Assessment FAQ · the coverage deliverable
A maturity grade without a control inventory is an opinion.
Every function diagnostic starts with one artefact: a YES / NO / NA answer for each of the 247 control objectives in the CSA AI Controls Matrix, across all 18 domains — every answer grounded in an evidence artefact, never a self-assertion.
A partial is shown as a partial; a gap is written down. Coverage fixes the territory before anyone grades it.
Why it comes first
Maturity measures how well you run controls. You can’t grade a control you never confirmed exists — so coverage is the floor the whole diagnostic stands on.
“Which controls are actually in place — with evidence — before we claim a maturity level?”
The answer
One evidence-backed answer per control: the defensible baseline.
The result isn’t a percentage; it’s a per-objective ledger you can hand to an auditor: what’s evidenced, what’s a justified NA, and every gap named. The maturity read and the remediation roadmap both build on it.
This is the long-form intro to the live crosswalk drill — the same artefact, walked by hand, with each objective’s specification and its authoritative mapping to ISO/IEC 42001, the EU AI Act, NIST AI 600-1, and BSI AIC4.