AI Transformation Maturity Assessment

Generated 2026-06-11T12:21:50.749Z · Engine ai-transformation-readiness-1.0.0

Models: gpt-5.5 (Pre-Flight) · claude-sonnet-4-6 (Audit) · gpt-5.5 (Evidence Check) · claude-sonnet-4-6 (Summary/Diagnosis) · claude-opus-4-7 (Roadmap) · gpt-5.5 (Fact-Check)

Knowledge Base: Remote PDF KB loaded (58 PDFs)

Source parse note: Material for AI Engine.pdf: PDF appears scanned or image-heavy; source coverage may depend on visual interpretation.

Evidence Check

Quality Gate Status: BLOCK

Assessment is unsafe to act on until blocking issues are resolved.

4/15 claims supported

Phase 1 findings were verified against the raw material before Phase 2 metrics were calculated.

Supported32
Weak13
Unsupported5
Missing0
Downgraded21
Rescanned15
Adjusted criteria
maturity.A1 · 1→0 · weak · rescanned
The cited role and lifecycle evidence is present in the AI Governance Process. It supports limited maturity around AI lifecycle ownership and governance roles, but not a full AI operating rhythm with cadence, backlog movement, learning loops, or traceable decision logs. The score of 1 is appropriately conservative.
antipattern.A1 · 1→0 · supported · rescanned
The AI Governance Process directly defines roles, lifecycle gates, AI Board responsibilities, escalation/reporting points, and ownership. It does not evidence delayed decisions, repeated approvals causing stalls, or unclear escalation boundaries. The zero anti-pattern score is supported.
antipattern.A3 · 1→0 · supported · rescanned
The documented lifecycle connects AI system identification, registration, design, validation, deployment, monitoring, review, and retirement. It also assigns ownership and requires verification, deployment approval, monitoring, feedback, and metrics. No harmful pilot-purgatory evidence is present.
maturity.B1 · 1→0 · supported · rescanned
The cited quotes are present in the source: deployment mentions integrating with existing systems in src-003 page 12, and tool/framework whitelisting appears in src-003 page 9. However, the source does not evidence APIs, service boundaries, events, governed connectors, brownfield wrapping, integration versioning, dependency mapping, ownership, or failure modes. A score of 0 is supported.
maturity.B2 · 2→0 · weak · rescanned
The source supports a governed AI lifecycle with registration, validation, deployment, monitoring, review, and retirement phases, including AI Board approvals and documented decommissioning. The cited quotes are traceable to src-003 pages 9, 12, and 14. The source does not show artifact versioning, rollback, or traceability from production behavior to model/prompt/data/tool/release versions, so a limited score of 1 is supported.
maturity.B3 · 1→0 · weak · rescanned
The source supports partial AI monitoring: logging and metrics for performance, accuracy, bias, security, compliance, defined metrics, feedback, baseline inconsistency notification, and corrective actions are present in src-003 pages 9, 12, 13, and 14. It does not evidence the broader observability stack required by the rubric, such as token/model spend, latency, routing, retrieval cost, cost-per-output, groundedness, business impact, defined offline/online evaluations, or explicit threshold-triggered retraining workflows. Score 1 is supported.
maturity.B4 · 1→0 · weak
The cited human-in-the-loop and reliability/security language is present in src-003 page 4, and the broader process includes risk classification, mitigation, and residual risk assessment. However, this is only adjacent evidence for the Secure-by-Design trust and safety layer. The source does not evidence red-teaming, prompt-injection testing, adversarial testing, guardrails, filters, embedded access controls, formal escalation paths, or an Agent Behavioral Contract. The low score of 1 is plausible only as a weak partial signal, not as full criterion satisfaction.
antipattern.B1 · 1→0 · unsupported
Adjudication: The source mentions tool/framework whitelisting and generic integration with existing systems, but it does not evidence manual exports, screen scraping, brittle point-to-point AI integrations, unclear service boundaries causing failures, or project-by-project fragile connectivity.
antipattern.B2 · 1→0 · unsupported
Adjudication: The source shows an approval-gated AI lifecycle with registration, verification/validation, deployment approval, monitoring, and retirement, but does not evidence uncontrolled model/prompt/agent promotion, manual unversioned prompt changes, irreproducible behavior, or lack of rollback.
antipattern.B3 · 1→1 · weak
The cited quote is real and traceable to src-003 page 12, and the source also mentions regular reporting, baseline inconsistency notification, and corrective actions. This partly counters the black-box operations anti-pattern. The only weak harmful signal is that the relevant monitoring sections omit token/model spend, cost-per-output, retrieval degradation, groundedness, and value-degradation monitoring. A score of 1 is therefore only weakly supported as a partial observability gap, not as evidence that failures are mainly found through complaints or financial surprises.
antipattern.B4 · 1→0 · unsupported
Adjudication: The source includes human-in-the-loop principles, design-stage risk identification and mitigation planning, and residual-risk review before deployment. It does not evidence safety theater, unbounded autonomy, missing behavioral limits, or safety handled only as a late-stage review.
maturity.C3 · 2→1 · weak · rescanned
The role/accountability quote is supported by src-003-p008-c011/page 8, the risk-level/approved-technology principle by src-003-p006-c008/page 6, and periodic audit/risk assessment language by src-003-p014-c022/page 14. These support embedded governance roles and auditable controls. The evidence is weaker on governance being explicitly flow-enabling rather than gate-oriented, so 2 is appropriate.

Source Registry & Domain Packets

Parsed source material was split into deterministic chunks and routed into A-E context packets. Packets guide model attention; they are not proof by themselves.

Sources5
Chunks104
DLP review chunks12
DLP caution hits6
DLP high-risk hits0
A · Adaptive Operating Model 19/33 chunks · weak coverage
B · Enterprise AI Architecture & Platform Readiness 17/24 chunks · packet coverage
C · AI Strategy, Governance & Value Realization 18/71 chunks · packet coverage
D · Data Foundations, Ownership & Accessibility 17/26 chunks · weak coverage
E · Business Capability & Service Architecture 15/15 chunks · weak coverage
Insufficient evidence | Delivery 100% · Evidence 16%
Evidence-Gated Readiness
3%
Evidence density 16% is below the 30% floor, so readiness is capped by available evidence.
Maturity Depth
5%
Average maturity score across all 25 criteria on a 0–3 scale, normalized to 0–100%. Captures partial progress that maturity_ratio misses.
Anti-Pattern Burden
5%
Average severity across all 25 anti-patterns. Higher = more friction blocking current AI Transformation practice. Low values mean "low confirmed burden" only when source evidence is strong enough.
Anti-Pattern Clearance
8%
Share of anti-patterns that were meaningfully tested and not found. This is positive only when the source had relevant coverage.
Anti-Pattern Coverage
24%
Share of anti-pattern criteria that were meaningfully assessed, either as findings or verified absences. Low coverage means absence is unknown, not good.
Maturity Ratio
0%
Share of the 25 maturity criteria that scored as fully embedded (3 of 3 sub-criteria met).

Maturity Gauges

3%

Evidence-Gated Readiness

Evidence density 16% is below the 30% floor, so readiness is capped by available evidence.

Target: High
0%

Maturity Level

Share of the 25 maturity criteria that scored as fully embedded (3 of 3 sub-criteria met).

Target: High
5%

Maturity Depth

Average maturity score across all 25 criteria on a 0–3 scale, normalized to 0–100%. Captures partial progress that maturity_ratio misses.

Target: High
16%

Anti-Pattern Level

Share of the 25 anti-patterns scored as deeply entrenched (3 of 3 sub-criteria met). Higher = worse.

Target: Low
5%

Anti-Pattern Burden

Average severity across all 25 anti-patterns. Higher = more friction blocking current AI Transformation practice. Low values mean "low confirmed burden" only when source evidence is strong enough.

Target: Low
8%

Anti-Pattern Clearance

Share of anti-patterns that were meaningfully tested and not found. This is positive only when the source had relevant coverage.

Target: High
24%

Anti-Pattern Coverage

Share of anti-pattern criteria that were meaningfully assessed, either as findings or verified absences. Low coverage means absence is unknown, not good.

Target: High
100%

Delivery Integrity

Did the audit pipeline complete? Share of 50 criteria the LLM returned valid data for. Below 100% means batches failed.

Target: High
16%

Evidence Density

Did the source actually cover the criterion? Share of 50 criteria with verified source coverage, including positive evidence, quote-backed gaps, anti-pattern findings, and verified anti-pattern absences.

Target: High

Visual Diagnosis

Category Footprint

Per-domain maturity (emerald) vs anti-pattern burden (rose). Each axis is one of the five batches; values are the sum of sub-criterion counts (0–15) for that batch.

A · Operating ModelB · AI PlatformC · GovernanceD · DataE · Service Architecture Maturity Anti-Patterns

Position vs. Quadrants

Validated maturity depth (x-axis) plotted against confirmed anti-pattern burden (y-axis). When evidence or anti-pattern coverage is insufficient, quadrant labels are suppressed.

