How the assessment actually works
Most AI maturity tools will not tell you how they arrive at a number. This page publishes the method: five lifecycle stages mapped to ISO/IEC 42001, eight scored dimensions across two separate scores, the maturity anchors, and the evidence levels that decide what any given answer is actually worth. The question bank stays private. The method does not.
This is a readiness assessment, not a compliance audit or legal advice. ISO/IEC 42001 certification can only be granted by a certification body accredited under ISO/IEC 42006. What this method produces is a readiness score, a maturity profile and prioritised findings — never a statement that an organisation is, or is not, compliant with any standard or regulation.
What is an AI readiness assessment?
An AI readiness assessment is a structured review of how an organisation adopts, governs and oversees AI. It produces two scores, a maturity profile across eight dimensions, and prioritised findings — measured against ISO/IEC 42001, ISO/IEC 23894, the NIST AI Risk Management Framework and the EU AI Act.
The word readiness is doing real work there. It is not a synonym for compliance and it is not a technology audit. It asks a narrower and more useful question: if a customer, an insurer, an auditor or a regulator arrived tomorrow and asked how you use AI and who is accountable for it, what could you actually show them?
Two organisations can run the same AI tools and be in entirely different positions. The difference is rarely the technology. It is whether anyone owns it, whether anyone could stop it, and whether anything is written down.
The five stages, mapped to ISO/IEC 42001
Governance is a lifecycle, not a document. These five stages are the sequence I work through, and each one corresponds to specific clauses of ISO/IEC 42001 — so the work you do at any stage is work a certification body would later recognise, rather than work that has to be redone.
Assess — establish the position
- Scope the AI systems in use, including free and informally adopted tools.
- Score the eight dimensions; produce the readiness and governance scores.
- Identify interested parties, obligations and the regulators with a legitimate interest.
- Output: scored profile, prioritised findings, one recommended next step.
Define — decide what you are willing to risk
- Name a single accountable owner, with the written authority to stop a tool being used.
- Set the AI policy, the risk appetite and the objectives the policy exists to serve.
- Define the approval gate a new AI tool must pass before anyone starts using it.
- Output: AI policy, risk appetite statement, accountable owner, approval gate.
Build — put the controls in place
- AI system inventory, data provenance records and supplier terms review.
- AI risk register; impact assessments where AI-supported decisions affect individuals.
- Statement of Applicability, human oversight points, and staff training with a record of it.
- Output: an AI management system that exists in operation, not only on paper.
Review — test it independently
- Internal audit against the standard, conducted the way a Lead Auditor would conduct it — or your own team trained to conduct it.
- Evidence testing: not "is there a policy", but "can you produce the record".
- Management review pack, so AI becomes a standing agenda item rather than an incident response.
- Output: independent findings report, nonconformities graded by severity.
Improve — and, if you want it, get certification-ready
- Corrective actions closed and evidenced; the loop back to Stage 1 on a defined cycle.
- Gap assessment against ISO/IEC 42001 ahead of engaging an accredited certification body.
- Support through the certification body's own assessment — as your side of the table.
- Output: a system that survives an external audit. I do not certify, and cannot.
What do the eight dimensions measure?
Eight dimensions, scored separately, then combined into two scores rather than one. A single blended number hides the profile that matters most — an organisation adopting AI quickly while its governance stands still.
Readiness score
Can this organisation get value from AI, and does it know what it is running?
Governance score
If someone asked you to account for how AI is used here, could you?
If AI output reaches a customer or a decision with no person able to review or override it, that finding outranks the entire scoring model. It is followed up regardless of how well the organisation scores elsewhere.
How is a score turned into a band?
Each dimension is scored, weighted, and expressed as a percentage of the maximum available. The two scores are then placed in one of four bands. Bands are absolute, not comparative — they describe your position against the standards, not against other organisations.
Foundational
AI is in use and essentially unmanaged. Nothing is written down and no one owns it. The first step is small and obvious.
Developing
Awareness exists and some practice has formed informally, but almost nothing would survive being asked for evidence.
Established
Ownership, policy and records exist and are broadly followed. Gaps are specific rather than systemic.
Advanced
The management system operates, is reviewed on a cycle, and produces evidence on request. Certification is a realistic goal.
The 0–4 maturity scale, with a worked example
Every question carries anchor wording, so scoring is a matter of matching a description rather than forming an impression. Here is the full anchor set for one dimension — D3, policy and oversight — as it is actually written in the instrument.
| Level | Anchor wording — "Is there a written policy on how AI can be used here?" | What it means |
|---|---|---|
| 0 | No. | Absent. Nothing exists to point to. |
| 1 | We have unwritten expectations. | Implicit. Practice exists in people's heads and leaves with them. |
| 2 | Something written exists, but it isn't really used. | Documented but inert. It would fail on the first question about application. |
| 3 | Yes — written, current, and people follow it. | Operating. The ceiling for any self-reported answer. |
| 4 | Operating, and demonstrated on examination. | Evidenced. Reached only when the artefact has been produced and tested. |
Weighted items — leadership ownership, policy, the approval gate, the regulator question, auditability, accuracy, human review and personal-data handling — count double, because a failure in any one of them changes the meaning of every other answer.
Why is a self-assessment capped below the top band?
