Hello. In the previous lesson, you turned an enterprise priority into an AI mandate: a bounded, outcome-led statement of what the GCC is authorized to achieve, with which partners, constraints, and measures.
That mandate tells you where the GCC should focus. A maturity assessment tells you what the GCC can realistically do now and what capabilities it must strengthen before taking on more ambitious work. A GCC may have an excellent mandate to improve support operations with AI, for example, but still lack safe data access, meaningful pilot measurement, or an operating model for scaling successful workflows.
In this lesson, you will learn to assess a GCC’s AI maturity systematically, using stages, dimensions, evidence, and capability gaps rather than intuition or an impressive list of AI tools.
Maturity is capability, not publicity
AI maturity is the organization’s demonstrated ability to select, govern, deliver, operate, and improve AI in ways that create sustained business value.
It is not:
- the number of GenAI licenses purchased;
- the number of chatbot demonstrations completed;
- whether a leader calls the organization “AI-first”;
- the technical sophistication of one isolated team; or
- a single successful proof of concept.
A GCC can be mature in one area and immature in another. It might have capable analysts and a strong data platform, for example, yet lack clear approval rights, trustworthy adoption metrics, or documented processes for responding to an unreliable AI output. That is why an assessment needs several dimensions and evidence for each one.
The assessment should answer four management questions:
- Where are we today? What can the GCC reliably do across a portfolio, not just in one pilot?
- What limits us? Which capability gaps prevent safe, repeatable value creation?
- Where do we need to be? What maturity level is appropriate for the GCC’s mandate over the next 12–18 months?
- What should we build first? Which few improvements unlock the most valuable next step?
The last question is the point. A maturity model is a decision tool, not a labeling exercise.
Two useful lenses: stages and dimensions
A strong assessment combines:
- Maturity stages, which describe the overall pattern of how AI is used and managed over time.
- Capability dimensions, which show where that pattern is strong, weak, or inconsistent.
MIT CISR’s Enterprise AI Maturity Model provides a useful four-stage backbone. Its central message is cumulative: enterprises build capabilities and learning as they progress, rather than jumping directly from experimentation to scaled, AI-enabled operations.
Building Enterprise AI Maturity | MIT CISR
Read MIT CISR’s four-stage model first. It provides a practical vocabulary for distinguishing experimentation, pilots, repeatable ways of working, and genuinely embedded AI operations.
Start with the section “Four Stages of Enterprise AI Maturity” and read the four-stage overview. Then read the sections “Stage 1: Experiment and Prepare,” “Stage 2: Build Pilots and Capabilities,” and “Stage 3: Develop AI Ways of Working,” focusing on the move from scattered experimentation to measurable pilots, reusable platforms, dashboards, and test-and-learn practices. Finish with “Stage 4: Become AI Future Ready,” especially the future-ready description. As you read, identify the evidence that would distinguish a claimed capability from a repeatable one.
MIT CISR’s stages can be translated into a practical GCC scale:
| Level | GCC maturity stage | What it means in practice |
|---|---|---|
| 1 | Experiment and prepare | Individuals or teams explore AI; basic policies, literacy, and data access are being established. |
| 2 | Build pilots and capabilities | The GCC runs intentional pilots tied to use cases and metrics, while beginning to address data, process, and delivery gaps. |
| 3 | Develop AI ways of working | AI delivery and operations are repeatable across multiple use cases; reusable platforms, governance, dashboards, and learning practices exist. |
| 4 | Become AI future ready | AI is embedded in core processes and decision-making; the GCC continuously improves and may provide AI-enabled services as a strategic enterprise capability. |
These are not merely labels of sophistication. They imply different management priorities.
- A Level 1 GCC should prioritize policy, literacy, use-case discipline, and safe experimentation.
- A Level 2 GCC should focus on proving value and creating repeatable pilot practices.
- A Level 3 GCC should improve reuse, portfolio governance, operating metrics, and scaled adoption.
- A Level 4 GCC should sustain innovation while continuously managing quality, cost, resilience, and evolving risk.
