AI Maturity Report

Your AI Maturity Score Is a Diagnosis.

By The1938Group  |  18 August 2026  |  Johannesburg

The 1938Group has previously introduced you to the AI Maturity Assessment, an evidence-based understanding of where your AI governance actually stands. Once completed, you will have something important: a number.

A number is not a plan.

'You're at Level 2 on Data Management' this information tells the board that something needs attention. It does not tell them what needs attention, why it's needed, what the cost will be to fix, who owns it, or understanding how it works. Most maturity scores end up exactly where most audit findings end up, without these structures, acknowledgment in a meeting, filed, and revisited a year later at the same level.

The second part of the assessment helps address this: the report. Specifically, how a raw domain score can become a structured, evidence-based, board-ready document. This document will help leadership in making a decision and formally signing-off on the plan.

Why the Score Alone Fails

An overall score answers one question: how mature is this domain in relation to the model. It does not answer any questions that determine the changes observed and required:

  • What is actually missing? "47% on Governance" could mean no policy exists, or a policy exists but nobody reviews compliance, or a policy exists and is reviewed but no one owns it. Same score, three completely different solutions to fix.

  • Why does the gap exist? If no one is aware of the problem or of a fix for the problem, than the training programme will only exists on paper but won't get rolled out.

  • What will closing it cost, and who is accountable? Recommendations without an owner, viable timelines or resourcing estimate is wishful thinking, not a plans.

  • How will you know it worked? If the success measure is not clearly defined, "we addressed the gap" is unfalsifiable. No one can say whether the situation actually improved or not.

 

THE CORE PRINCIPLE

A maturity score is diagnostic. A maturity report is prescriptive. The gap between the two is the difference between a percentage that gets acknowledged in a meeting and a roadmap that gets funded, assigned, and delivered.

 

The Anatomy of a Report That Gets Acted On

The 1938Group Maturity Assessment Report follows a fixed nine-section structure. Each section exists to answer a specific question a board or leadership team will ask.

 


SECTION

WHAT IT CONTAINS

WHAT IT ENABLES

1

Executive Summary

Overall maturity level, key strengths, priority gaps, recommended actions

Leadership gets the headline in under two minutes

2

Assessment Overview

Scope, methodology, assessment team, stakeholders consulted, limitations

Establishes credibility and the boundaries of what was assessed

3

Key Findings

What's working well vs what needs attention, each backed by evidence

Grounds every claim in observation, not opinion

4

Domain Analysis

All 8 domains scored individually with strengths, gaps, and recommendations

Turns one overall number into eight specific conversations

5

Maturity Profile

Scorecard, visual profile, benchmark comparison to industry and best practice

Shows not just where you are but how far from where you need to be

6

Gap Analysis

Root-cause analysis per critical gap, plus an impact/effort priority matrix

Distinguishes symptoms from causes; prevents surface-level fixes

7

Recommendations

Numbered, detailed recommendations with rationale, steps, resources, success measures

Converts findings into assignable, trackable initiatives

8

Implementation Roadmap

Three-phase plan with monthly activities, owners, and investment required

Gives the board a timeline and budget to approve, not just intentions

9

Appendices & Sign-Off

Full questionnaire responses, interview notes, documents reviewed, formal acceptance

Creates an auditable record — evidence if a regulator ever asks

 

Three sections carry most of the weight in turning a score into action: Domain Analysis, Gap Analysis, and Recommendations.

Domain Analysis: One Number Eight Conversations

An overall maturity score is an average. As discussed, averages hide the domain that is genuinely harmful behind domains that are doing much better. A report that stops at the overall number lets a Level 4 Technology score quietly offset a Level 1 Data Management score.

The Domain Analysis section prevents that averaging. Each of the eight domains gets its own maturity level, its own score, a narrative summary of what was found, domain specific strengths, domain specific gaps, and domain-specific recommendations. Nothing is hidden inside an aggregate.

Gap Analysis: Knowing Symptoms from Causes

Most governance gaps are symptoms of another oversight. "No AI training programme" is rarely the real problem, it is a symptom of not having an individual that is formally accountable for AI governance, or of a policy that was written but never resourced for rollout. Treating the symptom (schedule some training) without addressing the cause (assign an owner, allocate budget) produces a fix that will not last.

This is why every critical gap in the report is documented against a fixed set of fields ( current state, desired state, impact, root cause, effort to close, and priority). Here is a worked example, illustrating the kind of entry a Data Management gap generates:

 

Domain

Data Management

Current State

No documented classification framework in practice; employees rely on individual judgment about what is safe to paste into AI tools

Desired State

RAG framework documented, trained, and consistently applied by all AI users before every prompt

Impact of Gap

Elevated risk of POPIA-relevant data exposure; no defensible compliance position if the Information Regulator asks how AI-processed personal data is protected

Root Cause

The framework exists in the policy document but was never actioned through training or embedded into onboarding

Effort to Close

Medium; training content exists in Module 5; requires scheduling and completion tracking

Priority

Critical

 

Note what the root-cause field does here. It does not just state the gap again, it explains why the gap exists despite the policy technically being in place. That distinction is what separates a recommendation that closes the gap from a recommendation that just re-issues the same policy that nobody read the first time.

