Unified AI + Cyber Maturity Model

One score for AI governance. One for cyber. One combined posture.

The RAIC Maturity Dashboard publishes three coherent scores — GMI for AI governance, CGMI for cyber governance, and a combined TGP (Total Governance Posture) — all fed by a single Controls Register and a unified AI + Cyber Systems Registry.

The three scores

GMI — AI

Eight-dimension AI governance score (0–5 scale, weighted) mapped to ISO/IEC 42001, NIST AI RMF, and the EU AI Act. Powered by the AI Systems Registry, Use Case Register, AI controls, AI policies, attestations, and supplier reviews.

CGMI — Cyber

Nine cyber-governance dimensions scored 0–5 and weighted to a single index. Mapped to NIST CSF 2.0, CIS Controls v8.1, C2M2, and SOC 2. Fed by cyber controls, NHI inventory, Azure secret-expiry signals, the Shadow AI Catalog, and phishing-simulation results.

TGP — Combined

Total Governance Posture is a 50/50 blend of GMI and CGMI — one board-ready number with a 12-month trend, per-dimension gap callouts, and drill-down into the PowerGRYD five-layer pyramid.

How TGP tiers your posture
Gold (≥ 4.0): Optimized

Board-ready, audit-ready, ready to expand.

Silver (2.5–3.9): Managed

Defined controls operating with measurable outcomes.

Bronze (< 2.5): Initial

Ad-hoc or undocumented practice; gap callouts surface the fastest lifts.

Two domain-specific rubrics, one dashboard

Two domain-specific rubrics. One dashboard.

GMI and CGMI share the same 0–5 scoring shape and render on the same Maturity Dashboard chart — but the dimensions themselves are domain-specific. AI leaders and cyber leaders each see the rubric built for their domain.

GMI — AI (8 dimensions)

Policy

Binding acceptable-use, procurement, and incident rules — versioned and attested.

Inventory

Every AI system and use case in one registry.

Risk

Likelihood times impact scoring with documented treatment plans.

Controls

Multi-link adapter mapping one control to many AI frameworks at once.

Evidence

Auditor-grade documentation, attestations, and exports.

Operations

Cadence of reviews, audits, and supplier reassessments.

People

Training completion, role accountability, and concerns-channel usage.

Assurance

Internal audit, management review, and external attestation results.

CGMI — Cyber (9 dimensions)

Risk & Vulnerability Management

Continuous identification, prioritization, and remediation of cyber risks and vulnerabilities.

Incident Detection & Response

Monitoring, triage, response, and recovery from cyber events.

Cyber Governance & Policy

Binding cyber policies, roles, and accountability — versioned and attested.

Identity & Access Management

Human and non-human identity, least privilege, and access reviews.

Data Security & Privacy

Classification, encryption, retention, and privacy obligations.

Third-Party & Supply Chain

Supplier risk, contractual controls, and ongoing reassessment.

Asset & Configuration Management

Authoritative inventory and hardened, tracked configurations.

Workforce, Culture & Awareness

Training completion, phishing simulation, and security culture signals.

Business Continuity & Resilience

Tested recovery objectives, backups, and continuity exercises.

Maturity rubric (0–5)

How dimensions are scored

  • 0
    Absent
    No documented practice.
  • 1
    Initial
    Ad-hoc, unrepeatable activity.
  • 2
    Defined
    Documented but inconsistently applied.
  • 3
    Managed
    Operating with measurable outcomes.
  • 4
    Quantitative
    Outcomes tracked against targets and trends.
  • 5
    Optimizing
    Continuous improvement against evidence.
Reading the dashboard

From one number to root cause

  • Headline: TGP, GMI, and CGMI on one card with 12-month trend.
  • Gap callouts: The two lowest-scoring dimensions per domain surface with the artifacts that would lift them.
  • Drill-down: Any dimension opens its PowerGRYD layer view and the linked controls, risks, and evidence.
  • Framework overlay: every CGMI dimension card surfaces its NIST CSF 2.0 function (GOVERN/IDENTIFY/PROTECT/DETECT/RESPOND/RECOVER) plus its C2M2 domain and CIS v8.1 family — so a cyber leader sees, at a glance, which standard each score answers to.
  • Export: Board-ready DOCX and CSV exports straight from the dashboard.

Frameworks behind the scores

One control mapped through the multi-link adapter satisfies every framework it's connected to. The Maturity Dashboard and the framework coverage rollup move together.

ISO/IEC 42001

AI management system — 38/38 Annex A controls and Clauses 4–10 feed GMI.

NIST AI RMF

GOVERN, MAP, MEASURE, MANAGE outcomes mapped into GMI dimensions.

EU AI Act

Provider, deployer, importer, distributor obligations — 42-row catalog covering Articles 4/11/43/47/49/53/55 and Annexes I–XIII.

SOC 2

61 Trust Services Criteria feed CGMI evidence and the External Auditor binding.

NIST CSF 2.0

GOVERN, IDENTIFY, PROTECT, DETECT, RESPOND, RECOVER outcomes feed CGMI.

DOE Cybersecurity Capability Maturity Model (C2M2)

Domain-level practices feed CGMI dimension scoring.

CIS Controls v8.1

Implementation Group safeguards roll up through the multi-link adapter into CGMI.

SEC / FINRA

Hedge Fund Mode obligations contribute to both GMI and CGMI where applicable.