A GCC should not be pressured to operate at Level 4 simply because the enterprise wants an ambitious AI narrative. Its target maturity needs to fit its mandate, data sensitivity, service criticality, available investment, and enterprise decision rights.
The GCC assessment dimensions
Stages describe how mature the organization is. Dimensions clarify mature in what.
KPMG’s GCC maturity model identifies eight dimensions that make a useful GCC-specific assessment frame. They prevent a narrow focus on technology by putting strategy, service design, workforce, value, and controls in the same conversation.

For an AI Operations or Strategy Manager, assess each dimension through an AI lens.
| GCC dimension | Assessment question | Examples of credible evidence |
|---|---|---|
| Strategic alignment to headquarters | Is the GCC’s AI work linked to enterprise priorities and an agreed mandate? | Approved AI strategy, sponsor statements, portfolio criteria, mandate documents, steering-group decisions |
| Value and cost | Does the GCC measure business value and the total cost of AI initiatives? | Process baselines, benefit cases, pilot scorecards, adoption data, cost reports, scale or stop decisions |
| Governance and empowerment | Are decision rights, approval routes, and accountability clear? | Governance terms of reference, RACI or decision-rights map, intake process, approval records, escalation paths |
| Service portfolio | Does the GCC manage AI work as a coherent portfolio rather than disconnected requests? | Use-case inventory, prioritization criteria, roadmaps, service catalogue, reuse plans |
| Depth of capability | Does the GCC have sufficient operational, product, data, technical, and change capability to deliver its mandate? | Role definitions, delivery playbooks, staffing plans, communities of practice, partner model |
| Digital maturity | Are data, integration, platforms, access controls, and environments adequate for safe AI delivery? | Data catalogue, API availability, approved AI environment, architecture documentation, testing environment |
| Future-ready workforce | Can leaders and employees use AI appropriately, and can the GCC develop the capabilities it needs next? | Role-based learning, skills assessment, manager guidance, adoption support, training completion and proficiency evidence |
| Risk and compliance | Are risks identified, assessed, controlled, and monitored throughout the AI lifecycle? | Acceptable-use policy, risk assessments, data classifications, human-oversight rules, incident logs, audit trail |
Notice the distinction between Depth of capability and Future-ready workforce. The first asks whether the GCC can deliver today. The second asks whether it can sustain change tomorrow through skills planning, literacy, and talent development.
Likewise, Digital maturity is not equivalent to AI maturity. A GCC can have modern cloud systems but weak AI governance. Conversely, a GCC can have strong operating discipline but lack the secure data access or testing environment needed to scale beyond low-risk pilots.
A four-level rubric for each dimension
To assess maturity consistently, define observable behavior at each level. The same four levels apply to every dimension, but the evidence changes by dimension.
| Level | General pattern | Example: governance and empowerment | Example: value and cost |
|---|---|---|---|
| 1 — Experiment and prepare | Activity is local, informal, and inconsistent. | Decisions occur project by project; roles and approval paths are unclear. | Benefits are described qualitatively; no agreed baseline or cost view exists. |
| 2 — Build pilots and capabilities | Intentional practices exist, but are limited to selected pilots or teams. | A pilot governance group and approval path exist, though use varies by initiative. | Pilot metrics and basic business cases exist; some value is tracked. |
| 3 — Develop AI ways of working | Practices are standardized, repeatable, and used across the GCC portfolio. | Defined decision rights, stage gates, and escalation routes are routinely used. | Portfolio dashboards track realized value, adoption, quality, risk, and operating cost. |
| 4 — Become AI future ready | The GCC improves the system continuously and helps shape enterprise capability. | Governance data reveal bottlenecks and lead to regular redesign of policies and controls. | Value measurement informs resource allocation, service pricing or chargeback where relevant, and new AI-enabled services. |
The most important distinction is between having an artifact and using it effectively.
For example:
- A draft AI policy is not Level 3 governance.
