{
  "notice": "Illustrative mapping from the AI Governance Engineer Body of Knowledge v0.5.0 (not a claim of conformity)",
  "version": "0.5.0",
  "license": "CC BY 4.0",
  "licenseUrl": "https://creativecommons.org/licenses/by/4.0/",
  "schemaVersion": 1,
  "schema": "https://aigovernanceengineer.com/api/v1/schemas/maturity.json",
  "self": "https://aigovernanceengineer.com/api/v1/maturity.json",
  "source": "https://aigovernanceengineer.com/bok/maturity-model",
  "citation": {
    "title": "AI Governance Engineering: The Thesis & Body of Knowledge",
    "authors": [
      "Jorge García Aibar"
    ],
    "parentDoi": "https://doi.org/10.5281/zenodo.22956197",
    "conceptDoi": "https://doi.org/10.5281/zenodo.22857084"
  },
  "levels": [
    {
      "n": 1,
      "name": "Documented",
      "summary": "Governance exists as artefacts a human maintains: a policy PDF, a spreadsheet inventory, a risk register, a review before launch. The rules are written and someone is accountable, but nothing executes.",
      "signals": [
        "Policy documents",
        "A populated spreadsheet inventory",
        "Meeting minutes"
      ],
      "url": "https://aigovernanceengineer.com/bok/maturity-model#the-five-levels"
    },
    {
      "n": 2,
      "name": "Inventoried",
      "summary": "There is a real inventory of models and an agent registry, fed by a runtime data path rather than typed by hand: a deploy registers a system with an owner, a scope and a status. You can answer what is running on any given day.",
      "signals": [
        "A registry with an owner and a class for every system",
        "A discovery job reconciling registry against production"
      ],
      "url": "https://aigovernanceengineer.com/bok/maturity-model#the-five-levels"
    },
    {
      "n": 3,
      "name": "Tested",
      "summary": "Systems are evaluated against defined tests (capability, safety and adversarial evals) and the results are recorded as evidence. Failures are visible, but a failing eval does not yet stop anything.",
      "signals": [
        "Versioned eval suites",
        "Stored, timestamped eval results",
        "Red-team findings"
      ],
      "url": "https://aigovernanceengineer.com/bok/maturity-model#the-five-levels"
    },
    {
      "n": 4,
      "name": "Enforced",
      "summary": "The tests bite: policy-as-code and eval gates run in CI/CD and at admission, and a failing control blocks the merge or the deploy. Identity precedes autonomy, and the gating suites’ own coverage and adversarial quality are assessed, not just their existence.",
      "signals": [
        "Pipeline logs showing blocked releases with reasons",
        "Admission-control denials",
        "The registry acting as a deploy gate",
        "A tracked coverage or adversarial-quality metric for the gating suites"
      ],
      "url": "https://aigovernanceengineer.com/bok/maturity-model#the-five-levels"
    },
    {
      "n": 5,
      "name": "Continuous",
      "summary": "Assurance is produced continuously from the runtime data path: guardrail decisions, drift and agent behaviour stream into observability, and evidence is emitted as machine-readable artefacts as the pipeline and runtime operate. The audit is a query.",
      "signals": [
        "A live assurance store",
        "Streaming eval and guardrail telemetry",
        "An audit answered by running a query"
      ],
      "url": "https://aigovernanceengineer.com/bok/maturity-model#the-five-levels"
    }
  ]
}
