Sample consultancy report
Northwind Retail: Identity Security
Where AI has moved into this function, whether the controls kept up, and the one move that earns the next rung. Read in five minutes; decided in one meeting.
- Prepared on
- The aisecurityskills function diagnostic
- Basis
- Cloud Security Alliance (CSA) AI Controls Matrix (AICM) · AI Security Maturity Model (AISMM) × AI Cyber Maturity Model (AI-CMM)
- Evidence state
- Illustrative · fictional organisation
- Issued
- 18 Jul 2026
The verdict
Autonomy is pressing the gate: joiner-mover-leaver and provisioning already run augmented while named supervision and access-review cadence still trail.
Northwind Retail's identity security function reads at L2.5 governance against L2.2 autonomy: a mid-band retail posture where the gate is already under pressure. An identity policy, MFA on AI control planes, and least privilege on models and pipelines are in place. What presses the gate is the climb on joiner-mover-leaver and access provisioning while role-change speed, scheduled access review, agent-tighter limits, and named supervision of AI-assisted identity work remain only partial or absent. Governance must finish those rungs before autonomy claims another step.
Governance
L2.5
AI Security Maturity Model (AISMM) · how well it is secured
Autonomy
L2.2
AI Cyber Maturity Model (AI-CMM) · how far AI has gone
The gate
Shut
autonomy is running ahead of its controls
Where this function stands
The whole method in one drawing. Governance runs across, autonomy runs up, and the staircase is the gate: each governance level earned is the autonomy an organisation may responsibly claim.
What was measured
Two ladders, one instrument. Each answer maps to a Cloud Security Alliance AI Controls Matrix (AICM) control; a category claims a level only when that tier is evidenced, and an absent control caps it. The same rule scores every live run.
How well it is secured
L2.5
The CSA AI Security Maturity Model (AISMM): every answer maps to an AI Controls Matrix (AICM) control, and a level is claimed only when the tier is evidenced.
How far AI has gone
L2.2
The AI Cyber Maturity Model (AI-CMM): where the human sits in each workflow — in, on, then over the loop. our model · calibrated to SAE J3016.
Held below the next tier: IAM-18 absent
Held below the next tier: tier 3 not yet evidenced
Findings
Three, ranked, classified by what leadership does with each: act on a priority, protect a strength, and hold a deliberate choice.
- 01Priority
Named supervision and access review trail the autonomy already claimed
Joiner-mover-leaver and provisioning run augmented, yet scheduled access review is only partial, agent-tighter access limits are absent, and named accountability for AI-assisted identity work is still partial. That is the pressure on the gate: autonomy has moved ahead of the Capable evidence Governance still needs.
The exact control ids (for your security and governance, risk and compliance team)
IAM-08 · IAM-18 · GRC-15
- 02Strength
Identity policy, MFA, and least privilege reach Defined
A written rule covers who and what can reach AI systems, MFA is required on control-plane sign-in, and least privilege is enforced on models, training data, and pipelines. Analysts are trained on safe AI use. That floor is what the mid-band read rests on.
The exact control ids (for your security and governance, risk and compliance team)
IAM-01 · IAM-13 · IAM-05 · HRS-15
- 03By design
Recertification stays manual while lifecycle automation climbs
Identity recertification is held at Manual and break-glass plus access review stay assisted on purpose. Role-change speed is only partial. That restraint keeps the composite adopt average from closing the gate while named supervision and agent limits catch up.
The exact control ids (for your security and governance, risk and compliance team)
IAM-07 · IAM-08 · HRS-15
The climb
Direction, not a how-to: the next rung, and the governance that must move before autonomy does.
- Next quarter
Name accountable supervision for AI-assisted identity work and close the role-change partial so Governance and IAM can evidence Capable together.
- Two quarters
Put access review on a schedule with exception chase-down, then define tighter limits for autonomous agents before lifting break-glass another autonomy rung.
- Continuous
Hold MFA and least-privilege enforcement through each identity and agent change; re-run the diagnostic before lifting recertification off Manual.
About this instrument
What a reader should carry out of the room: how the diagnostic works, how progress is tracked, and what the practice is for.
One questionnaire, two reads
Every answer maps to a Cloud Security Alliance AI Controls Matrix (AICM) control. Read one way, the answers grade the function: governance versus autonomy, joined by the gate. Read the other way, the same answers name the skills each person in the function must acquire. Diagnosis and reskilling from one sitting.
Tracked, not judged
The first run is a baseline, never a verdict. Re-assess after the work and the radar overlays the previous run, so leadership sees movement, not a grade. The compatible-standard packs (ISO/IEC, the National Institute of Standards and Technology, and the CSA AI Consensus Assessments Initiative Questionnaire) are lenses on the same answers: assess once, report many ways.
Direction, not a solution
AI is a moving target, so the report names the next rung and the governance that must move first — never a vendor stack or a how-to. The gate keeps the climb honest: autonomy is claimed only after the controls that catch it are in place.