- A dashboard created for one executive presentation is not Level 3 performance management.
- A completed training course is not proof that employees can use AI safely in their actual workflow.
- A pilot with excellent anecdotal feedback is not proof of measurable value.
At Level 3, an artifact is embedded in normal operating practice. At Level 4, the GCC uses what it learns from that practice to systematically improve its operating model.
Evidence first: how to avoid a self-congratulatory assessment
People commonly overrate maturity because they assess intentions rather than evidence. To prevent this, use an evidence hierarchy.
| Strength of evidence | What it looks like | How much weight to give it |
|---|---|---|
| Weak | “We plan to create an AI governance board.” | Treat as an aspiration, not evidence of maturity. |
| Moderate | “We have an AI governance board and meet monthly.” | Evidence of a defined structure, but not necessarily effectiveness. |
| Strong | “The board has reviewed 18 use cases, rejected four due to data risk, and revised the intake criteria after repeated issues.” | Evidence that governance is operating and influencing outcomes. |
| Very strong | “Governance decisions, incidents, outcomes, and feedback are analyzed quarterly; controls and policies are updated as a result.” | Evidence of continuous improvement and higher maturity. |
This discipline is particularly useful in interviews and stakeholder workshops. Rather than asking, “Do we have good governance?” ask questions that request artifacts and examples:
- Which AI use cases were approved, delayed, redesigned, or stopped in the last six months?
- Who has the authority to approve a pilot involving customer or healthcare-related data?
- Can the GCC show a baseline and realized operational result for a completed pilot?
- Which AI systems are in use, who owns them, and what is their current lifecycle stage?
- What happens if an employee identifies a harmful output or a suspected data exposure?
- How does the GCC know whether a model or workflow is still performing acceptably in production?
A maturity assessment should combine document review, operating data, interviews, and a sample of actual initiatives. It should not rely exclusively on leadership opinion.
A practical GCC assessment process
Use the following process to produce a credible assessment in a few workshops and evidence-review sessions.
1. Set the scope and the decision to be supported
First, specify the unit being assessed. It might be:
- the entire GCC;
- a shared-services function such as finance operations;
- the GCC’s AI enablement team;
- an AI service portfolio for healthcare operations; or
- a single value stream, such as customer-support knowledge operations.
Also state the decision the assessment will support. Examples include:
- deciding whether to launch a controlled pilot;
- setting a 12-month capability roadmap;
- determining whether a GCC can operate a production AI service;
- requesting investment in a secure AI platform or workforce development;
- clarifying whether a centralized or federated operating model is appropriate.
Without this boundary, a broad GCC may appear immature because one unit is early-stage, while another is already operating AI at scale.
2. Agree on dimensions, indicators, and target levels
Use the eight dimensions above, then create two to four indicators per dimension appropriate to the GCC mandate.
For an AI-assisted support-knowledge mandate, selected indicators could be:
| Dimension | Useful indicators for the support-knowledge example |
|---|---|
| Strategic alignment | Sponsor commitment; defined support outcome; link to customer-service strategy |
| Value and cost | Baseline search time; answer-consistency measure; repeat-contact rate; pilot operating cost |
| Governance | Named process owner; data approval route; documented scale decision rights |
| Digital maturity | Approved knowledge sources; integration feasibility; secure user access; test environment |
| Workforce | Representative training; supervisor guidance; feedback channel; support model |
| Risk and compliance | Human review requirement; privacy assessment; escalation process; audit logging |
Set both a current-state score and a target-state score. The target should be tied to the decision at hand. A low-risk internal summarization pilot may be feasible at Level 2 in some dimensions. A workflow that influences patient communications, financial decisions, or customer commitments may require Level 3 capability in governance, risk, data, and monitoring before production deployment.
3. Collect evidence across functions
Maturity cannot be assessed solely by the technical team or the GCC leader. Include evidence from people who see different parts of the operating model:
- GCC leadership and executive sponsor;
- business process owners;
- AI operations or product operations leads;
- technology, architecture, and data leaders;
- information security, privacy, legal, risk, and compliance;
- frontline managers and end users;
- finance or transformation-office representatives.
