Skip to content
AI Vector

Methodology

The framework, published in full

You cannot audit a black box. The complete framework - every pillar, every dimension, the maturity scale, and how confidence is computed - is public. Registry version 1.1.0-draft.1.

Maturity levels

Every dimension is scored 0-5 against concrete, observable anchors. Level 3 means it works today but depends on particular people; level 4 means it is systematic; level 5 means it corrects and improves itself.

  1. 0

    Unestablished

  2. 1

    Exploratory

  3. 2

    Emerging

  4. 3

    Operational

  5. 4

    Systematic

  6. 5

    Adaptive

Separate confidence, by design

Alongside every maturity score sits an independent confidence measure, computed from coverage (how much of the dimension your answers address), corroboration (whether evidence backs the claims), and recency. The AI interviewer clarifies and explains, but it never sets a score: scoring is deterministic, versioned, and reproducible from your stored answers.

Benchmarking follows the same honesty: percentile comparisons unlock only when 30 or more comparable organizations have completed the assessment. Until then, reports cite clearly labeled external research for context - never blended or simulated peer data.

Anchored in established frameworks

The question bank is original - written for this framework, not copied from any instrument - and it is deliberately anchored in the practice codified by widely adopted frameworks. The territory the 24 dimensions cover, and the progressions the answer anchors describe, are consistent with:

NIST AI Risk Management Framework (AI RMF 1.0)

Our Governance and Operations questions track its Govern, Map, Measure, and Manage functions: policy and accountability, risk identification including third-party AI, testing and evaluation, and post-deployment monitoring and incident response.

ISO/IEC 42001 (AI management systems)

Management-system discipline runs through the bank: living policy, named accountability, impact and risk assessment, supplier controls for vendor AI, competence and awareness, and improvement on a cadence.

OECD AI Principles

The principles most relevant to organizational readiness - transparency and explainability, robustness and security, accountability, and human oversight - appear as concrete practices in the Governance and Responsible AI questions, including the 2024 emphasis on safe handling of general-purpose AI tools.

Established maturity-model practice

The staged, behaviorally anchored design follows the tradition of the Gartner AI Maturity Model, the CMU SEI and Accenture AI Adoption Maturity Model, and the MITRE AI Maturity Model: observable anchors per level across strategy, people, technology, governance, and value, rather than opinion scales.

Anchored does not mean certified. An AI Vector score is not a conformity assessment against any standard, and none of the organizations named above is affiliated with or endorses AI Vector. The mapping exists so that your results speak the same language as the frameworks your auditors, regulators, and boards already use.

Pillar 1

Strategy & Leadership

Whether AI direction is set, funded, and owned at the top of the organization, and whether leaders make decisions about AI with the same rigor they apply to any other material investment.

Ambition & Direction

The clarity, specificity, and business grounding of the organization’s stated AI ambition.

At level 5: A written AI ambition tied to named business outcomes, revisited on a fixed cadence, that any senior leader can state consistently.

Executive Sponsorship & Ownership

Who owns AI outcomes at executive level and how actively that ownership is exercised.

At level 5: A named executive owner with budget authority, AI outcomes in their goals, and a leadership team that reviews AI progress as a standing item.

Investment & Portfolio Discipline

How AI initiatives are funded, prioritized, and stopped: portfolio logic versus ad-hoc enthusiasm.

At level 5: A managed portfolio with explicit selection criteria, staged funding, and a track record of killing initiatives that miss gates.

Strategic Alignment

Whether AI work traces to the organization’s actual strategy and operating priorities, or floats free of them.

At level 5: Every funded AI initiative maps to a strategic priority with a named business sponsor, and strategy documents treat AI as an integral lever rather than an appendix.

Pillar 2

Value & Execution

Whether AI work ships, reaches users, and produces measured business value: the distance between pilots and production impact.

Use-Case Identification & Prioritization

How systematically the organization finds, sizes, and sequences AI opportunities.

At level 5: A living, sized backlog sourced from business units, prioritized on value and feasibility, refreshed on a cadence.

Delivery & Production Deployment

The organization’s demonstrated ability to move AI solutions from pilot to supported production use.

At level 5: A repeatable path to production with defined stage gates; most started initiatives either ship or are deliberately stopped, and shipped systems have owners and SLAs.

