Ask most banking CIOs where their institution sits on AI governance maturity, and you’ll generally get a confident answer. Ask them to prove it with production evidence rather than a policy document, and the confidence tends to thin out considerably. That gap – between where an institution believes it sits and where it can actually demonstrate it sits – is exactly where most regulatory findings originate.
Here is a five-level model for locating your institution honestly, and the specific work that separates each level from the next.
The Five Levels

Level 1 Ad Hoc
AI use is isolated across the institution – different teams running different models with minimal shared governance. There is no institution-wide risk taxonomy, and no one function owns AI risk as a category. Most institutions have moved past this level entirely; if you’re here, the priority is establishing ownership before anything else.
Level 2 Defined
Basic policies exist. Someone has written down what AI governance is supposed to look like. But controls are still largely manual, and ownership remains fragmented across the CIO’s technology function, the CRO’s model risk team, and the business units actually using the models. This is where a large share of the industry currently sits.
Level 3 Integrated
Lifecycle governance is embedded directly into delivery – engineering and compliance share a common definition of what “production-ready” actually means, rather than compliance reviewing engineering’s work after the fact. This is real progress over Level 2, but production monitoring and audit-readiness are still largely manual and reactive rather than automated and continuous.
Level 4 Industrialised
Monitoring is automated. Standards are enterprise-wide rather than team-by-team. Audit-readiness is a permanent operational state – meaning the evidence a regulator would ask for already exists, rather than needing to be assembled under deadline when an examination is announced. This is the level every regulatory instrument discussed in this series is now implicitly asking institutions to reach.
Level 5 Optimised
The governance framework itself learns and adapts alongside the models it governs – real-time, AI-enabled governance rather than a static framework applied to a dynamic system. Very few institutions are here today, and reaching it is not this year’s priority for most banks. It is worth knowing it exists as the direction of travel.
Where the Industry Actually Sits, and Why It Matters Now
Most global banks operate between Level 2 and Level 3 today – policies exist, some lifecycle governance is embedded, but production monitoring and audit-readiness remain manual and reactive. That specific band is not a comfortable place to be sitting in 2026 and 2027. It is precisely where SR 26-2, the EU AI Act’s approaching Annex III deadline, and the CFPB’s Circular 2026-03 will find the gap first – not in whether a policy exists on paper, but in whether the institution can produce, on demand, the evidence that the policy is actually being followed in production.
The finding is never that the policy was wrong. It is that no one could produce the evidence it was being followed.
What Actually Separates Level 3 from Level 4
The move from Level 2 to Level 3 is largely organisational – getting engineering and compliance to agree on a shared standard. The move from Level 3 to Level 4 is where most institutions underestimate the work involved, because it requires three things simultaneously rather than sequentially:
- Automated drift and bias monitoring running continuously in production, not reviewed on a quarterly or annual cycle.
- A single enterprise-wide definition of production-ready that every business line – retail, wholesale, capital markets – is held to, rather than each line interpreting the standard independently.
- Audit and reporting infrastructure that generates evidence as a byproduct of normal operation, rather than as a separate exercise triggered by an upcoming examination.
Diagnosing Your Own Position Honestly
A useful test: if a regulator asked tomorrow for evidence that your three highest-risk AI models had been monitored for drift over the past quarter, could your institution produce it within a day, or would it take a dedicated project team two weeks to assemble? The honest answer to that single question locates most institutions more accurately than any internal governance self-assessment.
This is not a model for banks with unlimited budget to industrialise governance in a single sprint. It is a sequencing tool – the specific, ordered work that moves an institution from where regulators will find the first gap to where they won’t find one at all.
Maturity Isn’t Uniform Across a Single Institution, Either
One complication most self-assessments miss: an institution rarely sits at one level uniformly. It’s common to find retail fraud detection sitting comfortably at Level 3, a wholesale credit model still at Level 2 because it was built years before the current governance policy existed, and a newly deployed customer-service copilot that hasn’t been formally assessed at all. Averaging these into a single institutional score obscures exactly the information a CIO or CRO needs – which specific models are the ones an examiner would find the gap in first. The honest version of this exercise assesses maturity model by model, or at minimum business-line by business-line, rather than producing one comforting enterprise-wide number that happens to be dragged upward by your best-governed system.
This is also where the maturity model and the fragmented-ownership problem intersect. An institution can’t consistently move a model from Level 2 to Level 3 if the team that owns it changes depending on which quarter you ask. Fixing the ownership question is frequently the actual prerequisite for the maturity question – not a separate initiative running in parallel.
This maturity model, and the full 0-90 day / 3-12 month / 12-24-month roadmap to move up it, is set out in Paper 5 of Maveric’s CIO Mandate Series:
AI Compliance and Regulatory Governance: A CIO & CRO Mandate for Global Banks