Because nothing has been examined. Every answer given without an examination is asserted, not evidenced — so it is capped at level 3 out of 4. That cap is deliberate, and it is the honest description of what a paid engagement adds.
| Level | What it means | How it is reached |
|---|---|---|
| E0 | Asserted. Someone believes this to be true. | Any answer given without review. |
| E1 | Described. The practice can be explained coherently and consistently. | Reviewed assessment — the answers are read and questioned by a person. Self-assessment ceiling. |
| E2 | Documented. The artefact exists and has been seen. | Scan or audit — policies, registers, records and supplier terms examined. |
| E3 | Operating. The control was tested and found to work in practice. | Full audit — sampling, walkthroughs, and testing against live records. |
A free assessment is scored on what you tell me. A paid engagement examines the evidence behind your answers — which is why a top score is not available on a self-assessment. That is the difference you are paying for, stated plainly.
Which standards is this built on?
The method is grounded in the standards below and structured around ISO/IEC 42001. It is built on the ISO/IEC 27001 Lead Auditor and Lead Implementer methodology I hold and use — extended into the AI-specific standards, which are newer and where my position is working knowledge and applied practice, not a held certification.
| Standard or regulation | What it is for | Where it lands in this method |
|---|---|---|
| ISO/IEC 42001 | AI management systems — the certifiable standard for how an organisation governs AI. | The spine. All five stages map to its clauses; the Statement of Applicability and Annex A controls sit in Stage 3. |
| ISO/IEC 23894 | Guidance on AI risk management, aligned to ISO 31000. | Stage 2 risk appetite and the Stage 3 AI risk register. |
| ISO/IEC 42005 | Guidance on AI system impact assessment. | Stage 3, wherever AI-supported decisions directly affect individuals — hiring, pricing, credit, treatment. |
| ISO/IEC 27001 | Information security management — the held credential this method is built on. | Data foundations, supplier terms, access, and the whole audit discipline in Stage 4. |
| NIST AI RMF | A voluntary US framework: Govern, Map, Measure, Manage. | Cross-checks the dimension set, particularly measurement and monitoring. |
| EU AI Act | EU regulation, risk-tiered by use case, with extraterritorial reach. | Scope and risk-tier classification per use case, from Stage 1 onward. |
| UK GDPR | Data protection where AI processes personal data. | D6. Whether that use has been assessed, and by whom. |
| UK regulators | Sector-led supervision — ICO, MHRA, FCA, CQC, GDC and others. | D3. The UK has no single AI statute; your regulator's expectations are the live obligation. |
EU AI Act GPAI obligations came into force on 2 August 2026. High-risk obligations were deferred to 2 December 2027 under the Digital Omnibus package. In the UK, the Artificial Intelligence (Regulation) Bill [HL] remains a private member's bill rather than government policy, and the UK approach is regulator-led. No UK AI statute does not mean no obligations — sector regulators are already active, and data protection law already applies.
Regulatory position verified: 3 September 2026Questions about the method
What is the difference between AI readiness and AI compliance?
Readiness is a measure of your own position: what exists, what is documented, what is actually followed, and where the gaps are. Compliance is a determination made against a specific legal or certification requirement — and for ISO/IEC 42001 it can only be granted by a certification body accredited under ISO/IEC 42006. A readiness assessment tells you what a certification body or a regulator would be likely to find. It never substitutes for their judgment.
Does the EU AI Act apply to a UK business?
It can. The Act applies extraterritorially where the output of an AI system is used in the EU, so a UK organisation serving EU customers or placing an AI-enabled product on the EU market may be in scope even with no EU establishment. GPAI obligations came into force on 2 August 2026; high-risk obligations were deferred to 2 December 2027 under the Digital Omnibus package. Scope should be assessed use case by use case, not assumed either way. Regulatory position verified 3 September 2026.
Do you certify organisations against ISO/IEC 42001?
No, and no consultancy can. ISO/IEC 42001 certification is granted only by a certification body accredited under ISO/IEC 42006 — and a body that consulted on your management system cannot then certify it. What I do is prepare organisations for that assessment and review their system independently, using the Lead Auditor and Lead Implementer methodology I hold under ISO/IEC 27001. Naming that boundary is the point, not a caveat.
Do I need this if we only use ChatGPT?
Often yes, and for a reason that has nothing to do with how sophisticated the tool is. The questions that produce the lowest scores are almost never about the model — they are about whether anyone owns the decision to use it, whether staff know what they are permitted to put into it, and whether anyone would know if something had gone wrong. A single widely-used general tool with no policy behind it is a more common finding than a complex AI estate.
Why two scores instead of one overall number?
Because the dangerous profile is invisible in a single number. An organisation with a strong readiness score and a weak governance score is moving fast and exposed — genuinely capable, adopting quickly, with oversight that has not kept pace. Blended into one figure it looks average. Split into two it is the clearest finding on the page.
Can I see the question bank?
The method is published here; the question bank is not. The 148-question consultant instrument and the 42-question screener are the intellectual property behind the service, and publishing them would also let an organisation rehearse its answers — which would make the resulting score worthless. An extract covering the methodology sections, without the question bank, is available on request.
Who sees the answers, and how is the data handled?
Answers are handled under ISO/IEC 27001-aligned practice: encrypted in transit and at rest, hosted in the UK or EEA, and accessible only to named individuals. Assessment records are retained for 24 months and then deleted or irreversibly anonymised. Any published research uses anonymised aggregate data only, and never where the population is too small to prevent a respondent being identified.
Where this method gets applied
The assessment and the fixed-scope audits are delivered through VisionXY7, the company I founded. The governance build, the independent review and the Chief AI Officer work below are engagements I lead personally.
Delivered by Dr. Mahdi Seify — PhD (AI-Driven Business Analytics), University of Liverpool · MBA, Information Systems · ISO/IEC 27001 Lead Auditor & Lead Implementer.