A · Method & impact criteria
What the AI is told to do: the BIA stages, the impact criteria and scales, the question set.
Playbook · v0.3 · draft · CC BY 4.0
AI Maturity Playbook for BCM: five levels crossed with four assessment axes. No organisation is "at level 3" — an honest self-assessment names four numbers, such as A4 · B2 · C1 · D1, and those four numbers are the product. Their average is not.
The five levels
Level 1 has no boundary. Level 2 keeps it in somebody's head. Level 3 writes it down. Level 4 measures against it. At level 5 the boundary becomes the control point — which is the only place a self-improving process can be governed from.
The four axes
They measure only what is not swappable: whether a method is written down, who approves what, what gets logged, and where the agent's limits sit. Change every tool in the stack and the four numbers stay the same.
A · Method & impact criteria
What the AI is told to do: the BIA stages, the impact criteria and scales, the question set.
B · Validation & accountability
Who is answerable for what the AI produced, and at which point in the BIA they sign for it.
C · Record currency & traceability
Whether the BCMS record is still true, and where each fact in it came from.
D · Limits & autonomy
What an agent may do to a live BCMS record without a person in the loop.
The register
| Axis | 1 · Ad hoc | 2 · Repeatable | 3 · Defined | 4 · Quantitatively managed | 5 · Optimising |
|---|---|---|---|---|---|
| A Method & impact criteria | Analysts prompt freehand. Two people, one interview, two different BIAs | One analyst's prompts get reused. The method lives in their chat history | Stages, impact criteria and question set written down, versioned, agreed with management before elicitation | Rework per stage and answers with no source are counted against that version | The method changes where rework and failed retrievals cluster |
| B Validation & accountability | AI output enters the BCMS unsigned. Nobody can say who agreed it | The analyst checks it. No record that they did, or of what they changed | The process owner validates impact, MTPD and dependencies before the record is saved. Not the analyst, not the tool | Validation rate, override rate and what owners changed are counted per stage | Stages with no overrides for a year drop to spot-check |
| C Record currency & traceability | Nobody knows when the dependency register was last true | A manual refresh once a year, if someone remembers | Every entry carries its source and date. Change triggers are named | Register age and the delay before a change shows up are measured; entries with no source are counted | Operational change proposes the BCMS update; people confirm or reject it |
| D Limits & autonomy | The agent may do whatever the tool allows, including overwriting a validated record | The limits live in the operator's head | Actions tiered by reversibility: draft freely, never write a validated record, never derive recovery plans from a BIA | Boundary hits and refusals are counted | Boundary-hit and refusal rates decide where the limits move next |
Evidence, and how you leave each level
| Row | 1 · Ad hoc | 2 · Repeatable | 3 · Defined | 4 · Quantitatively managed | 5 · Optimising |
|---|---|---|---|---|---|
| Evidence what you must be able to show | Nothing. That is the finding | Nothing you could hand an auditor | The method version, the named validators, and the source of each fact | Override rate, register age and boundary hits | Which BCMS change followed from which measurement |
| Next step how you leave this level | Run one BIA stage twice the same way | Write the method down, name who validates each stage | Start counting overrides and register age | Define a boundary that holds without step-by-step approval | Pick the next change from the numbers |
How to read this · no organisation is “at level 3”. An honest self-assessment names four numbers, for example A4 · B2 · C1 · D1.
Where this sits · ISO 22301:2019 and ISO 31000:2018 carry no maturity concept, so nothing here collides with the standard you already run.
Deliberately out of scope in v0.3 · security as its own axis, third-party agents, automation bias, and end-user disclosure.
Glossary
Take it away
3 A4 landscape sheets, set for paper rather than for a browser's print dialogue: the ladder and the axes on the first, the register on the second, evidence and next steps with the glossary on the third. Print it and score your own four numbers in the room.
Gerner, K. (2026). AI Maturity Playbook for BCM. Published by AI4BCM. CC BY 4.0 · creativecommons.org/licenses/by/4.0/