AI Governance Framework Primer

A practitioner-level introduction to the OWASP AI Maturity Assessment (AIMA) model — what it is, why it exists, and how it maps onto the regulatory frameworks most risk teams are already tracking.

AIMA-01Toolkit ArtefactPresentation-readyLinked to Chapter 01

What OWASP AIMA Is

AIMA is a maturity model purpose-built for AI governance, structured around business functions rather than technical controls alone. It asks not just 'do we have a policy' but 'how consistently is that policy actually operating, across which functions, with what evidence.'

What makes AIMA different

Business-function structure

Organized around how organizations actually operate, not just technical control lists.

Consistency over existence

Evaluates whether governance is reliably operating, not merely whether a policy document exists.

Evidence-based scoring

Requires demonstrable proof of maturity, not self-attestation alone.

The core question AIMA answers

How consistently is AI governance actually operating, across which functions, and with what evidence?

This framing shifts the conversation from checkbox compliance to operational reliability — a distinction that matters enormously when facing regulatory scrutiny or board-level accountability.

The Five Maturity Levels

AIMA's maturity model provides a structured progression from reactive, undocumented activity to continuously optimized governance. Each level represents a meaningful step in operational reliability and evidential strength.

1
2
3
4
5
1

1 · Ad Hoc

Reactive, undocumented, individual-dependent

2

2 · Defined

Policies exist on paper; adoption inconsistent

3

3 · Managed

Consistently followed, owned, basic metrics

4

4 · Measured

Quantified, tracked over time, decision-informing

5

5 · Optimized

Continuously improved from measured outcomes

Maturity Levels in Detail

Understanding what each level means in practice is essential before running any AIMA assessment. The distinctions between levels are operational, not cosmetic.

1

Ad Hoc

AI governance activity exists, but it's reactive, undocumented, and dependent on specific individuals. No repeatable process. High key-person risk.

2

Defined

Policies and processes exist on paper, but adoption is inconsistent across teams. The framework is written; the practice is not yet embedded.

3

Managed

Processes are consistently followed, with assigned ownership and basic metrics. Governance is operational, not just documented.

4

Measured

Governance activity is quantified, tracked over time, and used to inform decisions. Evidence is systematic and auditable.

5

Optimized

Governance is continuously improved based on measured outcomes and changing risk. The organization learns and adapts its AI governance posture.

The Six Business-Function Layers

AIMA assesses AI governance across six distinct business-function layers. Each layer represents a domain where governance must be consistently operating — not just documented — to achieve meaningful maturity scores.

Governance & Oversight

Who owns AI risk decisions, and how escalation actually works.

Risk Management

How AI-specific risk is identified, scored, and tracked to closure.

Data Management

Data quality, lineage, and consent as inputs to AI systems.

Model Development & Validation

Testing, bias evaluation, and change control before deployment.

Deployment & Monitoring

Drift detection, incident response, and retraining triggers after go-live.

Third-Party & Vendor AI

The layer covered in Chapter 02 of this series.

Layer Deep Dive: What Each Function Covers

Each of the six layers has a distinct scope. Understanding the boundaries between layers prevents gaps and overlaps in your assessment coverage.

Why Regulated Use Cases Need AIMA Over a Generic Checklist

What a checklist gives you

Control existence

A yes/no answer: does this control exist?

Point-in-time snapshot

A static view with no indication of reliability over time.

Binary output

Pass or fail — no gradient, no improvement pathway.

What AIMA gives you

Control reliability

Is this control consistently operating with evidence?

Longitudinal tracking

Maturity scores tracked over time, showing trajectory.

Defensible position

Evidence-backed statements for regulators and boards.

AIMA's maturity scoring is what lets you say, with evidence, 'this function is at Managed, and here's what Measured would require' — which is a materially stronger position than 'we have a policy.'

Mapping AIMA to NIST AI RMF

NIST AI RMF's four functions — Govern, Map, Measure, Manage — line up closely with AIMA's Governance, Risk Management, and Deployment & Monitoring layers, making AIMA a practical operating model for organizations that have already adopted NIST's functional language.

For organizations that have already adopted NIST's functional language, AIMA provides the operational depth that NIST's framework intentionally leaves to implementers. AIMA's six layers give each NIST function a concrete, assessable structure with maturity scoring built in.

Mapping AIMA to the EU AI Act

The EU AI Act's risk-tiering approach — unacceptable, high, limited, minimal risk — slots naturally into AIMA's Risk Management layer as the scoring criteria for what counts as 'high maturity' evidence for a given AI system's risk tier.

EU AI Act Risk Tiers

1
2
3
4
1

Unacceptable Risk

2

High Risk

3

Limited Risk

4

Minimal Risk

How AIMA integrates EU AI Act tiers

The EU AI Act's risk tiers become the scoring criteria within AIMA's Risk Management layer. For each AI system under assessment, the system's risk tier determines what level of maturity evidence is required to demonstrate adequate governance.

  • High-risk systems require Managed or above in Risk Management and Deployment & Monitoring layers to demonstrate compliance-grade governance.
  • Limited-risk systems may satisfy requirements at the Defined level with appropriate documentation.
  • Minimal-risk systems can be assessed more lightly, freeing governance capacity for higher-risk priorities.

How to Use This Primer

Read this before running AIMA-02 (the Gap & Risk Assessment Template) or AIMA-03 (the Maturity Scoping Question Bank) — both assume familiarity with the five levels and six layers described here.

1

AIMA-01

This document. Framework Primer — five levels, six layers, regulatory mapping.

2

AIMA-02

Next step. Gap & Risk Assessment Template — apply the framework to your organization.

3

AIMA-03

Then use. Maturity Scoping Question Bank — structured questions for each layer and level.

Prerequisites confirmed by this primer

  • Understanding of the five maturity levels and what distinguishes each
  • Familiarity with the six business-function layers AIMA assesses
  • Awareness of how AIMA maps to NIST AI RMF and the EU AI Act
  • Understanding of why maturity scoring is stronger than checklist compliance

What comes next

With this primer complete, practitioners are ready to scope an AIMA assessment, assign layer owners, and begin the gap analysis process using AIMA-02. The Maturity Scoping Question Bank in AIMA-03 provides the structured interview and evidence-gathering questions for each of the six layers across all five maturity levels.