WHAT MOVES A TENANT UP THE TIERS

Governance operations evidence raises the score

Maturity rises when a program runs, not when it is written down. These signals come straight from Governance Operations & Decision Rights and feed the GMI and CGMI dimensions that set your TGP tier.

  • Council cadence held and minuted — meetings that happened, with the decisions they produced.
  • Decision register depth — approvals and refusals recorded with the authority behind each one.
  • Exception hygiene — waivers that carry owners and expiry dates, and close before they lapse.
  • Escalation discipline — stalled items that moved up the ladder instead of stalling silently.
  • Authority coverage — an authority matrix that names an approver for every asset type and risk level.
Editions

Where the Maturity Dashboard ships

Professional

Full Maturity Dashboard with GMI, CGMI, TGP, trend, gap callouts, and PowerGRYD pyramid drill-down.

Enterprise

Adds the AIMS Audit Readiness, Hedge Fund, and Operations companion reports plus per-department maturity rollups.

Partner Portal

Governance Maturity Fleet publishes GMI, CGMI, and TGP for every client tenant in one table — included with MSP partnership.

Frequently asked questions

What is the Unified AI + Cyber Maturity Model?

It is RAIC's single scoring framework for both AI governance and cyber governance. One Controls Register, one Systems Registry, and one Risk Register feed three coherent scores — GMI for AI, CGMI for cyber, and a combined Total Governance Posture (TGP) — instead of two disconnected dashboards. Mapping a control once satisfies ISO 42001, NIST AI RMF, the EU AI Act, SOC 2, NIST CSF 2.0, CIS Controls v8.1, C2M2, and SEC/FINRA at the same time.

What is GMI (Governance Maturity Index)?

GMI is the AI-governance score. Eight dimensions — Policy, Inventory, Risk, Controls, Evidence, Operations, People, and Assurance — are each scored 0 to 5 against the RAIC maturity rubric and weighted into a single index. GMI rolls up evidence from the AI Systems Registry, Use Case Register, AI controls, attestations, supplier reviews, AI policies, and audit findings.

What is CGMI (Cyber Governance Maturity Index)?

CGMI is the cyber-governance score. Nine cyber-governance dimensions are each scored 0 to 5 and weighted to a single index: Risk & Vulnerability Management, Incident Detection & Response, Cyber Governance & Policy, Identity & Access Management, Data Security & Privacy, Third-Party & Supply Chain, Asset & Configuration Management, Workforce, Culture & Awareness, and Business Continuity & Resilience. CGMI maps to NIST CSF 2.0, CIS Controls v8.1, C2M2, and SOC 2. It is fed by cyber controls, NHI inventory, Azure secret-expiry signals, the Shadow AI Catalog, and phishing-simulation results.

What is TGP (Total Governance Posture) and how is it calculated?

TGP is a single board-ready number that blends GMI and CGMI 50/50. It is published on the Maturity Dashboard alongside a 12-month trend, per-dimension gap callouts, and a drill-down into the PowerGRYD five-layer governance pyramid. TGP also tiers your posture: Gold at 4.0 or higher (Optimized), Silver from 2.5 to 3.9 (Managed), and Bronze under 2.5 (Initial).

What dimensions feed GMI and CGMI?

GMI (AI, 8 dimensions): Policy, Inventory, Risk, Controls, Evidence, Operations, People, Assurance. CGMI (Cyber, 9 dimensions, in weighted priority order): Risk & Vulnerability Management, Incident Detection & Response, Cyber Governance & Policy, Identity & Access Management, Data Security & Privacy, Third-Party & Supply Chain, Asset & Configuration Management, Workforce, Culture & Awareness, Business Continuity & Resilience. Both rubrics use the same 0–5 scoring shape and render on the same Maturity Dashboard chart, but the dimensions themselves are domain-specific.

Which frameworks roll up into GMI, CGMI, and TGP?

ISO/IEC 42001, NIST AI RMF, and the EU AI Act drive GMI. SOC 2 (61 TSCs), NIST CSF 2.0, C2M2, and CIS Controls v8.1 drive CGMI. SEC and FINRA obligations apply to both sides when Hedge Fund Mode is enabled. Because every framework links back to the same controls and evidence, the maturity score and the framework coverage rollup move together — no spreadsheet reconciliation.

How does the Maturity Dashboard relate to PowerGRYD pyramid reports?

The Maturity Dashboard is the executive view — GMI, CGMI, TGP, trend, and the per-dimension breakdown. PowerGRYD is the operating view — five governance layers (Foundation, Policy, Operate, Assure, Improve) with per-layer scoring, integrity calculation, and drill-down into the underlying registers. The dashboard links into PowerGRYD wherever a dimension or layer needs investigation.

How do MSPs see maturity across their entire client fleet?

The Partner Portal includes a Governance Maturity Fleet view that publishes GMI, CGMI, and TGP for every client tenant in one table, with trend arrows and gap flags. Combined with Fleet Reports v2 (Compliance, AIMS Audit Readiness, NHI & Azure Hygiene, Operations, Hedge Fund), it gives partners a single screen for portfolio-level governance posture.

Which editions include the Maturity Dashboard?

The Maturity Dashboard, PowerGRYD pyramid reports, and Governance Maturity Fleet are included in Professional and Enterprise editions. MSP partners get the Fleet view in the Partner Portal at no per-seat cost.

See your TGP score

Start a free trial to publish GMI, CGMI, and TGP from your own registry, or see a demo to walk through the Maturity Dashboard with our team.