The goal is not consensus at all costs. Differences are diagnostic. If leadership believes the GCC has a strong AI intake process, but business owners cannot explain how requests are prioritized, that inconsistency is evidence that the process is not yet embedded.
4. Score the dimensions, recording rationale and confidence
For each dimension, record:
- current level;
- evidence that supports it;
- missing or contradictory evidence;
- target level;
- priority gap;
- accountable owner.
A simple assessment record might look like this:
| Dimension | Current | Target | Evidence-based rationale | Priority action |
|---|---|---|---|---|
| Strategic alignment | 2 | 3 | AI mandate exists for support operations, but portfolio criteria are not consistently used. | Establish a quarterly AI portfolio review with sponsor decisions. |
| Value and cost | 1 | 3 | Pilot ideas have qualitative benefits but no common baseline or benefit-realization method. | Introduce baseline, benefit, adoption, quality, and cost scorecard. |
| Governance and empowerment | 2 | 3 | Pilot approvals occur, but process-owner, data-owner, and GCC decision rights vary. | Define stage gates and decision rights for AI initiatives. |
| Digital maturity | 2 | 3 | Approved knowledge base exists, but access and integration are slow and fragmented. | Create an approved retrieval and testing environment. |
| Workforce | 1 | 2 | Small expert group uses GenAI; frontline representatives lack practical guidance. | Deliver role-based AI literacy and supervisor coaching. |
| Risk and compliance | 2 | 3 | Acceptable-use guidance exists, but AI-specific risk assessments and incident procedures are incomplete. | Implement risk assessment, human-review rules, and incident escalation. |
Do not create false precision. A score of 2.4 can look analytical, but it often hides disagreement and weak evidence. In most early assessments, an integer level plus a confidence rating is more honest:
- High confidence: multiple sources and operating evidence agree.
- Medium confidence: evidence exists but is incomplete or limited to a few teams.
- Low confidence: scoring is mainly based on stakeholder statements or unverified artifacts.
5. Identify constraints, not merely low scores
A maturity gap matters when it constrains the mandate.
Suppose the GCC scores Level 1 in workforce capability and Level 2 in digital maturity. Either may be important. But if the immediate mandate is a limited internal pilot with trained users, the workforce gap may be manageable. If the GCC cannot securely access approved knowledge sources, however, digital maturity may block the pilot entirely.
Classify gaps as:
- Gating: must be resolved before the next decision or deployment stage.
- Enabling: improves speed, consistency, or scalability, but does not block a controlled next step.
- Optimizing: improves an already functioning capability and is valuable after foundational gaps are addressed.
This avoids a common failure mode: launching a long list of maturity initiatives with no connection to the GCC’s highest-value AI opportunity.
Reading a maturity model as a roadmap
CNA’s model was written for government agencies, so its specific legal and public-accountability expectations should not be copied uncritically into a commercial GCC. Its structure is still highly useful: assess domains separately, compare current practice to observable indicators, identify the next level, and prioritize gaps.
CNA’s Artificial Intelligence (AI) Maturity Model for ...
Use this as a diagnostic-method resource rather than as a GCC template. Its detailed indicators demonstrate what evidence-based maturity assessment looks like, particularly for governance, data, workforce, performance, and risk.
Read the opening explanation of the five domains, beginning with the model structure. Then read the four maturity-level definitions from the assessment scale. In “Using the Model,” read the diagnostic approach, paying close attention to current versus desired maturity and gap prioritization. Finally, in the “Maturity Model” section, scan the detailed indicators under “Coordination, strategy, and planning,” “Datasets,” “Workforce and expertise,” “Performance,” and “Risk management.” Focus on the difference between isolated activity, established organization-wide practice, and continuous improvement.
CNA’s approach reinforces two practical principles:
- Score dimensions separately. A GCC may be established in data accessibility but only developing in performance monitoring.
