Assessment is unsafe to act on until blocking issues are resolved.
Phase 1 findings were verified against the raw material before Phase 2 metrics were calculated.
Parsed source material was split into deterministic chunks and routed into A-E context packets. Packets guide model attention; they are not proof by themselves.
Evidence density 16% is below the 30% floor, so readiness is capped by available evidence.
Share of the 25 maturity criteria that scored as fully embedded (3 of 3 sub-criteria met).
Average maturity score across all 25 criteria on a 0–3 scale, normalized to 0–100%. Captures partial progress that maturity_ratio misses.
Share of the 25 anti-patterns scored as deeply entrenched (3 of 3 sub-criteria met). Higher = worse.
Average severity across all 25 anti-patterns. Higher = more friction blocking current AI Transformation practice. Low values mean "low confirmed burden" only when source evidence is strong enough.
Share of anti-patterns that were meaningfully tested and not found. This is positive only when the source had relevant coverage.
Share of anti-pattern criteria that were meaningfully assessed, either as findings or verified absences. Low coverage means absence is unknown, not good.
Did the audit pipeline complete? Share of 50 criteria the LLM returned valid data for. Below 100% means batches failed.
Did the source actually cover the criterion? Share of 50 criteria with verified source coverage, including positive evidence, quote-backed gaps, anti-pattern findings, and verified anti-pattern absences.
Per-domain maturity (emerald) vs anti-pattern burden (rose). Each axis is one of the five batches; values are the sum of sub-criterion counts (0–15) for that batch.
Validated maturity depth (x-axis) plotted against confirmed anti-pattern burden (y-axis). When evidence or anti-pattern coverage is insufficient, quadrant labels are suppressed.
Fact-only current state · Insufficient evidence
The internal reference material process document confirms that a structured lifecycle framework exists on paper — covering identification, qualification, the assessed organization, the assessed organization, monitoring, review, the assessed organization the assessed organization — with named roles including an AI Board, AI System Owner, the assessed organization internal reference material Lead. Three KPIs are listed: AI system the assessed organization, documented use cases, the assessed organization a governance tool library.
What is missing: The audit could not confirm any of the following: whether the governance process has been activated for any live AI system; whether any AI system has completed qualification the assessed organization registration; whether pilots have been run, reviewed, or produced learning artefacts; whether service-area ownership of AI work exists in practice; whether data quality, data ownership, or data product accountability has been established; whether AI demand is the assessed organization routed by uncertainty, value, or risk; whether value measurement or impact statements exist for any AI initiative; the assessed organization whether security red-teaming or human-escalation controls have been exercised.
What is needed before a directive roadmap can be written: The next assessment cycle should include: evidence of at least one AI system that has passed through the qualification the assessed organization registration gate; operating rhythm artefacts such as AI Board meeting records or review minutes; pilot learning documentation; service-area AI ownership assignments; the assessed organization data readiness or data product evidence tied to at least one AI use case.
Confidence Notes — Unverified Claims
The following statements could not be verified against the source after 1 regenerate pass(es). Treat with caution.
What the audit found: The submitted documents indicate that a formal internal reference material lifecycle has been defined the assessed organization approved, with stated objectives that include customer value, fairness, transparency, the assessed organization regulatory compliance. Roles are specified for customer-facing responsibilities, including a Customer the assessed organization accountable for requirements gathering, the assessed organization approval, the assessed organization the assessed organization sign-off. Three governance KPIs are listed. However, the evidence density is 16% the assessed organization the readiness score is 3 out of 100, meaning the audit cannot confirm that any of these process commitments have been activated within a real service area or customer engagement. The the assessed organization is provisionally insufficient evidence.
What is missing: The audit found no evidence of AI opportunities tied to specific service outcomes or customer journeys; no service blueprints or value-stream maps showing where AI intervenes in customer-facing work; no pilot results, adoption data, or customer the assessed organization from any deployed AI system; no Impact Statements or business cases connecting AI investments to measurable service or outcome improvement; the assessed organization no indication of how work has been redesigned — rather than simply accelerated — in any service area.
What is needed before a directive roadmap can be written: Service-area owners should supply: at least one active AI use case with a documented business case or Impact Statement; customer journey or service blueprint evidence showing where AI is or will be applied; pilot outcome data or learning review records; the assessed organization articulation of how quality the assessed organization value will be measured post-launch for any AI-enabled service.
