Enterprise AI capability model¶
The capability model identifies what an organization must be able to do, independent of organizational structure or technology products.
Capability domains¶
| Domain | Representative capabilities |
|---|---|
| Strategy and portfolio | Mission alignment, opportunity discovery, prioritization, value realization |
| Governance and accountability | Policy, decision rights, use-case inventory, risk acceptance, reporting |
| Risk and assurance | Impact assessment, control design, evaluation, red teaming, independent review |
| Data and knowledge | Stewardship, rights, quality, lineage, semantics, retrieval, records |
| AI engineering | Experimentation, model selection, prompt engineering, orchestration, testing |
| Platform and integration | Model gateway, identity, APIs, eventing, tool registry, environment management |
| Security and privacy | Threat modeling, privacy engineering, supply-chain assurance, incident response |
| Operations | Release, observability, drift monitoring, change, continuity, retirement |
| People and adoption | Literacy, specialist skills, workforce impact, accessibility, change management |
| Procurement and supplier management | Supplier due diligence, contracts, portability, concentration-risk management |
Maturity scale¶
- Initial: teams depend on individual effort and ad hoc activity.
- Managed: teams assign ownership and apply minimum controls consistently.
- Defined: the organization establishes enterprise standards, reusable services, and measures.
- Measured: outcomes, control effectiveness, and operational performance drive decisions.
- Adaptive: evidence continuously improves policy, architecture, and investment.
Maturity is a means to better outcomes. Set target levels from organizational mission, risk exposure, operating scale, and investment priorities.
Relationship to ECA
These capability domains describe what the organization must be able to do. They are part of the enterprise context described by the seven Enterprise Context Architecture domains: People & Org, Business, Information, Technology, Governance, Integration, and Operational.
Assessment guidance¶
For each capability, record the accountable owner, current and target maturity, dependencies, evidence, gaps, funded initiatives, and target date. Validate self-assessments with operational evidence. Policy documents alone provide insufficient evidence of maturity.