COST BLINDNESS AI Transformation THEATER LOW / UNPROVEN SIGNAL VALIDATED STRENGTH Validated Maturity → Confirmed Burden → INSUFFICIENT EVIDENCE Quadrant placement withheld 0% 100% 100% 0% 5% / 5%

Evidence Summary

Fact-only current state · Insufficient evidence

A formally documented internal reference material lifecycle exists but no evidence of activation, live systems, pilots, data readiness, or service-area ownership was assessable from the submitted source material.

Key metrics

  • Readiness score: 3/100
  • Evidence density: 16% (below the 30% floor; score capped by available evidence)
  • Maturity Depth Index: 5%
  • Anti-Pattern Burden: 5% (confirmed)
  • Anti-Pattern Coverage: 24%
  • Silent criteria areas: 21
  • Maturity gaps confirmed: 21
  • Anti-pattern findings confirmed: 4
  • Verified anti-pattern absences: 2
  • Category scores — A: 0/15, B: 0/15, C: 3/15, D: 1/15, E: 0/15
  • Delivery integrity: 100% (all submitted criteria returned data)
  • Primary readable source: one internal reference material process document (17 pages, V1.0A, approved 2025-09-25)
  • Unreadable source: one scanned PDF (8 pages, 0% text extraction)

Source observations outside AI Transformation scope

  • A formally approved internal reference material lifecycle document exists, covering eight phases from identification to the assessed organization — this is a source observation, not a maturity strength, as activation evidence is absent.
  • Named governance roles are defined in the document: AI System Owner, AI Board, internal reference material Lead, internal reference material Process Owner, Customer Responsible, Sourcing the assessed organization the assessed organization.
  • The governance document references alignment with external the assessed organization including AI Act the assessed organization GDPR.
  • Three KPIs are listed for the governance process: AI system the assessed organization, documented use cases, the assessed organization a governance tool library.
  • Human-in-the-loop language appears in the governance objectives section.
  • Monitoring obligations for accuracy, bias, security, the assessed organization compliance are described in the operation phase of the lifecycle.

Confirmed gaps

  • No evidence that the internal reference material process has been activated for any AI system — no registered systems, no qualification records, no AI Board decisions were submitted.
  • No data readiness, data ownership, data quality, or data product evidence was found.
  • No pilot learning artefacts, launch-the assessed organization-learn records, or impact measurement evidence was submitted.
  • No service-area AI ownership assignments or service blueprints connecting AI to customer outcomes were present.
  • No AI demand routing logic, value stream mapping, or business case evidence was found.
  • Category A (AI strategy the assessed organization operating model) scored 0/15 — no assessable evidence.
  • Category B (data foundations) scored 0/15 — no assessable evidence.
  • Category E (value realization the assessed organization learning) scored 0/15 — no assessable evidence.

Confirmed anti-patterns

  • Governance documentation exists without evidence of operational activation — a policy-without-practice pattern is a hypothesis at this stage, but the absence of any activation evidence is a confirmed gap.
  • No anti-pattern absence could be confirmed for 19 of 21 anti-pattern criteria — coverage is too low to assess whether known AI readiness anti-patterns are present or absent in practice.

Verified anti-pattern absences

  • [A1] Tested absent: Final anti-pattern assessment: Tested absent. Evidence-check resolved the scanner score from 0 to 0 after a targeted rescan. Verifier status: supported. The AI Governance Process directly defines roles, lifecycle gates, AI Board responsibilities, escalation/reporting points, and ownership. It does not evidence delayed decisions, repeated approvals causing stalls, or unclear escalation boundaries. The zero anti-pattern score is supported. Coverage interpretation: The source has relevant coverage of AI decision roles and governance flow, so harmful decision fog would likely appear in the documented model if it were designed into the process. Actual operational decision delays are not independently evidenced.
  • [A3] Tested absent: Final anti-pattern assessment: Tested absent. Evidence-check resolved the scanner score from 0 to 0 after a targeted rescan. Verifier status: supported. The documented lifecycle connects AI system identification, registration, design, validation, deployment, monitoring, review, and retirement. It also assigns ownership and requires verification, deployment approval, monitoring, feedback, and metrics. No harmful pilot-purgatory evidence is present. Coverage interpretation: The AI Governance Process directly covers pilot-to-production governance, lifecycle ownership, validation, monitoring, and review, so disconnected pilots would likely be visible in the documented process design. Actual execution outcomes are not proven by this source.