What the audit found: A formally approved internal reference material process document (Version 1.0A, September 2025) describes a lifecycle model spanning eight phases, with process roles, a the assessed organization table, the assessed organization references to alignment with AI Policy, GDPR, AI Act, the assessed organization ISO standards. The overall score is 3 out of 100 with evidence density at 16%, the assessed organization 21 silent criteria areas returned no assessable evidence. The maturity the assessed organization is insufficient evidence.
What is missing: The audit could not confirm: whether any AI platform or infrastructure has been built or integrated; whether data products, data ownership, or data quality controls exist; whether prompt, model, or tool versioning is operationally active; whether observability or evaluation tooling is deployed; whether security controls, red-teaming, or agent behavioral boundaries have been tested; whether the internal reference material tool library referenced in the the assessed organization table exists the assessed organization is populated; the assessed organization whether the governance process has been applied to any system currently in production or pilot.
What is needed before a directive roadmap can be written: The next assessment cycle should include: evidence of at least one AI system registered in the governance tool library; architecture documentation for any AI platform or integration layer; data lineage or data product artefacts; monitoring the assessed organization observability configuration evidence; the assessed organization security or red-the assessed organization assessment records tied to any AI system under development or in operation.
Interpretation of evidence — not the implementation plan
The audit cannot identify a primary bottleneck with confidence. The provisional interpretation is that a governance framework has been designed but there is no assessable evidence that it has been put into practice across any domain — strategy, data, platform, service ownership, or value realization.
Confidence (low): Evidence density is 16%, below the 30% floor required for reliable scoring. Twenty-one criteria areas are silent. The sole readable source is a single governance process document with no activation evidence. The scanned PDF contributed zero assessable content. A diagnosis cannot be drawn with confidence from this evidence base.
Evidence does not support a directive roadmap yet.
To strengthen the next assessment cycle, include the following kinds of evidence in the source document.
other
Evidence in the source did not support a directive roadmap. This section reports what the audit can confirm and what additional material is needed before a confident strategy can be written.
The organization connects AI strategy, demand intake, delivery, learning, and governance through a visible operating rhythm with clear decision ownership.
Final maturity assessment: NOK. Evidence-check resolved the scanner score from 1 to 0 after a targeted rescan. Verifier status: weak. The cited role and lifecycle evidence is present in the AI Governance Process. It supports limited maturity around AI lifecycle ownership and governance roles, but not a full AI operating rhythm with cadence, backlog movement, learning loops, or traceable decision logs. The score of 1 is appropriately conservative.
AI work is routed through the operating model by work nature, value, uncertainty, risk, cost profile, capacity, competence, and service ownership instead of using one delivery model for every initiative.
Crit 1: No evidence of AI demand classification by nature of work. Crit 2: No evidence of separate delivery paths for predictable vs. uncertain AI demands. Crit 3: No evidence of routing connected to capacity, competence, value hypothesis, cost profile, or risk level. Total: 0. The source documents are an AI Governance Process, a Process Governance Management Process, and a Decision-Making Authority Policy - none address demand routing for AI work.
The organization de-risks AI transformation through Kickstart validation, bounded vertical slices, evidence-based business cases, and explicit conversion into Building-the-System scaling patterns.
Crit 1: No evidence of bounded vertical slices, Kickstart use cases, or safe experiments tied to service-area impact statements. Crit 2: No evidence of pilot learnings being captured and used to refine operating model, architecture, data, governance, safety, and value assumptions. Crit 3: No defined transition from Kickstart validation to Building-the-System scaling, no pilot playbook or absorption-readiness map. Total: 0.
AI knowledge flows through communities, chapters, guilds, and reusable practice rather than remaining isolated in experts or pilot teams.
Crit 1: No evidence of communities, chapters, guilds, or equivalent structures for AI learning. Crit 2: No evidence of lessons from AI pilots, failures, red teaming, or incidents being converted into reusable practices. Crit 3: No evidence of business, AI, data, platform, and service teams learning together about AI. Total: 0.
AI initiatives redesign work, handoffs, roles, review cost, rework cost, and feedback loops so human capacity moves toward higher-value contribution.
Crit 1: No evidence that AI initiatives are designed to reallocate human capacity toward higher-value work. Crit 2: No evidence of roles, handoffs, review points, exception paths, or human-in-the-loop responsibilities being redesigned. Crit 3: No evidence of measuring employee experience, cognitive load, review/rework cost, quality, or customer impact after AI introduction. Total: 0.
AI systems integrate through reliable service boundaries, brownfield-compatible APIs, events, and governed connectors with documented ownership and failure modes.
