The Framework

AI governance,

measured.

The Atolus AI Maturity Index is an assessment instrument that measures how responsibly a business adopts and operates AI. Every question traces to a named clause in a real law, regulation or standard — and every score comes from arithmetic that is written down, not from judgement.

Three Independent Scores

One number can't

carry three questions.

Most assessments collapse everything into a single grade. That hides the thing you most need to see, so the AMI keeps three axes separate and never adds them together.

AMI

Maturity

0–100 · higher is better

How well your AI practices are actually run — documented, owned, measured, verified. This is a capability score.

RES

Risk Exposure

0–100 · neutral

How much AI risk your business has taken on, given what your systems do and whose data they touch. Reported neutrally: exposure is a fact about your business, not a failing.

CGI

Compliance Gap

0–100 · lower is better

Which legal obligations that apply to you are unmet. Kept entirely separate from maturity, because a legal duty is not a capability.

The Headline Number

The Governance Deficit

The distance between the risk you have taken on and the maturity you have to manage it. When exposure runs ahead of governance, the gap is where incidents happen.

Governance Deficit = Risk Exposure − Maturity

It is a difference between two scores on the same 0–100 scale — a gap in points, not a percentage. It is the number most clients remember, and usually the one that moves a budget.

Position

Where you sit,

in one picture.

Risk Exposure on one axis, Maturity on the other, split at 50. Four positions, each with a different conversation attached.

Q1

Well Governed

Maturity ≥ 50 · Exposure < 50

Solid position, with headroom to adopt more AI safely.

Q2

Managed Ambition

Maturity ≥ 50 · Exposure ≥ 50

The mature target state for an AI-forward business. Sustain and monitor.

Q3

Latent Exposure

Maturity < 50 · Exposure < 50

Not urgent, but fragile. Any increase in AI use will outpace the controls. Build before scaling.

Q4

Critical Misalignment

Maturity < 50 · Exposure ≥ 50

Immediate action. This is where regulatory and operational incidents actually occur.

What It Measures

Eight domains,

44 sub-domains.

Not an invention — a re-cut of the NIST AI Risk Management Framework into units a small business can actually own, cross-checked against ISO/IEC 42001 Annex A.

D1

AI Governance & Accountability

Whether someone is actually in charge of AI here, whether the rules are written down, and whether decisions go through a process rather than to whoever moves first.

D2

Data Privacy & Data Protection

Whether personal data flowing into and out of AI systems is handled lawfully: a valid basis, a stated purpose, minimum necessary data, honored rights, assessed impacts, controlled transfers.

D3

Security & Resilience

Whether AI systems and the data they touch are protected against both conventional security failures and AI-specific attacks — and whether you could detect, respond to and recover from an incident.

D4

Third-Party & AI Supply Chain

For a smaller business, nearly all AI risk arrives through a vendor. How AI providers are selected, contracted, monitored and exited — and whether you know which AI tools your staff actually use.

D5

Transparency & Human Oversight

Whether people know they are dealing with AI, can understand and challenge decisions that affect them, and whether a competent human retains real authority over the output.

D6

Fairness, Safety & Model Quality

Whether you know how well your AI actually performs, whether you have checked for discriminatory outcomes, and whether fabricated or harmful output is controlled.

D7

Lifecycle & Operational Controls

Whether AI moves from idea to production through gates rather than by accident, and whether changes, versions, incidents and retirements are controlled.

D8

People, Culture & Competence

Whether the people using AI understand it well enough to use it safely, and whether staff can raise a concern without friction. AI literacy is a legal obligation under EU AI Act Art. 4, not a nice-to-have.

The domains are not weighted equally, and the weighting shifts by sector — a recruiting firm and a retailer do not carry the same risks, so they are not scored as though they did. Data privacy carries the most weight of the eight, because it holds the densest concentration of enforceable legal duties.

Maturity Levels

Five levels,

anchored to evidence.

Each answer maps to a defined anchor rather than to the respondent's sense of how they are doing. Level 5 does not require a department — it requires cadence, a metric, and independent verification.

  1. L1Ad Hoc
    Score band: 0–20

    Nothing exists, or activity is entirely individual and unrepeatable. Outcomes depend on who happens to be doing the work.

  2. L2Aware
    Score band: 21–40

    The organization recognizes the need and acts informally. Practices are inconsistent, undocumented, and not assigned to anyone.

  3. L3Defined
    Score band: 41–60

    The practice is documented, approved, communicated, and has a named owner. It is followed most of the time, but adherence is not verified.

  4. L4Managed
    Score band: 61–80

    The practice operates consistently, produces records, and adherence is measured against defined criteria. Deviations are detected and corrected.

  5. L5Optimized
    Score band: 81–100

    The practice is reviewed on a defined cadence using its own metrics, improved from that evidence, and independently verified.

The Instrument

Two tiers,

one scoring engine.

25
questions

Tier 1 screening — about 15 minutes, unassisted

96
questions

Tier 2 deep dive — evidence-prompted, across 44 sub-domains

25
obligations

hard legal duties, scored separately from maturity

8
domains

weighted by sector — not scored as though every domain carried the same risk

Sample questions

Deliberately plain. They are written to be answered by you, not decoded by you.

  • Does your organization have a written rule about what staff may and may not do with AI tools?
  • Is a data processing agreement in place with every AI provider that processes personal data on your behalf?
  • Have the people who use AI at work received training on how to use it safely and on its limitations?
Measured Against

The regulations that

actually reach you.

Most US businesses do not know which of these apply to them. The assessment starts by working that out from your own answers — jurisdiction, sector, data types and what your AI actually does — and scores you only against the obligations that genuinely bind you.

AI-specific

  • EU AI Act (Regulation (EU) 2024/1689)
  • NIST AI Risk Management Framework 1.0
  • ISO/IEC 42001:2023

Privacy

  • GDPR (Regulation (EU) 2016/679)
  • LGPD (Lei nº 13.709/2018, Brazil)
  • CCPA / CPRA

Security

  • ISO/IEC 27001:2022 Annex A
  • SOC 2 Trust Services Criteria

US federal, state & sectoral

  • HIPAA
  • Illinois BIPA & HB 3773
  • NYC Local Law 144
  • Colorado, Texas & Utah AI statutes
  • FTC Act §5

Coverage is not the same as currency. Our crosswalk records a verification date per regulation, and it is re-verified before it is used on your business.

Being Precise

What this is

not.

Publishing the limits is the point. An assessment that overstates what it can tell you is worth less than one that says plainly where it stops.

Not a legal opinion

It is a structured management-system assessment. A Compliance Gap of zero does not certify legal compliance, and we will not present it as if it did.

Not a certification

ISO/IEC 42001 and 27001 certification can only be issued by an accredited certification body. The AMI can be used to prepare for one.

Not an audit

Unless it is delivered at a stated high assurance level by a qualified assessor who has inspected the evidence rather than accepted it as described.

Not a replacement for a DPIA or vendor review

It tells you whether you have them, and how good they are.

Start Here

Find out where

you actually stand.

A 30-minute call, no pitch. We will walk through which regulations reach your business, what an assessment would cover, and whether it is worth doing at all right now.

Book a free 30-minute call
Typically responds within 1 business day