Anti-patterns not assessable from source

  • [A2] Not assessed: Final anti-pattern assessment: Not assessed. Evidence-check resolved the scanner score from 0 to 0. Verifier status: supported. The source does not show that all AI initiatives are forced through the same delivery model, nor does it show exploratory work being managed with rigid plans. A common governance lifecycle is documented, but that is not sufficient evidence of a one-size-fits-all delivery anti-pattern. Coverage interpretation: The source is mainly governance-process documentation and is largely silent on delivery model differentiation, demand routing, and how exploratory versus predictable AI work is actually managed.
  • [A4] Not assessed: Final anti-pattern assessment: Not assessed. Evidence-check resolved the scanner score from 0 to 0. Verifier status: supported. The source does not evidence AI knowledge concentrated in isolated experts, repeated mistakes, or dependence on heroes. It also does not provide enough AI learning-flow evidence to prove the opposite. The zero anti-pattern score is supported because no harmful signal is present. Coverage interpretation: The documents are governance/process descriptions and are largely silent on where AI expertise resides, how lessons are institutionalized, or whether teams rely on individual heroes.
  • [A5] Not assessed: Final anti-pattern assessment: Not assessed. Evidence-check resolved the scanner score from 0 to 0. Verifier status: supported. The source does not evidence AI being used mainly for fragmented task acceleration, nor does it show increased checking, rework, coordination burden, workslop, or activity/utilization-based measurement. The zero anti-pattern score is supported. Coverage interpretation: The available material does not assess work outcomes, employee experience, review/rework cost, cognitive load, or productivity measurement practices after AI introduction.
  • [B1] Not assessed: Final anti-pattern assessment: Not assessed. Evidence-check resolved the scanner score from 1 to 0. Verifier status: unsupported. Adjudication: The source mentions tool/framework whitelisting and generic integration with existing systems, but it does not evidence manual exports, screen scraping, brittle point-to-point AI integrations, unclear service boundaries causing failures, or project-by-project fragile connectivity. Coverage interpretation: Coverage is limited to AI governance and deployment process language, not integration architecture detail; it is too thin to support the harmful anti-pattern or a tested absence.
  • [B2] Not assessed: Final anti-pattern assessment: Not assessed. Evidence-check resolved the scanner score from 1 to 0. Verifier status: unsupported. Adjudication: The source shows an approval-gated AI lifecycle with registration, verification/validation, deployment approval, monitoring, and retirement, but does not evidence uncontrolled model/prompt/agent promotion, manual unversioned prompt changes, irreproducible behavior, or lack of rollback. Coverage interpretation: Coverage is relevant to lifecycle governance but lacks artifact-level release, versioning, rollback, and traceability details; absence of those details is not enough to establish the chaos anti-pattern.
  • [B4] Not assessed: Final anti-pattern assessment: Not assessed. Evidence-check resolved the scanner score from 1 to 0. Verifier status: unsupported. Adjudication: The source includes human-in-the-loop principles, design-stage risk identification and mitigation planning, and residual-risk review before deployment. It does not evidence safety theater, unbounded autonomy, missing behavioral limits, or safety handled only as a late-stage review. Coverage interpretation: Coverage addresses governance and risk control at a process level but lacks detailed AI safety engineering evidence; this is insufficient to confirm the harmful anti-pattern or fully rule it out.
  • [B5] Not assessed: Final anti-pattern assessment: Not assessed. Evidence-check resolved the scanner score from 0 to 0. Verifier status: supported. The provided sources do not evidence every project building its own AI stack, disconnected tool buying, duplicate spend, or fragmentation-driven maintenance debt. The scanner's zero score is supported by lack of anti-pattern evidence in the supplied material. Coverage interpretation: The source material is mostly governance/process documentation and is not sufficient to test for or rule out platform fragmentation across actual AI delivery teams.
  • [C1] Not assessed: Final anti-pattern assessment: Not assessed. Evidence-check resolved the scanner score from 0 to 0 after a targeted rescan. Verifier status: supported. No source evidence shows AI being treated as a slogan, everything being labeled an AI priority, or tool adoption preceding value definition. The AI governance process provides some counter-signals, including evaluation against business goals/customer needs and tool whitelisting before use. Coverage interpretation: The governance process is relevant but not a comprehensive strategy or portfolio artifact, so it does not fully test whether slogan-like AI strategy exists elsewhere.
  • [C2] Not assessed: Final anti-pattern assessment: Not assessed. Evidence-check resolved the scanner score from 0 to 0. Verifier status: supported. The provided sources do not contain evidence of fashion-driven use-case selection, unsupported ROI/savings claims, or celebration of spend/pilots without enterprise impact. Coverage interpretation: The source material is mainly governance/process documentation and does not cover the actual AI initiative portfolio, benefit claims, or post-release value reporting; therefore absence is not fully testable.
  • [C3] Not assessed: Final anti-pattern assessment: Not assessed. Evidence-check resolved the scanner score from 1 to 0. Verifier status: unsupported. Adjudication: The source shows structured governance controls such as tool whitelisting, AI Board validation, and sourcing/legal review, but it does not show that these controls create harmful rigidity, delay delivery, reduce safety effectiveness, or drive teams to bypass governance. Coverage interpretation: Coverage is process-design oriented rather than operational. It describes approval steps and responsibilities, but provides no evidence about actual flow friction, shadow AI behavior, unclear pathways, or governance being disconnected from business or architecture realities.
  • [C5] Not assessed: Final anti-pattern assessment: Not assessed. Evidence-check resolved the scanner score from 0 to 0. Verifier status: supported. No evidence in the provided sources shows uncontrolled AI backlog/spend growth, sunk-cost continuation of weak initiatives, or platform/tool expansion without value validation. Coverage interpretation: The source material does not meaningfully cover AI spend, portfolio dynamics, backlog growth, or investment governance, so absence of the anti-pattern cannot be confirmed from this packet alone.
  • [D1] Not assessed: Final anti-pattern assessment: Not assessed. Evidence-check resolved the scanner score from 0 to 0 after a targeted rescan. Verifier status: supported. The zero anti-pattern score is supported. The source does not evidence centralized or undefined data ownership causing context loss, AI teams guessing dataset meaning, or AI use cases stalling because nobody owns interpretation or correction. The AI System Owner role is system-level and does not prove domain data ownership, but it also does not prove the harmful pattern. Coverage interpretation: The available documents are AI governance and process governance specifications. They provide limited system-level ownership coverage but insufficient coverage of actual enterprise data ownership practices, so absence of this anti-pattern is not testable.
  • [D2] Not assessed: Final anti-pattern assessment: Not assessed. Evidence-check resolved the scanner score from 0 to 0. Verifier status: supported. The zero anti-pattern score is supported. The source does not show that data is collected merely because it is available, that models receive raw signals without context, or that outputs are unreliable because a semantic/business meaning layer is missing. Coverage interpretation: The source discusses governance-stage data preparation and quality at a high level, but does not provide enough operational detail about AI datasets or model inputs to prove the harmful pattern is absent.
  • [D3] Not assessed: Final anti-pattern assessment: Not assessed. Evidence-check resolved the scanner score from 0 to 0. Verifier status: supported. The zero anti-pattern score is supported. The source does not evidence stale copies, manual files, undocumented transformations, unknown data origins, unprovable quality, or quality failures discovered only after model or business escalation. Coverage interpretation: Although the governance process includes data quality, testing, monitoring, and documentation activities, it does not provide enough lineage or operational data-flow evidence to test whether data swamp or broken-lineage conditions exist in practice.
  • [D4] Not assessed: Final anti-pattern assessment: Not assessed. Evidence-check resolved the scanner score from 1 to 0. Verifier status: unsupported. Adjudication: The source discusses privacy and security principles, protection from unauthorized access and breaches, and data retention, but it does not show over-broad AI data access, uncontrolled experiment copies, missing logging/approval/purpose controls, or controls being added late. Coverage interpretation: Coverage is relevant but high-level; it is sufficient to show governance intent, not sufficient to assess whether the harmful access-control anti-pattern exists or is cleanly absent.
  • [D5] Not assessed: Final anti-pattern assessment: Not assessed. Evidence-check resolved the scanner score from 0 to 0. Verifier status: supported. The zero anti-pattern score is supported. The source is silent on RAG, embeddings, vector stores, duplicate knowledge stores, feature stores, retrieval failures, context growth, and duplicated retrieval costs; therefore there is no evidence of the harmful pattern. Coverage interpretation: The available source material does not cover retrieval or knowledge-store architecture, so absence of this anti-pattern is not testable from the provided documents.
  • [E2] Not assessed: Final anti-pattern assessment: Not assessed. Evidence-check resolved the scanner score from 0 to 0. Verifier status: supported. No source evidence shows AI being applied to isolated tasks, creating downstream rework, or ignoring customer experience/end-to-end flow. The documents are governance/process documents and do not provide operational examples of AI automation design. Coverage interpretation: The available documents are not service-flow or implementation evidence and would not reliably reveal spot optimization or silo automation if it existed.
  • [E4] Not assessed: Final anti-pattern assessment: Not assessed. Evidence-check resolved the scanner score from 0 to 0 after a targeted rescan. Verifier status: supported. The source defines an accountable AI System Owner through retirement, which counters the specific pattern of ownership disappearing after pilot/vendor delivery. It does not provide enough service-area organizational structure evidence to test whether AI teams are disconnected from service areas or whether work is split into sequential handoffs. Coverage interpretation: Lifecycle ownership is covered, but team topology relative to service areas is not sufficiently covered to confirm absence of disconnected AI project teams.
  • [E5] Not assessed: Final anti-pattern assessment: Not assessed. Evidence-check resolved the scanner score from 0 to 0. Verifier status: supported. No evidence shows broad AI rollout before readiness, failure to convert pilot learning into reusable patterns, or repeated independent mistakes across service areas. The source addresses lifecycle governance for individual AI systems, not enterprise scaling behavior. Coverage interpretation: The available source is silent on scaling strategy, rollout sequencing, service-area adoption, and pilot-to-pattern conversion, so absence of the big-bang anti-pattern is not testable.

Silent / missing evidence

  • No evidence of any AI system currently in production, pilot, or active development.
  • No security controls, red-teaming records, or agent behavioral boundary definitions.
  • No AI spend, cost visibility, or investment portfolio data.
  • No operating rhythm evidence: no AI Board minutes, no review cadence records, no learning review outputs.
  • No workforce capability, training, or change absorption evidence.
  • No customer or service outcome metrics connected to any AI initiative.

Evidence summary for the AI Transformation Lead

The internal reference material process document confirms that a structured lifecycle framework exists on paper — covering identification, qualification, the assessed organization, the assessed organization, monitoring, review, the assessed organization the assessed organization — with named roles including an AI Board, AI System Owner, the assessed organization internal reference material Lead. Three KPIs are listed: AI system the assessed organization, documented use cases, the assessed organization a governance tool library.

What is missing: The audit could not confirm any of the following: whether the governance process has been activated for any live AI system; whether any AI system has completed qualification the assessed organization registration; whether pilots have been run, reviewed, or produced learning artefacts; whether service-area ownership of AI work exists in practice; whether data quality, data ownership, or data product accountability has been established; whether AI demand is the assessed organization routed by uncertainty, value, or risk; whether value measurement or impact statements exist for any AI initiative; the assessed organization whether security red-teaming or human-escalation controls have been exercised.

What is needed before a directive roadmap can be written: The next assessment cycle should include: evidence of at least one AI system that has passed through the qualification the assessed organization registration gate; operating rhythm artefacts such as AI Board meeting records or review minutes; pilot learning documentation; service-area AI ownership assignments; the assessed organization data readiness or data product evidence tied to at least one AI use case.

Confidence Notes — Unverified Claims

The following statements could not be verified against the source after 1 regenerate pass(es). Treat with caution.

Evidence summary for the CFO

What the audit found: The submitted documents indicate that a formal internal reference material lifecycle has been defined the assessed organization approved, with stated objectives that include customer value, fairness, transparency, the assessed organization regulatory compliance. Roles are specified for customer-facing responsibilities, including a Customer the assessed organization accountable for requirements gathering, the assessed organization approval, the assessed organization the assessed organization sign-off. Three governance KPIs are listed. However, the evidence density is 16% the assessed organization the readiness score is 3 out of 100, meaning the audit cannot confirm that any of these process commitments have been activated within a real service area or customer engagement. The the assessed organization is provisionally insufficient evidence.

What is missing: The audit found no evidence of AI opportunities tied to specific service outcomes or customer journeys; no service blueprints or value-stream maps showing where AI intervenes in customer-facing work; no pilot results, adoption data, or customer the assessed organization from any deployed AI system; no Impact Statements or business cases connecting AI investments to measurable service or outcome improvement; the assessed organization no indication of how work has been redesigned — rather than simply accelerated — in any service area.

What is needed before a directive roadmap can be written: Service-area owners should supply: at least one active AI use case with a documented business case or Impact Statement; customer journey or service blueprint evidence showing where AI is or will be applied; pilot outcome data or learning review records; the assessed organization articulation of how quality the assessed organization value will be measured post-launch for any AI-enabled service.

Evidence summary for the Engineering Lead

What the audit found: A formally approved internal reference material process document (Version 1.0A, September 2025) describes a lifecycle model spanning eight phases, with process roles, a the assessed organization table, the assessed organization references to alignment with AI Policy, GDPR, AI Act, the assessed organization ISO standards. The overall score is 3 out of 100 with evidence density at 16%, the assessed organization 21 silent criteria areas returned no assessable evidence. The maturity the assessed organization is insufficient evidence.