Final maturity assessment: NOK. Evidence-check resolved the scanner score from 0 to 0 after a targeted rescan. Verifier status: supported. The cited quotes are present in the source: deployment mentions integrating with existing systems in src-003 page 12, and tool/framework whitelisting appears in src-003 page 9. However, the source does not evidence APIs, service boundaries, events, governed connectors, brownfield wrapping, integration versioning, dependency mapping, ownership, or failure modes. A score of 0 is supported.
Models, prompts, agents, tools, datasets, and evaluation suites are versioned and released through controlled lifecycle practices.
Final maturity assessment: NOK. Evidence-check resolved the scanner score from 1 to 0 after a targeted rescan. Verifier status: weak. The source supports a governed AI lifecycle with registration, validation, deployment, monitoring, review, and retirement phases, including AI Board approvals and documented decommissioning. The cited quotes are traceable to src-003 pages 9, 12, and 14. The source does not show artifact versioning, rollback, or traceability from production behavior to model/prompt/data/tool/release versions, so a limited score of 1 is supported.
Production AI behavior is monitored through a Sense & Respond loop for quality, safety, token/model spend, latency, routing performance, retrieval cost, cost-per-output, groundedness, drift, and business impact.
Final maturity assessment: NOK. Evidence-check resolved the scanner score from 1 to 0 after a targeted rescan. Verifier status: weak. The source supports partial AI monitoring: logging and metrics for performance, accuracy, bias, security, compliance, defined metrics, feedback, baseline inconsistency notification, and corrective actions are present in src-003 pages 9, 12, 13, and 14. It does not evidence the broader observability stack required by the rubric, such as token/model spend, latency, routing, retrieval cost, cost-per-output, groundedness, business impact, defined offline/online evaluations, or explicit threshold-triggered retraining workflows. Score 1 is supported.
Trust and safety controls are embedded Secure-by-Design into AI workflows, including red teaming, guardrails, access controls, human escalation, and adversarial testing.
Final maturity assessment: NOK. Evidence-check resolved the scanner score from 1 to 0. Verifier status: weak. The cited human-in-the-loop and reliability/security language is present in src-003 page 4, and the broader process includes risk classification, mitigation, and residual risk assessment. However, this is only adjacent evidence for the Secure-by-Design trust and safety layer. The source does not evidence red-teaming, prompt-injection testing, adversarial testing, guardrails, filters, embedded access controls, formal escalation paths, or an Agent Behavioral Contract. The low score of 1 is plausible only as a weak partial signal, not as full criterion satisfaction.
Reusable AI platform products provide shared model access, model routing, caching, quotas, budget alerts, data patterns, deployment templates, observability, evaluation, and cost-aware developer experience.
Crit 1: Not found — no shared AI platform products, model gateways, or reusable MLOps/LLMOps described. Crit 2: Not found — no platform team accountability to service-area teams as internal customers. Crit 3: Not found — no measurement of platform adoption, flow, reliability, or value enablement. The source documents are a governance process and a process management process, which are single-purpose and would not be expected to cover platform product capabilities. Total: 0.
AI ambition is connected to strategic purpose, customer value, business model choices, and explicit boundaries for where AI should not be used.
Crit 1: Partially met — the governance process references alignment with 'business goals' and 'customer needs' but does not articulate a clear strategic narrative for why AI matters to the business model or customer value proposition. Score 1 at most. Crit 2: Not found — no connection of AI ambition to specific service areas, value streams, or strategic domains. Crit 3: Not found — no explicit where-not-to-use-AI boundaries defined. Total: 1.
AI initiatives start from impact statements and value hypotheses, with evidence-based business cases, baseline and post-release measurement, unit economics, and value metrics beyond cost reduction.
Crit 1: Not found — no evidence of AI initiatives starting from impact statements rather than tool ideas. Crit 2: Not found — no outcome metrics, unit economics, or value metrics defined. Crit 3: Not found — no value hypothesis testing, pilot review, or kill/continue/scale decision logic. Total: 0.
AI governance is embedded into ownership, architecture, security, data, service operations, and auditability as an enabling system.
Final maturity assessment: Partial. Evidence-check resolved the scanner score from 2 to 1 after a targeted rescan. Verifier status: weak. The role/accountability quote is supported by src-003-p008-c011/page 8, the risk-level/approved-technology principle by src-003-p006-c008/page 6, and periodic audit/risk assessment language by src-003-p014-c022/page 14. These support embedded governance roles and auditable controls. The evidence is weaker on governance being explicitly flow-enabling rather than gate-oriented, so 2 is appropriate.
AI use cases are classified by risk and autonomy, with oversight, disclosure, logging, and accountability tied to risk level.
