regulator would be likely to find. It never substitutes for their judgment.

Does the EU AI Act apply to a UK business?

It can. The Act applies extraterritorially where the output of an AI system is used in the EU, so a UK organisation serving EU customers or placing an AI-enabled product on the EU market may be in scope even with no EU establishment. GPAI obligations came into force on 2 August 2026; high-risk obligations were deferred to 2 December 2027 under the Digital Omnibus package. Scope should be assessed use case by use case, not assumed either way. Regulatory position verified 3 September 2026.

Do you certify organisations against ISO/IEC 42001?

No, and no consultancy can. ISO/IEC 42001 certification is granted only by a certification body accredited under ISO/IEC 42006 — and a body that consulted on your management system cannot then certify it. What I do is prepare organisations for that assessment and review their system independently, using the Lead Auditor and Lead Implementer methodology I hold under ISO/IEC 27001. Naming that boundary is the point, not a caveat.

Do I need this if we only use ChatGPT?

Often yes, and for a reason that has nothing to do with how sophisticated the tool is. The questions that produce the lowest scores are almost never about the model — they are about whether anyone owns the decision to use it, whether staff know what they are permitted to put into it, and whether anyone would know if something had gone wrong. A single widely-used general tool with no policy behind it is a more common finding than a complex AI estate.

Why two scores instead of one overall number?

Because the dangerous profile is invisible in a single number. An organisation with a strong readiness score and a weak governance score is moving fast and exposed — genuinely capable, adopting quickly, with oversight that has not kept pace. Blended into one figure it looks average. Split into two it is the clearest finding on the page.

Can I see the question bank?

The method is published here; the question bank is not. The 148-question consultant instrument and the 42-question screener are the intellectual property behind the service, and publishing them would also let an organisation rehearse its answers — which would make the resulting score worthless. An extract covering the methodology sections, without the question bank, is available on request.

Who sees the answers, and how is the data handled?

Answers are handled under ISO/IEC 27001-aligned practice: encrypted in transit and at rest, hosted in the UK or EEA, and accessible only to named individuals. Assessment records are retained for 24 months and then deleted or irreversibly anonymised. Any published research uses anonymised aggregate data only, and never where the population is too small to prevent a respondent being identified.

Next Step

Where this method gets applied

The assessment and the fixed-scope audits are delivered through VisionXY7, the company I founded. The governance build, the independent review and the Chief AI Officer work below are engagements I lead personally.

Delivered by Dr. Mahdi Seify — PhD (AI-Driven Business Analytics), University of Liverpool · MBA, Information Systems · ISO/IEC 27001 Lead Auditor & Lead Implementer.