What is missing: The audit could not confirm: whether any AI platform or infrastructure has been built or integrated; whether data products, data ownership, or data quality controls exist; whether prompt, model, or tool versioning is operationally active; whether observability or evaluation tooling is deployed; whether security controls, red-teaming, or agent behavioral boundaries have been tested; whether the internal reference material tool library referenced in the the assessed organization table exists the assessed organization is populated; the assessed organization whether the governance process has been applied to any system currently in production or pilot.

What is needed before a directive roadmap can be written: The next assessment cycle should include: evidence of at least one AI system registered in the governance tool library; architecture documentation for any AI platform or integration layer; data lineage or data product artefacts; monitoring the assessed organization observability configuration evidence; the assessed organization security or red-the assessed organization assessment records tied to any AI system under development or in operation.

Diagnosis

Interpretation of evidence — not the implementation plan

Primary bottleneck

The audit cannot identify a primary bottleneck with confidence. The provisional interpretation is that a governance framework has been designed but there is no assessable evidence that it has been put into practice across any domain — strategy, data, platform, service ownership, or value realization.

Root causes

  • Hypothesis only — not evidenced: the governance lifecycle may have been designed without concurrent activation of the operational, data, the assessed organization platform foundations needed to make it functional.
  • Hypothesis only — not evidenced: AI readiness work may be concentrated in policy the assessed organization process documentation rather than in service-area execution or data preparation.
  • Confirmed gap: the source material submitted for audit was insufficient in volume the assessed organization variety to support a reliable diagnosis — one readable process document the assessed organization one unreadable scanned file cannot represent the full organizational state.

Domain diagnosis

  • A: A - Adaptive Operating Model: maturity signal 0/15. No verified maturity evidence was strong enough to score this domain above zero. Anti-pattern absence is mostly unknown, not proven healthy. 5 maturity criterion/criteria remain silent or not evidenced for this domain. No criterion-specific source coverage was verified for this domain.
  • B: B - Enterprise AI Architecture & Platform Readiness: maturity signal 0/15. No verified maturity evidence was strong enough to score this domain above zero. Verified source coverage is mostly Operational evidence.
  • C: C - AI Strategy, Governance & Value Realization: maturity signal 3/15. 2 maturity criterion/criteria remain silent or not evidenced for this domain. Verified source coverage is mostly Process, Accountability, Governance evidence.
  • D: D - Data Foundations, Ownership & Accessibility: maturity signal 1/15. Partial or stronger maturity evidence appears in D4 Data Leakage & Over-Broad Access. Anti-pattern absence is mostly unknown, not proven healthy. 4 maturity criterion/criteria remain silent or not evidenced for this domain. Verified source coverage is mostly Governance evidence.
  • E: E - Business Capability & Service Architecture: maturity signal 0/15. No verified maturity evidence was strong enough to score this domain above zero. Anti-pattern signal appears in E1 AI Ideas Detached from Business Architecture; E3 Untraceable AI Build Logic. 5 maturity criterion/criteria remain silent or not evidenced for this domain. Verified source coverage is mostly Process evidence.

Confidence (low): Evidence density is 16%, below the 30% floor required for reliable scoring. Twenty-one criteria areas are silent. The sole readable source is a single governance process document with no activation evidence. The scanned PDF contributed zero assessable content. A diagnosis cannot be drawn with confidence from this evidence base.

Planning Decision: NO GO

Evidence does not support a directive roadmap yet.

Safe to act on

  • Gather missing evidence as described in the validation plan before re-running the assessment.
  • Validate candidate themes against operational reality before treating them as confirmed gaps.

Evidence needed before action

  • At least one AI system registration record demonstrating the governance lifecycle has been activated.
  • AI Board meeting minutes or decision records from any qualification or the assessed organization gate.
  • Data readiness or data product documentation for at least one AI use case.
  • Platform or architecture documentation for any AI system in development or production.
  • Pilot or launch-the assessed organization-learn artefacts including outcome data the assessed organization learning review records.
  • Service-area AI ownership assignments linking named accountable roles to specific service domains.
  • An Impact Statement or business case connecting at least one AI initiative to a measurable service or customer outcome.
  • A readable, text-extractable version of the scanned PDF originally submitted.

Source Coverage Gaps

To strengthen the next assessment cycle, include the following kinds of evidence in the source document.

other

Findings & Validation Plan

Evidence in the source did not support a directive roadmap. This section reports what the audit can confirm and what additional material is needed before a confident strategy can be written.

Evidence-backed findings

  • A formally approved internal reference material process document (V1.0A, September 2025) defines eight lifecycle phases — identification, qualification the assessed organization registration, the assessed organization the assessed organization development, verification the assessed organization validation, the assessed organization, operation the assessed organization monitoring, review the assessed organization evaluation, the assessed organization the assessed organization — with associated role responsibilities for each phase.
  • Seven named governance roles are defined in the document: AI System Owner, AI Board, internal reference material Lead, internal reference material Process Owner, Customer Responsible, Sourcing the assessed organization the assessed organization, the assessed organization Customer the assessed organization.
  • The governance document explicitly states human-in-the-loop as a governance objective the assessed organization describes ongoing monitoring obligations for accuracy, bias, security, the assessed organization compliance during the operation phase.
  • Three KPIs are listed in the governance document — AI system the assessed organization count, documented use case count, the assessed organization a governance tool library — all of which are process-level activity metrics with no outcome or value linkage.
  • The governance document references alignment with AI Act, GDPR, the assessed organization ISO standards as compliance obligations, the assessed organization lists AI Policy, Security Policy, Privacy Policy, the assessed organization Risk Management as mandatory the assessed organization documents.
  • The scanned PDF submitted as the primary source document returned zero text across eight pages, contributing no assessable evidence to any scoring criterion.
  • Categories A, B, the assessed organization E each scored 0/15, indicating no assessable evidence was found for AI strategy the assessed organization operating model, data foundations, or value realization the assessed organization learning.
  • Twenty-one criteria areas returned no evidence (silent), meaning the audit could not confirm the presence or absence of readiness characteristics across the majority of the assessment framework.

Candidate remediation themes

  • internal reference material activation: moving from documented lifecycle to evidence of registered systems, gate decisions, the assessed organization operating rhythm.
  • Data foundations the assessed organization ownership: establishing data product accountability, quality controls, the assessed organization semantic context for AI use cases.
  • Service-area AI ownership: connecting AI work to named accountable owners within specific service domains the assessed organization customer value streams.
  • Value the assessed organization impact measurement: developing Impact Statements, business cases, the assessed organization post-launch outcome metrics for AI initiatives.
  • Responsible [PERSON_NAME_REDACTED] practice: operationalizing the human-in-the-loop, bias monitoring, the assessed organization security obligations described in the governance document.
  • Platform the assessed organization architecture readiness: establishing observable, integrated AI system infrastructure that supports the lifecycle the governance document describes.

Missing evidence

  • No AI system registration records demonstrating that the qualification the assessed organization registration phase has been completed for any system.
  • No AI Board meeting minutes, gate decisions, or approval records of any kind.
  • No data architecture, data ownership, or data product documentation.
  • No pilot or launch-the assessed organization-learn outcome records, learning review artefacts, or impact measurement data.
  • No service-area AI ownership assignments or service blueprints linking AI work to customer outcomes.
  • No AI platform, infrastructure, or observability tooling documentation.
  • No security, red-the assessed organization, or agent behavioral control evidence.
  • No readable content from the scanned PDF submitted as the primary source document.

Validation plan

  • Submit a text-extractable version of the scanned PDF, or replace it with equivalent readable documentation describing the AI initiatives it was intended to evidence.
  • Provide at least one AI system registration record completed under the existing governance process, including purpose, data description, the assessed organization risk the assessed organization fields.
  • Supply AI Board meeting minutes or decision logs from any governance gate — qualification, the assessed organization approval, or risk acceptance — to confirm the process is operational.
  • Submit data readiness documentation for at least one AI use case, including data source identification, quality assessment, the assessed organization ownership assignment.
  • Provide a pilot or launch-the assessed organization-learn artefact for any AI initiative, including an Impact Statement, defined success metrics, the assessed organization a post-pilot review record.
  • Identify the assessed organization document at least one service-area AI owner [PERSON_NAME_REDACTED] a named accountable role, associated service domain, the assessed organization active AI initiative — to allow assessment of service-area ownership the assessed organization operating model maturity.

Forensic Audit: AI Transformation Maturity

A · Adaptive Operating Model

A1

AI Operating Rhythm & Decision Rights

NOK

The organization connects AI strategy, demand intake, delivery, learning, and governance through a visible operating rhythm with clear decision ownership.

AI Reasoning

Final maturity assessment: NOK. Evidence-check resolved the scanner score from 1 to 0 after a targeted rescan. Verifier status: weak. The cited role and lifecycle evidence is present in the AI Governance Process. It supports limited maturity around AI lifecycle ownership and governance roles, but not a full AI operating rhythm with cadence, backlog movement, learning loops, or traceable decision logs. The score of 1 is appropriately conservative.

A2

Adaptive AI Demand Routing

NOK

AI work is routed through the operating model by work nature, value, uncertainty, risk, cost profile, capacity, competence, and service ownership instead of using one delivery model for every initiative.