Final maturity assessment: Partial. Evidence-check resolved the scanner score from 2 to 1 after a targeted rescan. Verifier status: weak. Risk classification and applicable law/regulation identification are supported by src-003-p010-c014/page 10, and risk-level governance is supported by src-003-p006-c008/page 6. The wider rubric elements around autonomy tiers, disclosure/logging tied to risk level, and explicit high-risk production blocking are only partially evidenced, though page 12 in fallback/source material also states the AI Board may approve deployment or request further development after residual risk assessment. A score of 2 is supportable but not higher.
AI investment decisions use evidence about impact, risk, readiness, AI budgeting, forecasting, spend guardrails, value-vs-cost, and learning value to kill, continue, scale, or pivot.
Crit 1: Not found — no portfolio logic, budgeting, forecasting, or spend guardrails described. Crit 2: Not found — no kill/continue/scale/pivot decision framework based on value-vs-cost evidence. Crit 3: Not found — no evidence of pilot learning feeding back into portfolio reprioritization. Total: 0.
Critical AI data is owned by service areas or domains that understand meaning, quality, lifecycle, and usage expectations.
Final maturity assessment: NOK. Evidence-check resolved the scanner score from 0 to 0 after a targeted rescan. Verifier status: supported. The source supports a zero score. It defines AI System Owner accountability at AI-system level and requires registration of data used and linkage to the AI system, but it does not evidence domain-owned AI data products, business-domain data owners, or published data products with definitions, context, access rules, and usage expectations.
Data carries semantic context, service meaning, process linkage, operational conditions, and decision relevance so AI systems can use it as contextual fuel.
Crit 1: Not found - no mention of semantic context, source meaning, service/business process linkage, or operational conditions enriched in data. Crit 2: Not found - no evidence that AI systems can understand what values mean in service context beyond raw values. Crit 3: Not found - no mapping of critical data elements to decisions, triggers, workflows, Jobs-to-Be-Done, or customer outcomes. Total: 0.
AI-critical data is cataloged, versioned, quality-checked, freshness-monitored, readiness-level assessed, and traceable across training, retrieval, inference, and decisions.
Final maturity assessment: NOK. Evidence-check resolved the scanner score from 1 to 0 after a targeted rescan. Verifier status: weak. The limited score is supported. Page 11 explicitly describes data cleaning, normalization, augmentation, and representative datasets for training/testing, and the page 9 process figure refers to management of data quality and usage limitations. However, the source does not evidence cataloging, versioning, readiness-level assessment, freshness monitoring, or lineage tracing across training, retrieval, inference, and decisions.
AI data access is role-based, auditable, purpose-limited, privacy-aware, and aligned with service or domain ownership.
Crit 1: Partially met - Privacy Policy referenced as mandatory and privacy principles stated, but no explicit documentation of data classification, purpose limitation, or access rights for AI data. Crit 2: Not found - no description of role-based, auditable access to AI data aligned with domain ownership. Crit 3: Not found - masking, anonymization, minimization, and boundary controls are not explicitly described as operational practices. Total: 1.
Structured, unstructured, real-time, batch, feature, retrieval, embedding, vector-store, and event-stream patterns are governed, reusable, and observable for context growth and retrieval cost.
Crit 1: Not found - no mention of structured, unstructured, real-time, batch, feature, or retrieval patterns for AI use. Crit 2: Not found - no mention of RAG, embedding, search, feature-store, or event-stream patterns being governed or made reusable. Crit 3: Not found - no measurement of retrieval quality, source coverage, freshness, grounding, context growth, embedding/vector-store duplication, or retrieval cost. Total: 0.
AI opportunities are mapped to service catalog, capabilities, customer paths, value streams, dependencies, platforms, data domains, and outcomes before solution design.
Crit 1: No service catalog, capability map, or equivalent model of value creation is present in any document. Crit 2: No mapping of AI opportunities to services, capabilities, customer paths, or value streams is found. Crit 3: No visibility of dependencies between capabilities, platforms, data, and service outcomes. Total: 0.
Target services are blueprinted end-to-end so AI interventions improve the whole value stream, surface handoff risks, and avoid local task optimization.
Crit 1: No end-to-end service mapping across customer journey, frontstage, backstage, systems, data, and handoffs. Crit 2: No bottlenecks, decision points, air gaps, failure modes, or automation candidates visible as a blueprint exercise. Crit 3: No evidence of AI interventions placed to improve whole value streams rather than local tasks. Total: 0.
AI-enabled features are traceable from impact statement, customer need, business outcome, and cost-to-serve to capability, cognitive model, component, data, platform, risk, and work package.