Value Measurement

Whether business impact of AI is measured against a baseline, honestly, per initiative.

At level 5: Baselined, attributable value measurement agreed with finance, reported per initiative, driving continue/stop decisions.

Adoption & Change Management

Whether deployed AI is actually used as intended by the people it was built for.

At level 5: Adoption is instrumented, targeted, and managed like a first-class delivery outcome, with users involved from design onward.

Pillar 3

Data & Technology

Whether the data estate and technical platform can support AI reliably, safely, and at reasonable cost.

Data Foundation & Quality

Availability, quality, and accessibility of the data AI work depends on.

At level 5: Critical data domains are cataloged, owned, quality-monitored, and accessible to authorized teams without heroics.

AI Platform & Tooling

The shared technical capability for building, deploying, and running AI workloads.

At level 5: A supported platform path (build or buy) that takes a use case from experiment to monitored production without bespoke plumbing each time.

Systems Integration

How readily AI capabilities connect to the systems where work actually happens.

At level 5: AI services integrate into core workflows through governed APIs; integration effort is a known, bounded cost rather than the dominant risk.

AI Operations & Reliability

How production AI systems are monitored, maintained, and kept within cost and performance bounds.

At level 5: Production AI has monitoring for quality drift and cost, defined incident response, and lifecycle management including retirement.

Pillar 4

Governance, Risk & Trust

Whether the organization can use AI in ways it can defend: to regulators, customers, employees, and its own values.

Policy & Accountability

Existence and enforcement of AI-specific policy, and clarity of accountability when AI causes harm or error.

At level 5: A living AI policy people actually follow, with named accountability for every deployed system and real consequences for violations.

Risk Management & Review

How AI-specific risks are identified, assessed, and reviewed before and after deployment.

At level 5: Proportionate, risk-tiered review integrated into delivery, with post-deployment monitoring feeding back into risk assessments.

Regulatory & Legal Readiness

Preparedness for the AI regulation and legal exposure relevant to the organization’s sectors and geographies.

At level 5: Applicable regulations are mapped to concrete obligations with owners and evidence; legal review is embedded in the delivery path, not a launch-day surprise.

Responsible AI Practice

Concrete practices for fairness, transparency, human oversight, and data protection in AI systems.

At level 5: Responsible-AI checks are built into tooling and process with evidence artifacts produced as a by-product of delivery, and affected people have working recourse channels.

Pillar 5

People & Operating Model

Whether the organization has the skills, structures, and working practices for AI to take root beyond a few enthusiasts.

Talent & Skills

Depth and distribution of AI-relevant skills, from specialists to the broad workforce.

At level 5: The organization can staff its AI ambitions from a managed mix of hiring, development, and partners, and knows where its skill gaps are.

Workforce AI Literacy

How broadly the workforce understands what AI can and cannot do in their own work.

At level 5: Role-relevant AI literacy is part of onboarding and development for every function, refreshed as the technology moves.

Operating Model & Teaming

How AI work is organized: central, federated, embedded, and how business and technical people work together.

At level 5: A deliberate operating model with clear interfaces between central capability and business units, staffed by durable cross-functional teams.

Culture & Incentives

Whether day-to-day incentives, psychological safety, and leadership behavior favor sound AI adoption.

At level 5: Experimentation with AI is normal, safe to fail at, and rewarded; skepticism is voiced and heard rather than driven underground.

Pillar 6

Scale & Learning

Whether the organization compounds: reusing what works, learning from what fails, and improving its own AI capability over time.

Reuse & Standardization

Whether solutions, components, and patterns are reused across the organization or rebuilt each time.

At level 5: Shared components, patterns, and vendor arrangements are the default path; teams extend a common base instead of starting from zero.

Knowledge & Learning Loops

How lessons from AI work, including failures, are captured and change future behavior.

At level 5: Post-implementation reviews are routine, honest, and demonstrably change standards, training, and the next project’s plan.

Ecosystem & Partnerships

How deliberately the organization uses vendors, partners, and external communities in its AI capability.

At level 5: Partnerships are chosen against a build-buy-partner logic, managed for knowledge transfer, and exited cleanly when they stop earning their place.

Capability Improvement

Whether the organization measures and improves its own AI capability as a system, not just individual projects.

At level 5: AI capability is assessed on a cadence, gaps become funded actions, and the improvement loop itself has an owner.