AI Reasoning

Crit 1: No evidence of AI demand classification by nature of work. Crit 2: No evidence of separate delivery paths for predictable vs. uncertain AI demands. Crit 3: No evidence of routing connected to capacity, competence, value hypothesis, cost profile, or risk level. Total: 0. The source documents are an AI Governance Process, a Process Governance Management Process, and a Decision-Making Authority Policy - none address demand routing for AI work.

A3

Evidence-Based Launch-and-Learn Model

NOK

The organization de-risks AI transformation through Kickstart validation, bounded vertical slices, evidence-based business cases, and explicit conversion into Building-the-System scaling patterns.

AI Reasoning

Crit 1: No evidence of bounded vertical slices, Kickstart use cases, or safe experiments tied to service-area impact statements. Crit 2: No evidence of pilot learnings being captured and used to refine operating model, architecture, data, governance, safety, and value assumptions. Crit 3: No defined transition from Kickstart validation to Building-the-System scaling, no pilot playbook or absorption-readiness map. Total: 0.

A4

Shared Learning Architecture

NOK

AI knowledge flows through communities, chapters, guilds, and reusable practice rather than remaining isolated in experts or pilot teams.

AI Reasoning

Crit 1: No evidence of communities, chapters, guilds, or equivalent structures for AI learning. Crit 2: No evidence of lessons from AI pilots, failures, red teaming, or incidents being converted into reusable practices. Crit 3: No evidence of business, AI, data, platform, and service teams learning together about AI. Total: 0.

A5

Human-AI Work Redesign

NOK

AI initiatives redesign work, handoffs, roles, review cost, rework cost, and feedback loops so human capacity moves toward higher-value contribution.

AI Reasoning

Crit 1: No evidence that AI initiatives are designed to reallocate human capacity toward higher-value work. Crit 2: No evidence of roles, handoffs, review points, exception paths, or human-in-the-loop responsibilities being redesigned. Crit 3: No evidence of measuring employee experience, cognitive load, review/rework cost, quality, or customer impact after AI introduction. Total: 0.

B · Enterprise AI Architecture & Platform Readiness

B1

Service-Boundary-Based AI Integration

NOK

AI systems integrate through reliable service boundaries, brownfield-compatible APIs, events, and governed connectors with documented ownership and failure modes.

AI Reasoning

Final maturity assessment: NOK. Evidence-check resolved the scanner score from 0 to 0 after a targeted rescan. Verifier status: supported. The cited quotes are present in the source: deployment mentions integrating with existing systems in src-003 page 12, and tool/framework whitelisting appears in src-003 page 9. However, the source does not evidence APIs, service boundaries, events, governed connectors, brownfield wrapping, integration versioning, dependency mapping, ownership, or failure modes. A score of 0 is supported.

B2

AI Lifecycle & Release Control

NOK

Models, prompts, agents, tools, datasets, and evaluation suites are versioned and released through controlled lifecycle practices.

AI Reasoning

Final maturity assessment: NOK. Evidence-check resolved the scanner score from 1 to 0 after a targeted rescan. Verifier status: weak. The source supports a governed AI lifecycle with registration, validation, deployment, monitoring, review, and retirement phases, including AI Board approvals and documented decommissioning. The cited quotes are traceable to src-003 pages 9, 12, and 14. The source does not show artifact versioning, rollback, or traceability from production behavior to model/prompt/data/tool/release versions, so a limited score of 1 is supported.

B3

AI Observability & Evaluation System

NOK

Production AI behavior is monitored through a Sense & Respond loop for quality, safety, token/model spend, latency, routing performance, retrieval cost, cost-per-output, groundedness, drift, and business impact.

AI Reasoning

Final maturity assessment: NOK. Evidence-check resolved the scanner score from 1 to 0 after a targeted rescan. Verifier status: weak. The source supports partial AI monitoring: logging and metrics for performance, accuracy, bias, security, compliance, defined metrics, feedback, baseline inconsistency notification, and corrective actions are present in src-003 pages 9, 12, 13, and 14. It does not evidence the broader observability stack required by the rubric, such as token/model spend, latency, routing, retrieval cost, cost-per-output, groundedness, business impact, defined offline/online evaluations, or explicit threshold-triggered retraining workflows. Score 1 is supported.

B4

Secure-by-Design AI Trust & Safety Layer

NOK

Trust and safety controls are embedded Secure-by-Design into AI workflows, including red teaming, guardrails, access controls, human escalation, and adversarial testing.

AI Reasoning

Final maturity assessment: NOK. Evidence-check resolved the scanner score from 1 to 0. Verifier status: weak. The cited human-in-the-loop and reliability/security language is present in src-003 page 4, and the broader process includes risk classification, mitigation, and residual risk assessment. However, this is only adjacent evidence for the Secure-by-Design trust and safety layer. The source does not evidence red-teaming, prompt-injection testing, adversarial testing, guardrails, filters, embedded access controls, formal escalation paths, or an Agent Behavioral Contract. The low score of 1 is plausible only as a weak partial signal, not as full criterion satisfaction.

B5

AI Platform as Product

NOK

Reusable AI platform products provide shared model access, model routing, caching, quotas, budget alerts, data patterns, deployment templates, observability, evaluation, and cost-aware developer experience.

AI Reasoning

Crit 1: Not found — no shared AI platform products, model gateways, or reusable MLOps/LLMOps described. Crit 2: Not found — no platform team accountability to service-area teams as internal customers. Crit 3: Not found — no measurement of platform adoption, flow, reliability, or value enablement. The source documents are a governance process and a process management process, which are single-purpose and would not be expected to cover platform product capabilities. Total: 0.

C · AI Strategy, Governance & Value Realization

C1

Purpose-Driven AI Strategy

Partial

AI ambition is connected to strategic purpose, customer value, business model choices, and explicit boundaries for where AI should not be used.

AI Reasoning

Crit 1: Partially met — the governance process references alignment with 'business goals' and 'customer needs' but does not articulate a clear strategic narrative for why AI matters to the business model or customer value proposition. Score 1 at most. Crit 2: Not found — no connection of AI ambition to specific service areas, value streams, or strategic domains. Crit 3: Not found — no explicit where-not-to-use-AI boundaries defined. Total: 1.

Evidence
  • “This stage gathers ideas for AI systems, whether initiated from within the organization or proposed by external customers. It includes evaluating these concepts based on their alignment with business goals, technological possibilities, and customer needs.” — 5.1.1 AI system identification · Process
C2

Impact-Driven AI Value Framing

NOK

AI initiatives start from impact statements and value hypotheses, with evidence-based business cases, baseline and post-release measurement, unit economics, and value metrics beyond cost reduction.

AI Reasoning

Crit 1: Not found — no evidence of AI initiatives starting from impact statements rather than tool ideas. Crit 2: Not found — no outcome metrics, unit economics, or value metrics defined. Crit 3: Not found — no value hypothesis testing, pilot review, or kill/continue/scale decision logic. Total: 0.

C3

Embedded AI Governance Model

Partial

AI governance is embedded into ownership, architecture, security, data, service operations, and auditability as an enabling system.

AI Reasoning

Final maturity assessment: Partial. Evidence-check resolved the scanner score from 2 to 1 after a targeted rescan. Verifier status: weak. The role/accountability quote is supported by src-003-p008-c011/page 8, the risk-level/approved-technology principle by src-003-p006-c008/page 6, and periodic audit/risk assessment language by src-003-p014-c022/page 14. These support embedded governance roles and auditable controls. The evidence is weaker on governance being explicitly flow-enabling rather than gate-oriented, so 2 is appropriate.

Evidence
  • “AI System Owner ... Accountable for the AI System and its performance and compliance until retirement. ... AI Leader Responsible that AI strategy and adherence to policy is carried out ... AI Governance Process Owner Responsible for defining, cascading and verifying the implementation of company's AI Governance. ... AI Board ... qualifies the subsequent AI system to be granted implementation or not, based on a set of predefined rules.” — page 8 · Process roles · Accountability
  • “Acceptable: AI solutions are governed according to their risk levels in adherence to internal and external requirements and only approved AI technologies and third-party solutions are considered for development, deployment and utilization.” — page 6 · Principles and guidelines · Governance
  • “The team performs periodic audits and assessments to verify that the AI system complies with relevant regulations, standards, and ethical guidelines. The team also conducts periodic risk assessments to identify and mitigate potential risks associated with the AI system.” — page 14 · Review & evaluation · Governance
C4

Risk-Based Responsible AI Control

Partial

AI use cases are classified by risk and autonomy, with oversight, disclosure, logging, and accountability tied to risk level.

AI Reasoning

Final maturity assessment: Partial. Evidence-check resolved the scanner score from 2 to 1 after a targeted rescan. Verifier status: weak. Risk classification and applicable law/regulation identification are supported by src-003-p010-c014/page 10, and risk-level governance is supported by src-003-p006-c008/page 6. The wider rubric elements around autonomy tiers, disclosure/logging tied to risk level, and explicit high-risk production blocking are only partially evidenced, though page 12 in fallback/source material also states the AI Board may approve deployment or request further development after residual risk assessment. A score of 2 is supportable but not higher.

