Playbook · v0.3 · draft · CC BY 4.0

Score where you actually stand.

AI Maturity Playbook for BCM: five levels crossed with four assessment axes. No organisation is "at level 3" — an honest self-assessment names four numbers, such as A4 · B2 · C1 · D1, and those four numbers are the product. Their average is not.

PDF · 3 A4 sheets · 69 KB · v0.3, 2026-09-10

The five levels

The boundary is what separates them.

Level 1 has no boundary. Level 2 keeps it in somebody's head. Level 3 writes it down. Level 4 measures against it. At level 5 the boundary becomes the control point — which is the only place a self-improving process can be governed from.

  1. 1 · AD HOC Everyone tries something. Nobody knows what produced which BIA.
  2. 2 · REPEATABLE It works because one person knows how. Almost none of it is written down.
  3. 3 · DEFINED Method, validation points, sources and limits are written down and versioned.
  4. 4 · QUANTITATIVELY MANAGED Overrides, register age and boundary hits are counted.
  5. 5 · OPTIMISING The numbers show what to fix next. People set the boundary and check it afterwards.

The four axes

The axes are the part that does the work.

They measure only what is not swappable: whether a method is written down, who approves what, what gets logged, and where the agent's limits sit. Change every tool in the stack and the four numbers stay the same.

A · Method & impact criteria

What the AI is told to do: the BIA stages, the impact criteria and scales, the question set.

B · Validation & accountability

Who is answerable for what the AI produced, and at which point in the BIA they sign for it.

C · Record currency & traceability

Whether the BCMS record is still true, and where each fact in it came from.

D · Limits & autonomy

What an agent may do to a live BCMS record without a person in the loop.

The register

Four axes × five levels. Score each on its own.

Axis 1 · Ad hoc 2 · Repeatable 3 · Defined 4 · Quantitatively managed 5 · Optimising
A Method & impact criteria Analysts prompt freehand. Two people, one interview, two different BIAsOne analyst's prompts get reused. The method lives in their chat historyStages, impact criteria and question set written down, versioned, agreed with management before elicitationRework per stage and answers with no source are counted against that versionThe method changes where rework and failed retrievals cluster
B Validation & accountability AI output enters the BCMS unsigned. Nobody can say who agreed itThe analyst checks it. No record that they did, or of what they changedThe process owner validates impact, MTPD and dependencies before the record is saved. Not the analyst, not the toolValidation rate, override rate and what owners changed are counted per stageStages with no overrides for a year drop to spot-check
C Record currency & traceability Nobody knows when the dependency register was last trueA manual refresh once a year, if someone remembersEvery entry carries its source and date. Change triggers are namedRegister age and the delay before a change shows up are measured; entries with no source are countedOperational change proposes the BCMS update; people confirm or reject it
D Limits & autonomy The agent may do whatever the tool allows, including overwriting a validated recordThe limits live in the operator's headActions tiered by reversibility: draft freely, never write a validated record, never derive recovery plans from a BIABoundary hits and refusals are countedBoundary-hit and refusal rates decide where the limits move next

Evidence, and how you leave each level

Both rows read across, not down.

Row 1 · Ad hoc 2 · Repeatable 3 · Defined 4 · Quantitatively managed 5 · Optimising
Evidence what you must be able to show Nothing. That is the findingNothing you could hand an auditorThe method version, the named validators, and the source of each factOverride rate, register age and boundary hitsWhich BCMS change followed from which measurement
Next step how you leave this level Run one BIA stage twice the same wayWrite the method down, name who validates each stageStart counting overrides and register ageDefine a boundary that holds without step-by-step approvalPick the next change from the numbers

How to read this · no organisation is “at level 3”. An honest self-assessment names four numbers, for example A4 · B2 · C1 · D1.

Where this sits · ISO 22301:2019 and ISO 31000:2018 carry no maturity concept, so nothing here collides with the standard you already run.

Deliberately out of scope in v0.3 · security as its own axis, third-party agents, automation bias, and end-user disclosure.

Glossary

The words the register uses.

Boundary
The written line around what the AI may do on its own. A boundary hit is one occasion where it tried to cross that line and was stopped.
Override
A person changed what the AI produced before accepting it. The override rate is the share that gets changed.
Register age
How long since anyone last confirmed the dependency register is true.
Rework
A BIA stage that had to be done again.
Reversibility
How hard an action is to undo. It decides which actions the agent may take alone.
Elicitation
The interview or workshop where you get the information from people.
Spot-check
Reviewing a sample instead of every case.
Automation bias
Trusting the machine's answer over your own judgement.
End-user disclosure
Telling the people affected that AI was involved.

Take it away

The printable sheets.

3 A4 landscape sheets, set for paper rather than for a browser's print dialogue: the ladder and the axes on the first, the register on the second, evidence and next steps with the glossary on the third. Print it and score your own four numbers in the room.

How to cite the playbook
Gerner, K. (2026). AI Maturity Playbook for BCM. Published by AI4BCM. CC BY 4.0 · creativecommons.org/licenses/by/4.0/

v0.3 · 2026-09-10 · draft. The playbook is published under CC BY 4.0 like AI4BCM Guidance, and carries its own credit line — it is a different document with a different author list.