- Use the next maturity level as the roadmap. Do not try to leap several levels at once. Ask what evidence and operating practices would demonstrate the next level.
For instance, if a GCC is at Level 2 in governance, the Level 3 goal is not “more meetings.” It is consistent use of defined decision rights, lifecycle checkpoints, compliance requirements, documentation, and escalation procedures across initiatives.
Presenting the assessment without oversimplifying it
A radar chart is an effective way to show a multi-dimensional profile, especially in an executive conversation. It makes uneven maturity visible quickly.

A visual can help, but avoid treating the average score as the full answer. An “overall maturity” figure can be useful for tracking progress only if leaders can see:
- the dimensions underneath it;
- the weighting logic, if some dimensions are more consequential;
- the evidence used;
- any gating gaps concealed by the average; and
- the actions and owners associated with priority gaps.
For example, a GCC could average 2.5 across eight dimensions but still be unable to put a customer-facing AI workflow into production because risk and compliance are at Level 1. The average is descriptive; the gating constraint is decisive.
A concise executive output is usually enough:
- Purpose and scope: What GCC unit, service, or mandate was assessed?
- Maturity profile: Current and target levels across the eight dimensions.
- Evidence summary: A few high-confidence strengths and key uncertainties.
- Top three gaps: Particularly those that block value realization or safe scaling.
- 90-day actions: Owners, milestones, and decision points.
- Decision requested: Investment, pilot authorization, governance changes, or reassessment timing.
Worked interpretation: a GCC support-operations mandate
Return to the earlier mandate: AI-assisted retrieval of approved knowledge for enterprise support representatives.
Imagine the GCC finds the following:
- Leaders have an approved customer-support efficiency priority and a named executive sponsor.
- Two teams have built prototypes using generic GenAI tools.
- The approved knowledge base is fragmented, ownership is unclear, and access permissions are inconsistent.
- The GCC has no common evaluation set for answer quality.
- Supervisors are interested, but there is no training or process for representatives to flag unsafe outputs.
- Security has issued general GenAI guidance but has not approved a production pattern for this use case.
The correct conclusion is not, “The GCC is immature, so do nothing.” Nor is it, “The prototypes work, so deploy.”
A disciplined conclusion might be:
The GCC is at Level 2 in strategic alignment and early Level 2 in pilot capability, but Level 1–2 in data readiness, user enablement, performance measurement, and AI-specific operating controls. It is ready for a controlled, human-reviewed pilot using approved sources, but not ready for autonomous customer-facing deployment or broad production scaling.
The resulting roadmap should be proportionate:
| Time horizon | Capability-building focus |
|---|---|
| First 90 days | Confirm knowledge ownership; establish approved data access; define a pilot evaluation set; document decision rights and risk controls. |
| Pilot period | Measure retrieval usefulness, answer quality, handling-time impact, adoption, exceptions, and cost; train users and supervisors; capture feedback. |
| Scale decision | Compare results with thresholds; strengthen monitoring, support processes, and governance before expanding to more teams or customer-facing use. |
This is the judgment expected of an AI Operations or Strategy Manager: matching the ambition of the AI mandate to the organization’s demonstrated ability to execute safely and repeatedly.
Key takeaways
An AI maturity assessment helps a GCC decide what it can responsibly undertake now and what it must build next.
Use a structured approach:
- apply four maturity stages: experiment and prepare, build pilots and capabilities, develop AI ways of working, and become AI future ready;
- assess several dimensions rather than relying on a single score;
- examine GCC-specific dimensions including strategy, value, governance, service portfolio, capability depth, digital foundations, workforce, and risk;
- score against observable evidence, not aspirations or isolated demonstrations;
- identify gating capability gaps that limit the GCC’s mandate; and
- convert the assessment into owned, time-bound capability-building actions.
The next lesson moves from organizational readiness to initiative governance: you will map the stakeholders involved in selecting, approving, delivering, and operating an AI initiative.
Can't find a good explanation? Sign up and we'll make it for you
Sign up