Evidence
  • “AI System Owner / Team shall also define AI System risk classification and identification of applicable laws and regulations. ... The AI Board is responsible for validating the AI system proposal for design and development. ... The AI Board assesses the feasibility, potential risks, and benefits of the proposed system before giving green light for further development.” — page 10 · AI system qualification & registration · Governance
  • “Acceptable: AI solutions are governed according to their risk levels in adherence to internal and external requirements and only approved AI technologies and third-party solutions are considered for development, deployment and utilization.” — page 6 · Principles and guidelines · Governance
C5

Evidence-Based AI Investment Portfolio

NOK

AI investment decisions use evidence about impact, risk, readiness, AI budgeting, forecasting, spend guardrails, value-vs-cost, and learning value to kill, continue, scale, or pivot.

AI Reasoning

Crit 1: Not found — no portfolio logic, budgeting, forecasting, or spend guardrails described. Crit 2: Not found — no kill/continue/scale/pivot decision framework based on value-vs-cost evidence. Crit 3: Not found — no evidence of pilot learning feeding back into portfolio reprioritization. Total: 0.

D · Data Foundations, Ownership & Accessibility

D1

Domain-Owned AI Data Products

NOK

Critical AI data is owned by service areas or domains that understand meaning, quality, lifecycle, and usage expectations.

AI Reasoning

Final maturity assessment: NOK. Evidence-check resolved the scanner score from 0 to 0 after a targeted rescan. Verifier status: supported. The source supports a zero score. It defines AI System Owner accountability at AI-system level and requires registration of data used and linkage to the AI system, but it does not evidence domain-owned AI data products, business-domain data owners, or published data products with definitions, context, access rules, and usage expectations.

D2

Context-Rich AI-Ready Data

NOK

Data carries semantic context, service meaning, process linkage, operational conditions, and decision relevance so AI systems can use it as contextual fuel.

AI Reasoning

Crit 1: Not found - no mention of semantic context, source meaning, service/business process linkage, or operational conditions enriched in data. Crit 2: Not found - no evidence that AI systems can understand what values mean in service context beyond raw values. Crit 3: Not found - no mapping of critical data elements to decisions, triggers, workflows, Jobs-to-Be-Done, or customer outcomes. Total: 0.

D3

Data Quality & Lineage Control

NOK

AI-critical data is cataloged, versioned, quality-checked, freshness-monitored, readiness-level assessed, and traceable across training, retrieval, inference, and decisions.

AI Reasoning

Final maturity assessment: NOK. Evidence-check resolved the scanner score from 1 to 0 after a targeted rescan. Verifier status: weak. The limited score is supported. Page 11 explicitly describes data cleaning, normalization, augmentation, and representative datasets for training/testing, and the page 9 process figure refers to management of data quality and usage limitations. However, the source does not evidence cataloging, versioning, readiness-level assessment, freshness monitoring, or lineage tracing across training, retrieval, inference, and decisions.

D4

Governed AI Data Access

Partial

AI data access is role-based, auditable, purpose-limited, privacy-aware, and aligned with service or domain ownership.

AI Reasoning

Crit 1: Partially met - Privacy Policy referenced as mandatory and privacy principles stated, but no explicit documentation of data classification, purpose limitation, or access rights for AI data. Crit 2: Not found - no description of role-based, auditable access to AI data aligned with domain ownership. Crit 3: Not found - masking, anonymization, minimization, and boundary controls are not explicitly described as operational practices. Total: 1.

Evidence
  • “Respect and privacy: Users and their data are treated with dignity and respect. The rights of individuals to access, manage, and control the data they generate, as well as to decide on the purposes for which data is used are secured and safeguarded.” — 3.2 Principles and guidelines · Governance
  • “all data associated with the AI system is either archived or deleted, depending on the organizations or customer's data retention policies and regulatory requirements. This ensures that sensitive information is handled responsibly, and that data privacy is maintained.” — 5.1.8 Retire AI system · Governance
D5

Reusable AI Data Access Patterns

NOK

Structured, unstructured, real-time, batch, feature, retrieval, embedding, vector-store, and event-stream patterns are governed, reusable, and observable for context growth and retrieval cost.

AI Reasoning

Crit 1: Not found - no mention of structured, unstructured, real-time, batch, feature, or retrieval patterns for AI use. Crit 2: Not found - no mention of RAG, embedding, search, feature-store, or event-stream patterns being governed or made reusable. Crit 3: Not found - no measurement of retrieval quality, source coverage, freshness, grounding, context growth, embedding/vector-store duplication, or retrieval cost. Total: 0.

E · Business Capability & Service Architecture

E1

AI-Anchored Service & Capability Architecture

NOK

AI opportunities are mapped to service catalog, capabilities, customer paths, value streams, dependencies, platforms, data domains, and outcomes before solution design.

AI Reasoning

Crit 1: No service catalog, capability map, or equivalent model of value creation is present in any document. Crit 2: No mapping of AI opportunities to services, capabilities, customer paths, or value streams is found. Crit 3: No visibility of dependencies between capabilities, platforms, data, and service outcomes. Total: 0.

E2

AI-Ready Service Blueprinting

NOK

Target services are blueprinted end-to-end so AI interventions improve the whole value stream, surface handoff risks, and avoid local task optimization.

AI Reasoning

Crit 1: No end-to-end service mapping across customer journey, frontstage, backstage, systems, data, and handoffs. Crit 2: No bottlenecks, decision points, air gaps, failure modes, or automation candidates visible as a blueprint exercise. Crit 3: No evidence of AI interventions placed to improve whole value streams rather than local tasks. Total: 0.

E3

Traceable AI Solution Structure

NOK

AI-enabled features are traceable from impact statement, customer need, business outcome, and cost-to-serve to capability, cognitive model, component, data, platform, risk, and work package.

AI Reasoning

Final maturity assessment: NOK. Evidence-check resolved the scanner score from 1 to 0 after a targeted rescan. Verifier status: weak. The quoted registration requirement is present on page 9 and is reinforced on page 10. It supports partial traceability through description, purpose, business objectives, data linkage, risk classification, and applicable laws. It does not evidence full decomposition into impact statement, capability, cognitive model, component, platform, work package, cost-to-serve, or service architecture layers.

E4

Service Area Ownership of AI Value Creation

NOK

Integrated service-area teams own business, application, data, AI, and operational outcomes end to end.

AI Reasoning

Final maturity assessment: NOK. Evidence-check resolved the scanner score from 1 to 0 after a targeted rescan. Verifier status: weak. The quote is real and supports lifecycle accountability for an AI System Owner through retirement. However, the criterion is specifically about integrated service-area teams owning business, application, data, AI, and operational outcomes end-to-end. The source does not evidence service-area team ownership, platform teams as enablers, or AI solutions as living products within service areas.

E5

Phased AI Scaling Through Service Areas

NOK

AI scales from Kickstart learning into Building-the-System rollout through service-area readiness, reusable patterns, platform capabilities, guardrails, feedback loops, cost-to-serve awareness, and reassessment.

AI Reasoning

Crit 1: No evidence of scaling sequenced by service-area readiness, architectural clarity, data readiness, risk level, or cost-to-serve readiness. Crit 2: No pilot-to-playbook conversion, templates, platform capabilities, guardrails, or absorption-readiness evidence. Crit 3: No Sense and Respond loops, retrospectives, readiness reassessment, or value realization review built into a rollout process. Total: 0.

Forensic Audit: Anti-Patterns

A · Adaptive Operating Model

A1

AI Decision Fog & Governance Fat

Tested absent

AI decisions stall or repeat across forums because ownership, decision rights, and escalation boundaries are unclear.

AI Reasoning

Final anti-pattern assessment: Tested absent. Evidence-check resolved the scanner score from 0 to 0 after a targeted rescan. Verifier status: supported. The AI Governance Process directly defines roles, lifecycle gates, AI Board responsibilities, escalation/reporting points, and ownership. It does not evidence delayed decisions, repeated approvals causing stalls, or unclear escalation boundaries. The zero anti-pattern score is supported. Coverage interpretation: The source has relevant coverage of AI decision roles and governance flow, so harmful decision fog would likely appear in the documented model if it were designed into the process. Actual operational decision delays are not independently evidenced.

A2

One-Size-Fits-All AI Delivery

Not assessed

All AI initiatives are forced through the same delivery model regardless of uncertainty, risk, demand type, value profile, cost profile, or learning need.

AI Reasoning

Final anti-pattern assessment: Not assessed. Evidence-check resolved the scanner score from 0 to 0. Verifier status: supported. The source does not show that all AI initiatives are forced through the same delivery model, nor does it show exploratory work being managed with rigid plans. A common governance lifecycle is documented, but that is not sufficient evidence of a one-size-fits-all delivery anti-pattern. Coverage interpretation: The source is mainly governance-process documentation and is largely silent on delivery model differentiation, demand routing, and how exploratory versus predictable AI work is actually managed.

A3

Pilot Purgatory

Tested absent

AI pilots remain disconnected from production, service-area ownership, safety evidence, reusable platform capabilities, and measurable business outcomes.