Final maturity assessment: NOK. Evidence-check resolved the scanner score from 1 to 0 after a targeted rescan. Verifier status: weak. The quoted registration requirement is present on page 9 and is reinforced on page 10. It supports partial traceability through description, purpose, business objectives, data linkage, risk classification, and applicable laws. It does not evidence full decomposition into impact statement, capability, cognitive model, component, platform, work package, cost-to-serve, or service architecture layers.
Integrated service-area teams own business, application, data, AI, and operational outcomes end to end.
Final maturity assessment: NOK. Evidence-check resolved the scanner score from 1 to 0 after a targeted rescan. Verifier status: weak. The quote is real and supports lifecycle accountability for an AI System Owner through retirement. However, the criterion is specifically about integrated service-area teams owning business, application, data, AI, and operational outcomes end-to-end. The source does not evidence service-area team ownership, platform teams as enablers, or AI solutions as living products within service areas.
AI scales from Kickstart learning into Building-the-System rollout through service-area readiness, reusable patterns, platform capabilities, guardrails, feedback loops, cost-to-serve awareness, and reassessment.
Crit 1: No evidence of scaling sequenced by service-area readiness, architectural clarity, data readiness, risk level, or cost-to-serve readiness. Crit 2: No pilot-to-playbook conversion, templates, platform capabilities, guardrails, or absorption-readiness evidence. Crit 3: No Sense and Respond loops, retrospectives, readiness reassessment, or value realization review built into a rollout process. Total: 0.
AI decisions stall or repeat across forums because ownership, decision rights, and escalation boundaries are unclear.
Final anti-pattern assessment: Tested absent. Evidence-check resolved the scanner score from 0 to 0 after a targeted rescan. Verifier status: supported. The AI Governance Process directly defines roles, lifecycle gates, AI Board responsibilities, escalation/reporting points, and ownership. It does not evidence delayed decisions, repeated approvals causing stalls, or unclear escalation boundaries. The zero anti-pattern score is supported. Coverage interpretation: The source has relevant coverage of AI decision roles and governance flow, so harmful decision fog would likely appear in the documented model if it were designed into the process. Actual operational decision delays are not independently evidenced.
All AI initiatives are forced through the same delivery model regardless of uncertainty, risk, demand type, value profile, cost profile, or learning need.
Final anti-pattern assessment: Not assessed. Evidence-check resolved the scanner score from 0 to 0. Verifier status: supported. The source does not show that all AI initiatives are forced through the same delivery model, nor does it show exploratory work being managed with rigid plans. A common governance lifecycle is documented, but that is not sufficient evidence of a one-size-fits-all delivery anti-pattern. Coverage interpretation: The source is mainly governance-process documentation and is largely silent on delivery model differentiation, demand routing, and how exploratory versus predictable AI work is actually managed.
AI pilots remain disconnected from production, service-area ownership, safety evidence, reusable platform capabilities, and measurable business outcomes.
Final anti-pattern assessment: Tested absent. Evidence-check resolved the scanner score from 0 to 0 after a targeted rescan. Verifier status: supported. The documented lifecycle connects AI system identification, registration, design, validation, deployment, monitoring, review, and retirement. It also assigns ownership and requires verification, deployment approval, monitoring, feedback, and metrics. No harmful pilot-purgatory evidence is present. Coverage interpretation: The AI Governance Process directly covers pilot-to-production governance, lifecycle ownership, validation, monitoring, and review, so disconnected pilots would likely be visible in the documented process design. Actual execution outcomes are not proven by this source.
AI knowledge is concentrated in isolated experts, repeated mistakes, and heroics instead of reusable institutional learning.
Final anti-pattern assessment: Not assessed. Evidence-check resolved the scanner score from 0 to 0. Verifier status: supported. The source does not evidence AI knowledge concentrated in isolated experts, repeated mistakes, or dependence on heroes. It also does not provide enough AI learning-flow evidence to prove the opposite. The zero anti-pattern score is supported because no harmful signal is present. Coverage interpretation: The documents are governance/process descriptions and are largely silent on where AI expertise resides, how lessons are institutionalized, or whether teams rely on individual heroes.
AI accelerates fragmented tasks but increases hidden review cost, rework cost, checking, coordination, cognitive load, or low-quality output.
Final anti-pattern assessment: Not assessed. Evidence-check resolved the scanner score from 0 to 0. Verifier status: supported. The source does not evidence AI being used mainly for fragmented task acceleration, nor does it show increased checking, rework, coordination burden, workslop, or activity/utilization-based measurement. The zero anti-pattern score is supported. Coverage interpretation: The available material does not assess work outcomes, employee experience, review/rework cost, cognitive load, or productivity measurement practices after AI introduction.
