ai · security · skills

Sample consultancy report

Initech: Security Governance, Risk & Assurance

Where AI has moved into this function, whether the controls kept up, and the one move that earns the next rung. Read in five minutes; decided in one meeting.

Prepared on
The aisecurityskills function diagnostic
Basis
Cloud Security Alliance (CSA) AI Controls Matrix (AICM) · AI Security Maturity Model (AISMM) × AI Cyber Maturity Model (AI-CMM)
Evidence state
Illustrative · fictional organisation
Issued
18 Jul 2026
01

The verdict

An honest early-days starting point: a few foundational policies are written, while assurance, continuity, and provider risk still sit at Initial and most workflows stay human-run.

Initech's security governance, risk and assurance function reads at L1.7 governance against L1.6 autonomy: a small-software starting posture, not a finished programme. An AI governance programme, an AppSec policy for the apps teams assure, a threat-and-vulnerability policy covering AI components, and a written audit approach are in place. What keeps the read early-days is the rest: named risk ownership and supervision are only partial or absent, independent assurance and corrective-action tracking have not started, supplier and portability controls are unfinished, and AI-scoped continuity is still missing. Policy drafting and audit evidence run assisted; vendor risk, BCP exercises, and people-security reviews remain largely manual.

Governance

L1.7

AI Security Maturity Model (AISMM) · how well it is secured

Autonomy

L1.6

AI Cyber Maturity Model (AI-CMM) · how far AI has gone

The gate

Shut

autonomy is running ahead of its controls

02

Where this function stands

The whole method in one drawing. Governance runs across, autonomy runs up, and the staircase is the gate: each governance level earned is the autonomy an organisation may responsibly claim.

Initech on the governance-and-autonomy gridGovernance from L1 to L5 across, autonomy from L1 to L4 up. The gate staircase marks the autonomy each governance level has earned. Initech sits at governance 1.7, autonomy 1.6, inside the governed region.Ungoverned: ahead of controlsGoverned: earned autonomyInitech today · L1.7 / L1.6L1L2L3L4L5L1L2L3L4Governance (AISMM) → each level earned is autonomy allowedAutonomy (AI-CMM) ↑
The gate is the product’s one rule: autonomy must never outrun governance. This function sits at L1.7 governance, which allows autonomy up to L1 — and it runs at L1.6, inside the line. Climbing the wall, not the drop.
03

What was measured

Two ladders, one instrument. Each answer maps to a Cloud Security Alliance AI Controls Matrix (AICM) control; a category claims a level only when that tier is evidenced, and an absent control caps it. The same rule scores every live run.

How well it is secured

L1.7

InitialRepeatableDefinedCapableEfficient

The CSA AI Security Maturity Model (AISMM): every answer maps to an AI Controls Matrix (AICM) control, and a level is claimed only when the tier is evidenced.

How far AI has gone

L1.6

ManualAssistedAugmentedAutonomous

The AI Cyber Maturity Model (AI-CMM): where the human sits in each workflow — in, on, then over the loop. our model · calibrated to SAE J3016.

GovernanceL2 Repeatable · 1 of 5 evidenced

Held below the next tier: GRC-15 absent

App SecurityL2 Repeatable · 1 of 3 evidenced

Held below the next tier: AIS-04 absent

AI Supported Development and Supply Chain SecurityL2 Repeatable · 1 of 3 evidenced

Held below the next tier: TVM-03 absent

Privacy and ComplianceL2 Repeatable · 1 of 4 evidenced

Held below the next tier: A&A-02 absent

Risk & Provider Assessment & ManagementL1 Initial · 0 of 7 evidenced

Held below the next tier: tier 2 not yet evidenced

Infrastructure Security and ResilienceL1 Initial · 0 of 4 evidenced

Held below the next tier: BCR-01 absent

04

Findings

Three, ranked, classified by what leadership does with each: act on a priority, protect a strength, and hold a deliberate choice.

  1. 01Priority

    Assurance, continuity, and provider risk still sit at Initial

    Independent assessment, managed audit findings, and corrective-action tracking are absent. Continuity has no AI-scoped plan, and provider risk plus portability stay partial or absent. Those gaps are the board priority: without them the function cannot claim Defined beyond the four foundational policies.

    The exact control ids (for your security and governance, risk and compliance team)

    A&A-02 · BCR-01 · STA-01 · IPY-01

  2. 02Strength

    Four foundational policies are written and claim Defined

    An AI governance programme with documented policies, an application security policy covering AI-enabled apps, a threat-and-vulnerability policy for AI components, and a written audit-and-assurance approach are implemented. That floor is the honest early-days strength: starting points exist to build on.

    The exact control ids (for your security and governance, risk and compliance team)

    GRC-01 · AIS-01 · TVM-01 · A&A-01

  3. 03By design

    Most workflows stay human while Defined evidence finishes

    Policy drafting and audit evidence run assisted. Vendor risk, BCP exercises, and people-security reviews stay manual on purpose. Analyst training and named supervision of AI-assisted assurance are only partial or absent. That restraint keeps autonomy from outrunning the still-thin governance floor.

    The exact control ids (for your security and governance, risk and compliance team)

    HRS-15 · GRC-15 · GRC-02

05

The climb

Direction, not a how-to: the next rung, and the governance that must move before autonomy does.

  1. Next quarter

    Stand up independent assurance of the highest-risk AI areas and write an AI-scoped continuity policy so Privacy and Compliance and Infrastructure Security can evidence Defined.

  2. Two quarters

    Document supply-chain and portability approaches for AI providers, name supervision for AI-assisted assurance work, and close the risk-management partial so Governance and provider-risk categories can climb together.

  3. Continuous

    Hold the four foundational policies through each product and vendor change; re-run the diagnostic before lifting vendor-risk or BCP workflows another autonomy rung.

06

About this instrument

What a reader should carry out of the room: how the diagnostic works, how progress is tracked, and what the practice is for.

One questionnaire, two reads

Every answer maps to a Cloud Security Alliance AI Controls Matrix (AICM) control. Read one way, the answers grade the function: governance versus autonomy, joined by the gate. Read the other way, the same answers name the skills each person in the function must acquire. Diagnosis and reskilling from one sitting.

Tracked, not judged

The first run is a baseline, never a verdict. Re-assess after the work and the radar overlays the previous run, so leadership sees movement, not a grade. The compatible-standard packs (ISO/IEC, the National Institute of Standards and Technology, and the CSA AI Consensus Assessments Initiative Questionnaire) are lenses on the same answers: assess once, report many ways.

Direction, not a solution

AI is a moving target, so the report names the next rung and the governance that must move first — never a vendor stack or a how-to. The gate keeps the climb honest: autonomy is claimed only after the controls that catch it are in place.

Derived at build time from the Initech posture config through the live function-diagnostic scorer: the same questions, tiers, and gate every real run uses. A bank change re-derives this sample automatically; nothing here is hand-scored.

Initech is a fictional organisation; the postures are self-assessed sample data, never client results. Nothing in this report is certification, and no standards body has reviewed it.