Recommendations: From Finding to Assignable Initiative

Each critical gap generates a numbered, detailed recommendation, a small implementation brief with its own priority, effort estimate, timeline, implementation steps, resource requirements, and success measure. This allows the recommendation to be turned into something a named person can pick up and execute, rather than something that reads well in a report and then goes nowhere.

 

R1: Actioning the RAG Data Classification Framework

Priority: Critical   |   Effort: Medium   |   Timeline: 4 weeks

Gap Addressed: Data Management: documented policy not reflected in daily practice.

Recommendation: Deliver classification training to all AI users; embed the RAG decision point into onboarding for new starters.

Implementation: (1) Finalise training content and scenarios. (2) Schedule sessions across all business units. (3) Track completion against a 90% target.

Success Measure: Training completion rate; reduction in flagged high-risk AI prompts month over month.

 

Notice the specific target: a 90% completion target, not "improve training uptake." A named metric to measure success: reduction in flagged high-risk prompts, not "better compliance." in order to follow up on a recommendation it must be measurable. Recommendations that can't be measured will eventually be quietly removed from the agenda by month three.

The Gap Prioritisation Matrix: Where to Start

Not every gap deserves the same urgency or costs the same effort to resolve. The report plots the identified gaps on a simple two-axis matrix, impact against effort, to separate the four categories of action:

  • Quick Wins: High impact, low effort. Do these first. They build momentum and demonstrate that the assessment leads to real change.

  • Major Projects: High impact, high effort. Plan these properly, they need budget, sponsorship, and a realistic timeline. Don't skip them because they're difficult.

  • Fill-Ins: Low impact, low effort. Worth doing if time allows, but never at the expense of the two above categories.

  • Consider Carefully: Low impact, high effort. These are deferral candidates. Spending significant resource here while critical gaps remain open is a common and avoidable mistake.


This matrix is often the single most useful page in the report for a leadership team with limited bandwidth: it tells them exactly where to spend the first thirty days of attention.

The Implementation Roadmap: Three Phases, Twelve Months

Recommendations without a sequence are a wish list. The roadmap organises every recommendation into three phases, each with a clear objective and an expected maturity level at completion:

 

PHASE

WHEN

OBJECTIVE

TARGET

Phase 1: Foundation

Months 1–3

Establish governance framework and close critical gaps

Level 2

Phase 2: Development

Months 4–6

Build capability, deploy training, formalise processes

Level 3

Phase 3: Maturity

Months 7–12

Embed practices; measure and improve continuously

Level 3–4

 

Each phase carries a month-by-month activity table with named deliverables and owners, plus phase-specific milestones. More critically, each phase carries an investment estimate, personnel time, external consulting, technology, and training cost, because a roadmap without a budget attached is not something the finance department or CFO will approve.

Success Metrics: How You Know It Worked

The report closes the loop with a defined set of metrics, tracked from baseline through 6-month and 12-month targets. This is what makes the twelve-month plan more than an aspiration, it gives the governance body something concrete to review at each check-in.

 

METRIC

BASELINE

6-MONTH

12-MONTH

Overall maturity level

Level 2

Level 3

Level 3-4

Policy compliance rate

40%

70%

90%

Training completion rate

25%

65%

90%

AI incident rate (self-reported)

Unknown

Tracked

Declining trend

 

A re-assessment against the full 43-question framework at the 12-month mark closes the loop entirely: the same instrument that produced the original diagnosis now measures whether the treatment worked.

Sign-Off: Making Governance an Artefact, Not a Conversation

The report closes with formal sign-off. The sign-off should be prepared by, reviewed by, and accepted by the client. This is an intentional design choice. A signed report can be presented as evidence, If a regulator, auditor, or board member ever asks how AI governance is being managed, "here is the report we reviewed and accepted, with the roadmap we approved" is a stronger more prepared answer than "we've talked about it."

This connects directly to the accountability principle: the AI did it is never an acceptable explanation for a poor outcome. The same logic applies at the governance level. Phrases such as we didn't know, or it was on someone's list is a far weaker position to take, especially, when a signed, dated report with named owners and target dates already exists.

From Diagnosis to Discipline

The maturity assessment answers the question, where are we? The report answers, what happens next? who owns it? and how the leadership and their teams will know it worked. An assessment without a report structure removes accountability. Creating awareness without accountability. A report template without an assessment produces generic recommendations that are disconnected from the actual evidence.

All together, the assessment gives the leadership team what it actually needs: an honest baseline, a prioritised plan, a funded roadmap, and a document they can put their name to.

 

If your organisation has a maturity score sitting in a spreadsheet somewhere with no plan attached to it, that is the gap worth closing first.