AI use cases depend on manual exports, screen scraping, brittle brownfield point integrations, unclear service boundaries, and fragile dependencies.
Final anti-pattern assessment: Not assessed. Evidence-check resolved the scanner score from 1 to 0. Verifier status: unsupported. Adjudication: The source mentions tool/framework whitelisting and generic integration with existing systems, but it does not evidence manual exports, screen scraping, brittle point-to-point AI integrations, unclear service boundaries causing failures, or project-by-project fragile connectivity. Coverage interpretation: Coverage is limited to AI governance and deployment process language, not integration architecture detail; it is too thin to support the harmful anti-pattern or a tested absence.
Models, prompts, and agents move into production without versioning, review, reproducibility, or rollback.
Final anti-pattern assessment: Not assessed. Evidence-check resolved the scanner score from 1 to 0. Verifier status: unsupported. Adjudication: The source shows an approval-gated AI lifecycle with registration, verification/validation, deployment approval, monitoring, and retirement, but does not evidence uncontrolled model/prompt/agent promotion, manual unversioned prompt changes, irreproducible behavior, or lack of rollback. Coverage interpretation: Coverage is relevant to lifecycle governance but lacks artifact-level release, versioning, rollback, and traceability details; absence of those details is not enough to establish the chaos anti-pattern.
AI failures, invisible token spend, unmonitored model usage, static-model drift, hallucinations, retrieval degradation, cost surprises, value erosion, and unsafe outputs are found through complaints or financial surprises rather than Sense & Respond monitoring.
Final anti-pattern assessment: Partial finding. Evidence-check resolved the scanner score from 1 to 1. Verifier status: weak. The cited quote is real and traceable to src-003 page 12, and the source also mentions regular reporting, baseline inconsistency notification, and corrective actions. This partly counters the black-box operations anti-pattern. The only weak harmful signal is that the relevant monitoring sections omit token/model spend, cost-per-output, retrieval degradation, groundedness, and value-degradation monitoring. A score of 1 is therefore only weakly supported as a partial observability gap, not as evidence that failures are mainly found through complaints or financial surprises. Coverage interpretation: Relevant monitoring coverage exists and shows some controls, but it omits several AI-specific operational and cost observability areas, leaving a partial harmful-pattern signal.
Guardrails are trusted without red-team evidence, agents have unclear behavioral limits, and safety reviews happen too late.
Final anti-pattern assessment: Not assessed. Evidence-check resolved the scanner score from 1 to 0. Verifier status: unsupported. Adjudication: The source includes human-in-the-loop principles, design-stage risk identification and mitigation planning, and residual-risk review before deployment. It does not evidence safety theater, unbounded autonomy, missing behavioral limits, or safety handled only as a late-stage review. Coverage interpretation: Coverage addresses governance and risk control at a process level but lacks detailed AI safety engineering evidence; this is insufficient to confirm the harmful anti-pattern or fully rule it out.
Every AI project assembles its own stack, tools, model access, embeddings, vector stores, retrieval patterns, governance, monitoring, cost controls, and maintenance burden without shared standards.
Final anti-pattern assessment: Not assessed. Evidence-check resolved the scanner score from 0 to 0. Verifier status: supported. The provided sources do not evidence every project building its own AI stack, disconnected tool buying, duplicate spend, or fragmentation-driven maintenance debt. The scanner's zero score is supported by lack of anti-pattern evidence in the supplied material. Coverage interpretation: The source material is mostly governance/process documentation and is not sufficient to test for or rule out platform fragmentation across actual AI delivery teams.
AI is treated as a generic transformation slogan without strategic choices, value boundaries, or prioritization logic.
Final anti-pattern assessment: Not assessed. Evidence-check resolved the scanner score from 0 to 0 after a targeted rescan. Verifier status: supported. No source evidence shows AI being treated as a slogan, everything being labeled an AI priority, or tool adoption preceding value definition. The AI governance process provides some counter-signals, including evaluation against business goals/customer needs and tool whitelisting before use. Coverage interpretation: The governance process is relevant but not a comprehensive strategy or portfolio artifact, so it does not fully test whether slogan-like AI strategy exists elsewhere.
AI initiatives are selected for visibility, fashion, tool adoption, token/model spend, or cost/TCO claims, with benefits asserted without baselines, measurement, unit economics, or enterprise impact.