AI Reasoning

Final anti-pattern assessment: Tested absent. Evidence-check resolved the scanner score from 0 to 0 after a targeted rescan. Verifier status: supported. The documented lifecycle connects AI system identification, registration, design, validation, deployment, monitoring, review, and retirement. It also assigns ownership and requires verification, deployment approval, monitoring, feedback, and metrics. No harmful pilot-purgatory evidence is present. Coverage interpretation: The AI Governance Process directly covers pilot-to-production governance, lifecycle ownership, validation, monitoring, and review, so disconnected pilots would likely be visible in the documented process design. Actual execution outcomes are not proven by this source.

A4

Fragmented AI Knowledge & Hero Culture

Not assessed

AI knowledge is concentrated in isolated experts, repeated mistakes, and heroics instead of reusable institutional learning.

AI Reasoning

Final anti-pattern assessment: Not assessed. Evidence-check resolved the scanner score from 0 to 0. Verifier status: supported. The source does not evidence AI knowledge concentrated in isolated experts, repeated mistakes, or dependence on heroes. It also does not provide enough AI learning-flow evidence to prove the opposite. The zero anti-pattern score is supported because no harmful signal is present. Coverage interpretation: The documents are governance/process descriptions and are largely silent on where AI expertise resides, how lessons are institutionalized, or whether teams rely on individual heroes.

A5

Digital Taylorism & Workslop

Not assessed

AI accelerates fragmented tasks but increases hidden review cost, rework cost, checking, coordination, cognitive load, or low-quality output.

AI Reasoning

Final anti-pattern assessment: Not assessed. Evidence-check resolved the scanner score from 0 to 0. Verifier status: supported. The source does not evidence AI being used mainly for fragmented task acceleration, nor does it show increased checking, rework, coordination burden, workslop, or activity/utilization-based measurement. The zero anti-pattern score is supported. Coverage interpretation: The available material does not assess work outcomes, employee experience, review/rework cost, cognitive load, or productivity measurement practices after AI introduction.

B · Enterprise AI Architecture & Platform Readiness

B1

Legacy Labyrinth & Brittle AI Connectivity

Not assessed

AI use cases depend on manual exports, screen scraping, brittle brownfield point integrations, unclear service boundaries, and fragile dependencies.

AI Reasoning

Final anti-pattern assessment: Not assessed. Evidence-check resolved the scanner score from 1 to 0. Verifier status: unsupported. Adjudication: The source mentions tool/framework whitelisting and generic integration with existing systems, but it does not evidence manual exports, screen scraping, brittle point-to-point AI integrations, unclear service boundaries causing failures, or project-by-project fragile connectivity. Coverage interpretation: Coverage is limited to AI governance and deployment process language, not integration architecture detail; it is too thin to support the harmful anti-pattern or a tested absence.

B2

Notebook-to-Production / Prompt-to-Production Chaos

Not assessed

Models, prompts, and agents move into production without versioning, review, reproducibility, or rollback.

AI Reasoning

Final anti-pattern assessment: Not assessed. Evidence-check resolved the scanner score from 1 to 0. Verifier status: unsupported. Adjudication: The source shows an approval-gated AI lifecycle with registration, verification/validation, deployment approval, monitoring, and retirement, but does not evidence uncontrolled model/prompt/agent promotion, manual unversioned prompt changes, irreproducible behavior, or lack of rollback. Coverage interpretation: Coverage is relevant to lifecycle governance but lacks artifact-level release, versioning, rollback, and traceability details; absence of those details is not enough to establish the chaos anti-pattern.

B3

Black-Box AI Operations

Partial finding

AI failures, invisible token spend, unmonitored model usage, static-model drift, hallucinations, retrieval degradation, cost surprises, value erosion, and unsafe outputs are found through complaints or financial surprises rather than Sense & Respond monitoring.

AI Reasoning

Final anti-pattern assessment: Partial finding. Evidence-check resolved the scanner score from 1 to 1. Verifier status: weak. The cited quote is real and traceable to src-003 page 12, and the source also mentions regular reporting, baseline inconsistency notification, and corrective actions. This partly counters the black-box operations anti-pattern. The only weak harmful signal is that the relevant monitoring sections omit token/model spend, cost-per-output, retrieval degradation, groundedness, and value-degradation monitoring. A score of 1 is therefore only weakly supported as a partial observability gap, not as evidence that failures are mainly found through complaints or financial surprises. Coverage interpretation: Relevant monitoring coverage exists and shows some controls, but it omits several AI-specific operational and cost observability areas, leaving a partial harmful-pattern signal.

Evidence
  • “Monitoring includes logging and metrics for tracking performance, accuracy, bias, security, and compliance, enabling timely interventions.” — 5.1.5 Deployment · Operational
B4

Safety Theater & Unbounded Autonomy

Not assessed

Guardrails are trusted without red-team evidence, agents have unclear behavioral limits, and safety reviews happen too late.

AI Reasoning

Final anti-pattern assessment: Not assessed. Evidence-check resolved the scanner score from 1 to 0. Verifier status: unsupported. Adjudication: The source includes human-in-the-loop principles, design-stage risk identification and mitigation planning, and residual-risk review before deployment. It does not evidence safety theater, unbounded autonomy, missing behavioral limits, or safety handled only as a late-stage review. Coverage interpretation: Coverage addresses governance and risk control at a process level but lacks detailed AI safety engineering evidence; this is insufficient to confirm the harmful anti-pattern or fully rule it out.

B5

Tool Fragmentation & Hidden Factory

Not assessed

Every AI project assembles its own stack, tools, model access, embeddings, vector stores, retrieval patterns, governance, monitoring, cost controls, and maintenance burden without shared standards.

AI Reasoning

Final anti-pattern assessment: Not assessed. Evidence-check resolved the scanner score from 0 to 0. Verifier status: supported. The provided sources do not evidence every project building its own AI stack, disconnected tool buying, duplicate spend, or fragmentation-driven maintenance debt. The scanner's zero score is supported by lack of anti-pattern evidence in the supplied material. Coverage interpretation: The source material is mostly governance/process documentation and is not sufficient to test for or rule out platform fragmentation across actual AI delivery teams.

C · AI Strategy, Governance & Value Realization

C1

AI Slogan Strategy

Not assessed

AI is treated as a generic transformation slogan without strategic choices, value boundaries, or prioritization logic.

AI Reasoning

Final anti-pattern assessment: Not assessed. Evidence-check resolved the scanner score from 0 to 0 after a targeted rescan. Verifier status: supported. No source evidence shows AI being treated as a slogan, everything being labeled an AI priority, or tool adoption preceding value definition. The AI governance process provides some counter-signals, including evaluation against business goals/customer needs and tool whitelisting before use. Coverage interpretation: The governance process is relevant but not a comprehensive strategy or portfolio artifact, so it does not fully test whether slogan-like AI strategy exists elsewhere.

C2

Use-Case Chasing & Vanity Benefits

Not assessed

AI initiatives are selected for visibility, fashion, tool adoption, token/model spend, or cost/TCO claims, with benefits asserted without baselines, measurement, unit economics, or enterprise impact.

AI Reasoning

Final anti-pattern assessment: Not assessed. Evidence-check resolved the scanner score from 0 to 0. Verifier status: supported. The provided sources do not contain evidence of fashion-driven use-case selection, unsupported ROI/savings claims, or celebration of spend/pilots without enterprise impact. Coverage interpretation: The source material is mainly governance/process documentation and does not cover the actual AI initiative portfolio, benefit claims, or post-release value reporting; therefore absence is not fully testable.

C3

Rigid Gatekeeping Governance

Not assessed

AI governance slows flow without improving safety, leaving teams unclear how to proceed or incentivizing shadow AI.

AI Reasoning

Final anti-pattern assessment: Not assessed. Evidence-check resolved the scanner score from 1 to 0. Verifier status: unsupported. Adjudication: The source shows structured governance controls such as tool whitelisting, AI Board validation, and sourcing/legal review, but it does not show that these controls create harmful rigidity, delay delivery, reduce safety effectiveness, or drive teams to bypass governance. Coverage interpretation: Coverage is process-design oriented rather than operational. It describes approval steps and responsibilities, but provides no evidence about actual flow friction, shadow AI behavior, unclear pathways, or governance being disconnected from business or architecture realities.

C4

Unclassified Risk & Ambiguous Accountability

Partial finding

AI use cases launch without risk classification, accountable owners, human override, escalation, or appeal mechanisms.

AI Reasoning

Final anti-pattern assessment: Partial finding. Evidence-check resolved the scanner score from 1 to 1. Verifier status: weak. The source strongly counters part of this anti-pattern by requiring risk classification and assigning an AI System Owner accountable for performance and compliance until retirement. However, the governance process does not clearly specify affected-party override, appeal, fallback, or escalation mechanisms, so there is a limited gap signal. The provided quote is real but mostly contextual/countervailing rather than direct evidence of the harmful pattern. Coverage interpretation: Relevant AI governance documentation covers risk classification, accountability, and human-in-loop principles, but lacks explicit override/appeal/fallback mechanisms; this supports only a partial anti-pattern signal.

