ai · security · skills

Assessment FAQ · the coverage deliverable

A maturity grade without a control inventory is an opinion.

Every function diagnostic starts with one artefact: a YES / NO / NA answer for each of the 247 control objectives in the CSA AI Controls Matrix, across all 18 domains — every answer grounded in an evidence artefact, never a self-assertion.

One control objectivee.g. IAM-05Evidence artefactbacks it?YES — fully evidencedNA — out of scope, justifiedNO — gap, written down

A partial is shown as a partial; a gap is written down. Coverage fixes the territory before anyone grades it.

Why it comes first

Maturity measures how well you run controls. You can’t grade a control you never confirmed exists — so coverage is the floor the whole diagnostic stands on.

“Which controls are actually in place — with evidence — before we claim a maturity level?”

The answer

One evidence-backed answer per control: the defensible baseline.

The result isn’t a percentage; it’s a per-objective ledger you can hand to an auditor: what’s evidenced, what’s a justified NA, and every gap named. The maturity read and the remediation roadmap both build on it.

This is the long-form intro to the live crosswalk drill — the same artefact, walked by hand, with each objective’s specification and its authoritative mapping to ISO/IEC 42001, the EU AI Act, NIST AI 600-1, and BSI AIC4.

The crosswalk drill, objective by objective →

Run the diagnostic on a function →
← Back to Insights

Subscribe for the next essay.