Final anti-pattern assessment: Not assessed. Evidence-check resolved the scanner score from 0 to 0. Verifier status: supported. The provided sources do not contain evidence of fashion-driven use-case selection, unsupported ROI/savings claims, or celebration of spend/pilots without enterprise impact. Coverage interpretation: The source material is mainly governance/process documentation and does not cover the actual AI initiative portfolio, benefit claims, or post-release value reporting; therefore absence is not fully testable.
AI governance slows flow without improving safety, leaving teams unclear how to proceed or incentivizing shadow AI.
Final anti-pattern assessment: Not assessed. Evidence-check resolved the scanner score from 1 to 0. Verifier status: unsupported. Adjudication: The source shows structured governance controls such as tool whitelisting, AI Board validation, and sourcing/legal review, but it does not show that these controls create harmful rigidity, delay delivery, reduce safety effectiveness, or drive teams to bypass governance. Coverage interpretation: Coverage is process-design oriented rather than operational. It describes approval steps and responsibilities, but provides no evidence about actual flow friction, shadow AI behavior, unclear pathways, or governance being disconnected from business or architecture realities.
AI use cases launch without risk classification, accountable owners, human override, escalation, or appeal mechanisms.
Final anti-pattern assessment: Partial finding. Evidence-check resolved the scanner score from 1 to 1. Verifier status: weak. The source strongly counters part of this anti-pattern by requiring risk classification and assigning an AI System Owner accountable for performance and compliance until retirement. However, the governance process does not clearly specify affected-party override, appeal, fallback, or escalation mechanisms, so there is a limited gap signal. The provided quote is real but mostly contextual/countervailing rather than direct evidence of the harmful pattern. Coverage interpretation: Relevant AI governance documentation covers risk classification, accountability, and human-in-loop principles, but lacks explicit override/appeal/fallback mechanisms; this supports only a partial anti-pattern signal.
The AI portfolio, platform usage, pilot estate, and AI spend grow without capacity, readiness, value proof, learning logic, budget guardrails, or willingness to stop weak initiatives.
Final anti-pattern assessment: Not assessed. Evidence-check resolved the scanner score from 0 to 0. Verifier status: supported. No evidence in the provided sources shows uncontrolled AI backlog/spend growth, sunk-cost continuation of weak initiatives, or platform/tool expansion without value validation. Coverage interpretation: The source material does not meaningfully cover AI spend, portfolio dynamics, backlog growth, or investment governance, so absence of the anti-pattern cannot be confirmed from this packet alone.
Data ownership is centralized, undefined, or detached from business meaning, leaving AI teams to guess context.
Final anti-pattern assessment: Not assessed. Evidence-check resolved the scanner score from 0 to 0 after a targeted rescan. Verifier status: supported. The zero anti-pattern score is supported. The source does not evidence centralized or undefined data ownership causing context loss, AI teams guessing dataset meaning, or AI use cases stalling because nobody owns interpretation or correction. The AI System Owner role is system-level and does not prove domain data ownership, but it also does not prove the harmful pattern. Coverage interpretation: The available documents are AI governance and process governance specifications. They provide limited system-level ownership coverage but insufficient coverage of actual enterprise data ownership practices, so absence of this anti-pattern is not testable.
AI systems receive available raw data without semantic richness, service context, process linkage, operational conditions, or decision relevance.
Final anti-pattern assessment: Not assessed. Evidence-check resolved the scanner score from 0 to 0. Verifier status: supported. The zero anti-pattern score is supported. The source does not show that data is collected merely because it is available, that models receive raw signals without context, or that outputs are unreliable because a semantic/business meaning layer is missing. Coverage interpretation: The source discusses governance-stage data preparation and quality at a high level, but does not provide enough operational detail about AI datasets or model inputs to prove the harmful pattern is absent.
AI outputs rely on stale copies, undocumented transformations, unknown origins, and unprovable data quality.
Final anti-pattern assessment: Not assessed. Evidence-check resolved the scanner score from 0 to 0. Verifier status: supported. The zero anti-pattern score is supported. The source does not evidence stale copies, manual files, undocumented transformations, unknown data origins, unprovable quality, or quality failures discovered only after model or business escalation. Coverage interpretation: Although the governance process includes data quality, testing, monitoring, and documentation activities, it does not provide enough lineage or operational data-flow evidence to test whether data swamp or broken-lineage conditions exist in practice.
AI tools access sensitive data with unclear purpose, logging, approval, retention, or boundary controls.
