Maturity
How well your AI practices are actually run — documented, owned, measured, verified. This is a capability score.
The Atolus AI Maturity Index is an assessment instrument that measures how responsibly a business adopts and operates AI. Every question traces to a named clause in a real law, regulation or standard — and every score comes from arithmetic that is written down, not from judgement.
Most assessments collapse everything into a single grade. That hides the thing you most need to see, so the AMI keeps three axes separate and never adds them together.
How well your AI practices are actually run — documented, owned, measured, verified. This is a capability score.
How much AI risk your business has taken on, given what your systems do and whose data they touch. Reported neutrally: exposure is a fact about your business, not a failing.
Which legal obligations that apply to you are unmet. Kept entirely separate from maturity, because a legal duty is not a capability.
The distance between the risk you have taken on and the maturity you have to manage it. When exposure runs ahead of governance, the gap is where incidents happen.
Governance Deficit = Risk Exposure − Maturity
It is a difference between two scores on the same 0–100 scale — a gap in points, not a percentage. It is the number most clients remember, and usually the one that moves a budget.
Risk Exposure on one axis, Maturity on the other, split at 50. Four positions, each with a different conversation attached.
Solid position, with headroom to adopt more AI safely.
The mature target state for an AI-forward business. Sustain and monitor.
Not urgent, but fragile. Any increase in AI use will outpace the controls. Build before scaling.
Immediate action. This is where regulatory and operational incidents actually occur.
Not an invention — a re-cut of the NIST AI Risk Management Framework into units a small business can actually own, cross-checked against ISO/IEC 42001 Annex A.
Whether someone is actually in charge of AI here, whether the rules are written down, and whether decisions go through a process rather than to whoever moves first.
Whether personal data flowing into and out of AI systems is handled lawfully: a valid basis, a stated purpose, minimum necessary data, honored rights, assessed impacts, controlled transfers.
Whether AI systems and the data they touch are protected against both conventional security failures and AI-specific attacks — and whether you could detect, respond to and recover from an incident.
For a smaller business, nearly all AI risk arrives through a vendor. How AI providers are selected, contracted, monitored and exited — and whether you know which AI tools your staff actually use.
Whether people know they are dealing with AI, can understand and challenge decisions that affect them, and whether a competent human retains real authority over the output.
Whether you know how well your AI actually performs, whether you have checked for discriminatory outcomes, and whether fabricated or harmful output is controlled.
Whether AI moves from idea to production through gates rather than by accident, and whether changes, versions, incidents and retirements are controlled.
Whether the people using AI understand it well enough to use it safely, and whether staff can raise a concern without friction. AI literacy is a legal obligation under EU AI Act Art. 4, not a nice-to-have.
The domains are not weighted equally, and the weighting shifts by sector — a recruiting firm and a retailer do not carry the same risks, so they are not scored as though they did. Data privacy carries the most weight of the eight, because it holds the densest concentration of enforceable legal duties.
Each answer maps to a defined anchor rather than to the respondent's sense of how they are doing. Level 5 does not require a department — it requires cadence, a metric, and independent verification.
Nothing exists, or activity is entirely individual and unrepeatable. Outcomes depend on who happens to be doing the work.
The organization recognizes the need and acts informally. Practices are inconsistent, undocumented, and not assigned to anyone.
The practice is documented, approved, communicated, and has a named owner. It is followed most of the time, but adherence is not verified.
The practice operates consistently, produces records, and adherence is measured against defined criteria. Deviations are detected and corrected.
The practice is reviewed on a defined cadence using its own metrics, improved from that evidence, and independently verified.
Tier 1 screening — about 15 minutes, unassisted
Tier 2 deep dive — evidence-prompted, across 44 sub-domains
hard legal duties, scored separately from maturity
weighted by sector — not scored as though every domain carried the same risk
Deliberately plain. They are written to be answered by you, not decoded by you.
Most US businesses do not know which of these apply to them. The assessment starts by working that out from your own answers — jurisdiction, sector, data types and what your AI actually does — and scores you only against the obligations that genuinely bind you.
Coverage is not the same as currency. Our crosswalk records a verification date per regulation, and it is re-verified before it is used on your business.
Publishing the limits is the point. An assessment that overstates what it can tell you is worth less than one that says plainly where it stops.
It is a structured management-system assessment. A Compliance Gap of zero does not certify legal compliance, and we will not present it as if it did.
ISO/IEC 42001 and 27001 certification can only be issued by an accredited certification body. The AMI can be used to prepare for one.
Unless it is delivered at a stated high assurance level by a qualified assessor who has inspected the evidence rather than accepted it as described.
It tells you whether you have them, and how good they are.
A 30-minute call, no pitch. We will walk through which regulations reach your business, what an assessment would cover, and whether it is worth doing at all right now.
Book a free 30-minute call