FEATURED RESOURCE

AI Governance Maturity Scorecard

A scorecard for assessing how mature your current AI governance model actually is — across policy, review, monitoring, and reporting.

Most legal departments assume their AI governance is somewhere in the middle. This scorecard replaces that assumption with a specific answer, scored across the dimensions that determine whether a governance program can actually hold up under scrutiny.

How to Use This Scorecard

Score each dimension from 1 to 5 based on where your department stands today, not where you intend to be. Be specific — "we have a policy" only counts as a higher score if that policy is actually applied to real tools, not just written and filed away.

Score Each Dimension

Dimension 1 — Not Started 3 — Partial 5 — Fully Operational
Use Policy No written policy exists. A policy exists but isn't consistently applied. A specific, current policy is applied to every new tool.
Visibility No central record of what AI is in use. Some tools are tracked; others are unknown. A complete, current inventory of AI use exists.
Risk Review No formal review before adoption. Review happens inconsistently, often after the fact. Every new use case goes through a defined risk review.
Vendor Assessment Vendor AI features are not separately assessed. Some vendors are assessed; embedded features often aren't. All vendor AI, including embedded features, is assessed on a schedule.
Ongoing Monitoring Approval is a one-time event. Some tools are revisited, but not systematically. Approved use is monitored continuously for scope or vendor changes.
Reporting No way to answer what AI is in use if asked. Reporting is possible but requires manual reconstruction. A structured record can be reported on immediately, for any audience.

Interpreting Your Score

6–14: Ungoverned

AI use is happening without a consistent way to see, assess, or account for it. This is the highest-exposure stage, and the most common starting point.

15–23: Emerging

Some structure exists, but gaps in visibility, vendor assessment, or monitoring leave the department unable to answer confidently in every case.

24–30: Operational

A consistent governance model is in place and can be demonstrated. The focus at this stage shifts to maintaining and scaling it as AI capability grows.

The core issue

The dimension that scores lowest is usually the one that determines your actual exposure, not the average. A strong policy score doesn't help if visibility is still at a 1.

Rescore quarterly, not once

AI capability inside your existing vendor stack changes faster than most governance programs get reassessed. A score that was accurate six months ago may already be out of date.

Next Step

Wherever your score lands, the path forward is the same sequence covered across this hub: a clear use policy, a consistent governance workflow, and the reporting to demonstrate it's actually working. Start with whichever dimension scored lowest — that's where the real exposure sits.

A maturity score isn't a grade. It's a map of exactly where to focus next.