A practitioner-level introduction to the OWASP AI Maturity Assessment (AIMA) model — what it is, why it exists, and how it maps onto the regulatory frameworks most risk teams are already tracking.
AIMA is a maturity model purpose-built for AI governance, structured around business functions rather than technical controls alone. It asks not just 'do we have a policy' but 'how consistently is that policy actually operating, across which functions, with what evidence.'
Organized around how organizations actually operate, not just technical control lists.
Evaluates whether governance is reliably operating, not merely whether a policy document exists.
Requires demonstrable proof of maturity, not self-attestation alone.
How consistently is AI governance actually operating, across which functions, and with what evidence?
This framing shifts the conversation from checkbox compliance to operational reliability — a distinction that matters enormously when facing regulatory scrutiny or board-level accountability.
AIMA's maturity model provides a structured progression from reactive, undocumented activity to continuously optimized governance. Each level represents a meaningful step in operational reliability and evidential strength.
Reactive, undocumented, individual-dependent
Policies exist on paper; adoption inconsistent
Consistently followed, owned, basic metrics
Quantified, tracked over time, decision-informing
Continuously improved from measured outcomes
Understanding what each level means in practice is essential before running any AIMA assessment. The distinctions between levels are operational, not cosmetic.
AI governance activity exists, but it's reactive, undocumented, and dependent on specific individuals. No repeatable process. High key-person risk.
Policies and processes exist on paper, but adoption is inconsistent across teams. The framework is written; the practice is not yet embedded.
Processes are consistently followed, with assigned ownership and basic metrics. Governance is operational, not just documented.
Governance activity is quantified, tracked over time, and used to inform decisions. Evidence is systematic and auditable.
Governance is continuously improved based on measured outcomes and changing risk. The organization learns and adapts its AI governance posture.
AIMA assesses AI governance across six distinct business-function layers. Each layer represents a domain where governance must be consistently operating — not just documented — to achieve meaningful maturity scores.
Who owns AI risk decisions, and how escalation actually works.
How AI-specific risk is identified, scored, and tracked to closure.
Data quality, lineage, and consent as inputs to AI systems.
Testing, bias evaluation, and change control before deployment.
Drift detection, incident response, and retraining triggers after go-live.
The layer covered in Chapter 02 of this series.
Each of the six layers has a distinct scope. Understanding the boundaries between layers prevents gaps and overlaps in your assessment coverage.
A yes/no answer: does this control exist?
A static view with no indication of reliability over time.
Pass or fail — no gradient, no improvement pathway.
Is this control consistently operating with evidence?
Maturity scores tracked over time, showing trajectory.
Evidence-backed statements for regulators and boards.
AIMA's maturity scoring is what lets you say, with evidence, 'this function is at Managed, and here's what Measured would require' — which is a materially stronger position than 'we have a policy.'
NIST AI RMF's four functions — Govern, Map, Measure, Manage — line up closely with AIMA's Governance, Risk Management, and Deployment & Monitoring layers, making AIMA a practical operating model for organizations that have already adopted NIST's functional language.

For organizations that have already adopted NIST's functional language, AIMA provides the operational depth that NIST's framework intentionally leaves to implementers. AIMA's six layers give each NIST function a concrete, assessable structure with maturity scoring built in.
The EU AI Act's risk-tiering approach — unacceptable, high, limited, minimal risk — slots naturally into AIMA's Risk Management layer as the scoring criteria for what counts as 'high maturity' evidence for a given AI system's risk tier.
The EU AI Act's risk tiers become the scoring criteria within AIMA's Risk Management layer. For each AI system under assessment, the system's risk tier determines what level of maturity evidence is required to demonstrate adequate governance.
Read this before running AIMA-02 (the Gap & Risk Assessment Template) or AIMA-03 (the Maturity Scoping Question Bank) — both assume familiarity with the five levels and six layers described here.
This document. Framework Primer — five levels, six layers, regulatory mapping.
Next step. Gap & Risk Assessment Template — apply the framework to your organization.
Then use. Maturity Scoping Question Bank — structured questions for each layer and level.
With this primer complete, practitioners are ready to scope an AIMA assessment, assign layer owners, and begin the gap analysis process using AIMA-02. The Maturity Scoping Question Bank in AIMA-03 provides the structured interview and evidence-gathering questions for each of the six layers across all five maturity levels.
AI Governance Framework Primer