Evidence
  • “AI System Owner... Accountable for the AI System and its performance and compliance until retirement.” — 4.1 Process roles · Accountability
C5

AI Investment Drift

Not assessed

The AI portfolio, platform usage, pilot estate, and AI spend grow without capacity, readiness, value proof, learning logic, budget guardrails, or willingness to stop weak initiatives.

AI Reasoning

Final anti-pattern assessment: Not assessed. Evidence-check resolved the scanner score from 0 to 0. Verifier status: supported. No evidence in the provided sources shows uncontrolled AI backlog/spend growth, sunk-cost continuation of weak initiatives, or platform/tool expansion without value validation. Coverage interpretation: The source material does not meaningfully cover AI spend, portfolio dynamics, backlog growth, or investment governance, so absence of the anti-pattern cannot be confirmed from this packet alone.

D · Data Foundations, Ownership & Accessibility

D1

Ownerless Data & Context Loss

Not assessed

Data ownership is centralized, undefined, or detached from business meaning, leaving AI teams to guess context.

AI Reasoning

Final anti-pattern assessment: Not assessed. Evidence-check resolved the scanner score from 0 to 0 after a targeted rescan. Verifier status: supported. The zero anti-pattern score is supported. The source does not evidence centralized or undefined data ownership causing context loss, AI teams guessing dataset meaning, or AI use cases stalling because nobody owns interpretation or correction. The AI System Owner role is system-level and does not prove domain data ownership, but it also does not prove the harmful pattern. Coverage interpretation: The available documents are AI governance and process governance specifications. They provide limited system-level ownership coverage but insufficient coverage of actual enterprise data ownership practices, so absence of this anti-pattern is not testable.

D2

Raw Data Without Meaning

Not assessed

AI systems receive available raw data without semantic richness, service context, process linkage, operational conditions, or decision relevance.

AI Reasoning

Final anti-pattern assessment: Not assessed. Evidence-check resolved the scanner score from 0 to 0. Verifier status: supported. The zero anti-pattern score is supported. The source does not show that data is collected merely because it is available, that models receive raw signals without context, or that outputs are unreliable because a semantic/business meaning layer is missing. Coverage interpretation: The source discusses governance-stage data preparation and quality at a high level, but does not provide enough operational detail about AI datasets or model inputs to prove the harmful pattern is absent.

D3

Data Swamp & Broken Lineage

Not assessed

AI outputs rely on stale copies, undocumented transformations, unknown origins, and unprovable data quality.

AI Reasoning

Final anti-pattern assessment: Not assessed. Evidence-check resolved the scanner score from 0 to 0. Verifier status: supported. The zero anti-pattern score is supported. The source does not evidence stale copies, manual files, undocumented transformations, unknown data origins, unprovable quality, or quality failures discovered only after model or business escalation. Coverage interpretation: Although the governance process includes data quality, testing, monitoring, and documentation activities, it does not provide enough lineage or operational data-flow evidence to test whether data swamp or broken-lineage conditions exist in practice.

D4

Data Leakage & Over-Broad Access

Not assessed

AI tools access sensitive data with unclear purpose, logging, approval, retention, or boundary controls.

AI Reasoning

Final anti-pattern assessment: Not assessed. Evidence-check resolved the scanner score from 1 to 0. Verifier status: unsupported. Adjudication: The source discusses privacy and security principles, protection from unauthorized access and breaches, and data retention, but it does not show over-broad AI data access, uncontrolled experiment copies, missing logging/approval/purpose controls, or controls being added late. Coverage interpretation: Coverage is relevant but high-level; it is sufficient to show governance intent, not sufficient to assess whether the harmful access-control anti-pattern exists or is cleanly absent.

D5

Ad Hoc Retrieval & Duplicate Knowledge Stores

Not assessed

Teams create stale, incomplete, duplicate, costly, or unowned RAG, embedding, vector-store, feature, and knowledge stores.

AI Reasoning

Final anti-pattern assessment: Not assessed. Evidence-check resolved the scanner score from 0 to 0. Verifier status: supported. The zero anti-pattern score is supported. The source is silent on RAG, embeddings, vector stores, duplicate knowledge stores, feature stores, retrieval failures, context growth, and duplicated retrieval costs; therefore there is no evidence of the harmful pattern. Coverage interpretation: The available source material does not cover retrieval or knowledge-store architecture, so absence of this anti-pattern is not testable from the provided documents.

E · Business Capability & Service Architecture

E1

AI Ideas Detached from Business Architecture

Partial finding

AI use cases are listed without linkage to service catalog, capability map, value stream, service-area ownership, data domain, or dependency structure.

AI Reasoning

Final anti-pattern assessment: Partial finding. Evidence-check resolved the scanner score from 1 to 1. Verifier status: weak. The quote is present and shows AI ideas are evaluated against business goals, technological possibilities, and customer needs. The harmful-pattern signal is mainly an omission: the intake/registration process does not require linkage to a service catalog, capability map, value stream, or service-area ownership model. This is a partial design-level signal, not direct evidence from an actual use-case list. Coverage interpretation: The AI governance process is relevant to AI intake and registration, so omission of service/capability architecture linkage is meaningful. However, the source does not provide actual AI use-case inventories or implementation records, so the anti-pattern cannot be fully confirmed.

Evidence
  • “This stage gathers ideas for AI systems, whether initiated from within the organization or proposed by external customers. It includes evaluating these concepts based on their alignment with business goals, technological possibilities, and customer needs.” — 5.1.1 AI system identification · Process
E2

Spot Optimization & Silo Automation

Not assessed

AI speeds isolated tasks while increasing downstream rework, coordination, or poor customer/service flow.

AI Reasoning

Final anti-pattern assessment: Not assessed. Evidence-check resolved the scanner score from 0 to 0. Verifier status: supported. No source evidence shows AI being applied to isolated tasks, creating downstream rework, or ignoring customer experience/end-to-end flow. The documents are governance/process documents and do not provide operational examples of AI automation design. Coverage interpretation: The available documents are not service-flow or implementation evidence and would not reliably reveal spot optimization or silo automation if it existed.

E3

Untraceable AI Build Logic

Partial finding

AI components are built without clear linkage to capability, customer need, data source, platform dependency, value outcome, or cost-to-serve where evidence exists.

AI Reasoning

Final anti-pattern assessment: Partial finding. Evidence-check resolved the scanner score from 1 to 1. Verifier status: weak. The quote is present and shows partial traceability controls: description, purpose, business objectives, data linkage, risk classification, and applicable laws. The harmful-pattern finding is only partially supported because the process omits explicit capability, feature, platform dependency, value outcome, cost-to-serve, and work-package traceability, but it does not show teams actually building AI components with vague or tool-led requirements. Coverage interpretation: The governance process has relevant coverage of registration and pre-build controls. It partially mitigates untraceable build logic, while still leaving traceability gaps at capability/platform/value/cost layers.

Evidence
  • “The AI System Owner / Team is responsible for the AI System registration, including description, purpose and business objectives. Description of data used with linkage to the AI System. AI System Owner / Team shall also define AI System risk classification and identification of applicable laws and regulations.” — 5.1.2 AI system qualification & registration · Process
E4

Disconnected AI Project Teams

Not assessed

AI teams are separated from service areas and ownership disappears after pilots, vendors, or temporary projects.

AI Reasoning

Final anti-pattern assessment: Not assessed. Evidence-check resolved the scanner score from 0 to 0 after a targeted rescan. Verifier status: supported. The source defines an accountable AI System Owner through retirement, which counters the specific pattern of ownership disappearing after pilot/vendor delivery. It does not provide enough service-area organizational structure evidence to test whether AI teams are disconnected from service areas or whether work is split into sequential handoffs. Coverage interpretation: Lifecycle ownership is covered, but team topology relative to service areas is not sufficiently covered to confirm absence of disconnected AI project teams.

E5

Big-Bang AI Transformation

Not assessed

AI is scaled broadly before Kickstart learning proves service readiness, architecture, data ownership, safety, cost-to-serve readiness, and operating model patterns.

AI Reasoning

Final anti-pattern assessment: Not assessed. Evidence-check resolved the scanner score from 0 to 0. Verifier status: supported. No evidence shows broad AI rollout before readiness, failure to convert pilot learning into reusable patterns, or repeated independent mistakes across service areas. The source addresses lifecycle governance for individual AI systems, not enterprise scaling behavior. Coverage interpretation: The available source is silent on scaling strategy, rollout sequencing, service-area adoption, and pilot-to-pattern conversion, so absence of the big-bang anti-pattern is not testable.

Quality & Strategy Hygiene Appendix

Quality Gate detail is retained here for traceability. WARN-level strategy hygiene notes do not invalidate the assessment score.

Reviewer Summary · gpt-5.5

The assessment is blocked because evidence density is below the minimum floor, so the maturity reading is not sufficiently grounded in the source material. Strategy hygiene notes were retained for traceability; they do not invalidate the score, but the evidence-density block does.

Blocking
Sanitized strategy items
Evidence-check adjustments
Strategy hygiene notes
Remaining warnings
Remaining fact-check notes