Final anti-pattern assessment: Not assessed. Evidence-check resolved the scanner score from 1 to 0. Verifier status: unsupported. Adjudication: The source discusses privacy and security principles, protection from unauthorized access and breaches, and data retention, but it does not show over-broad AI data access, uncontrolled experiment copies, missing logging/approval/purpose controls, or controls being added late. Coverage interpretation: Coverage is relevant but high-level; it is sufficient to show governance intent, not sufficient to assess whether the harmful access-control anti-pattern exists or is cleanly absent.
Teams create stale, incomplete, duplicate, costly, or unowned RAG, embedding, vector-store, feature, and knowledge stores.
Final anti-pattern assessment: Not assessed. Evidence-check resolved the scanner score from 0 to 0. Verifier status: supported. The zero anti-pattern score is supported. The source is silent on RAG, embeddings, vector stores, duplicate knowledge stores, feature stores, retrieval failures, context growth, and duplicated retrieval costs; therefore there is no evidence of the harmful pattern. Coverage interpretation: The available source material does not cover retrieval or knowledge-store architecture, so absence of this anti-pattern is not testable from the provided documents.
AI use cases are listed without linkage to service catalog, capability map, value stream, service-area ownership, data domain, or dependency structure.
Final anti-pattern assessment: Partial finding. Evidence-check resolved the scanner score from 1 to 1. Verifier status: weak. The quote is present and shows AI ideas are evaluated against business goals, technological possibilities, and customer needs. The harmful-pattern signal is mainly an omission: the intake/registration process does not require linkage to a service catalog, capability map, value stream, or service-area ownership model. This is a partial design-level signal, not direct evidence from an actual use-case list. Coverage interpretation: The AI governance process is relevant to AI intake and registration, so omission of service/capability architecture linkage is meaningful. However, the source does not provide actual AI use-case inventories or implementation records, so the anti-pattern cannot be fully confirmed.
AI speeds isolated tasks while increasing downstream rework, coordination, or poor customer/service flow.
Final anti-pattern assessment: Not assessed. Evidence-check resolved the scanner score from 0 to 0. Verifier status: supported. No source evidence shows AI being applied to isolated tasks, creating downstream rework, or ignoring customer experience/end-to-end flow. The documents are governance/process documents and do not provide operational examples of AI automation design. Coverage interpretation: The available documents are not service-flow or implementation evidence and would not reliably reveal spot optimization or silo automation if it existed.
AI components are built without clear linkage to capability, customer need, data source, platform dependency, value outcome, or cost-to-serve where evidence exists.
Final anti-pattern assessment: Partial finding. Evidence-check resolved the scanner score from 1 to 1. Verifier status: weak. The quote is present and shows partial traceability controls: description, purpose, business objectives, data linkage, risk classification, and applicable laws. The harmful-pattern finding is only partially supported because the process omits explicit capability, feature, platform dependency, value outcome, cost-to-serve, and work-package traceability, but it does not show teams actually building AI components with vague or tool-led requirements. Coverage interpretation: The governance process has relevant coverage of registration and pre-build controls. It partially mitigates untraceable build logic, while still leaving traceability gaps at capability/platform/value/cost layers.
AI teams are separated from service areas and ownership disappears after pilots, vendors, or temporary projects.
Final anti-pattern assessment: Not assessed. Evidence-check resolved the scanner score from 0 to 0 after a targeted rescan. Verifier status: supported. The source defines an accountable AI System Owner through retirement, which counters the specific pattern of ownership disappearing after pilot/vendor delivery. It does not provide enough service-area organizational structure evidence to test whether AI teams are disconnected from service areas or whether work is split into sequential handoffs. Coverage interpretation: Lifecycle ownership is covered, but team topology relative to service areas is not sufficiently covered to confirm absence of disconnected AI project teams.
AI is scaled broadly before Kickstart learning proves service readiness, architecture, data ownership, safety, cost-to-serve readiness, and operating model patterns.
Final anti-pattern assessment: Not assessed. Evidence-check resolved the scanner score from 0 to 0. Verifier status: supported. No evidence shows broad AI rollout before readiness, failure to convert pilot learning into reusable patterns, or repeated independent mistakes across service areas. The source addresses lifecycle governance for individual AI systems, not enterprise scaling behavior. Coverage interpretation: The available source is silent on scaling strategy, rollout sequencing, service-area adoption, and pilot-to-pattern conversion, so absence of the big-bang anti-pattern is not testable.
Quality Gate detail is retained here for traceability. WARN-level strategy hygiene notes do not invalidate the assessment score.
The assessment is blocked because evidence density is below the minimum floor, so the maturity reading is not sufficiently grounded in the source material. Strategy hygiene notes were retained for traceability; they do not invalidate the score, but the evidence-density block does.