← Back to Blog
AI maturity grid: 4 stages (Aspiring, Emerging, Engaged, Champion) across 5 dimensions (Data, Technology, Process, People, Governance) — audit toolkit
Industry

AI audit toolkit for industrial mid-caps: grid, evidence, board-ready output

Tooled-up AI audit for industrial mid-caps: 5-dimension maturity grid, audit evidence (model cards, AI Act art. 12 logs), board-ready quantified output. Operational version of the NIST AI RMF and IIA framework — distinct from an introductory method.

By Damien Godard

TL;DR: An AI audit at an industrial mid-cap cannot be reduced to a 4-step method. What separates an audit that triggers decisions from one that gathers dust is the audit toolkit: a maturity grid across 5 axes (Data, Technology, Process, People, Governance), audit evidence that is documented (model cards, decision log, runtime logs required by Article 12 of the AI Act), and board-ready output that turns the snapshot into a costed roadmap. The frameworks are public: NIST AI RMF 1.0 (Govern/Map/Measure/Manage), IIA AI Auditing Framework (2024 update), BCG AI Maturity Matrix (4 stages), Forrester AI Maturity Assessment (6 competencies), MIT CISR Enterprise AI Maturity Model (4 stages), ENISA Multilayer Framework (AI cybersecurity). This article gives you the full operational toolkit for an industrial mid-cap, aligned with these frameworks and the practice of internal audit.

"Audit ia" captures 320 monthly searches in France (DataForSEO, collected 28/09/2026); "audit intelligence artificielle" triggers a Google AI Overview — a signal of a tooling demand, not an introductory one. Yet most content ranking for these queries is "method in 4 steps" — describing how without providing what with. Our article AI audit: a step-by-step method for your business covers the how — governance, mapping, measuring, managing. This one covers the what with: the tools, frameworks, evidence and reporting format that transform an audit from a one-off deliverable into a board decision.

This article targets industrial directors, CISOs, data/AI leaders, internal auditors and consulting teams at industrial PMEs and mid-caps. You will find the tooled-up framework — maturity grid, required evidence, reporting model — to move from a descriptive audit to a decision-grade one, without reinventing the toolkit on every engagement.

Why a Toolkit, Not Only a Method

A method alone is not enough. Three reasons, observed in the field with French industrial mid-caps and documented by major advisory firms.

First, traceability. Without a public framework, an audit is just an opinion: "we estimate your system is at 6/10 on bias." No year-on-year comparison, no sectoral benchmark, no defensible answer to a regulator. The NIST AI Risk Management Framework (AI RMF) 1.0, published on 26 January 2023 by NIST, organises the audit around four functions — Govern, Map, Measure, Manage — with verifiable categories and subcategories (NIST AI RMF Core, AI RMF 1.0 (2023)). That is the tooled-up thread, distinct from a "method in 4 steps": every subcategory is a requirement you can mark acquired / partial / absent.

Second, independence. An internal audit looks at its own systems. The Institute of Internal Auditors (IIA), in the 2024 update of its Artificial Intelligence Auditing Framework, formalises the three lines of defence model applied to AI — operational teams (1st line), risk and compliance functions (2nd line), independent internal audit (3rd line) (IIA, AI Auditing Framework, 2024). Without tooling (grid, evidence, standardised reporting), the 3rd line cannot challenge the 1st.

Third, the cyber spillover. The European Union Agency for Cybersecurity (ENISA) published in 2024 a Multilayer Framework for Good Cybersecurity Practices for AI, which stacks three layers — cyber foundations, AI-specific cybersecurity, sector-specific cybersecurity (ENISA, Multilayer Framework (2024)). For an industrial mid-cap, the AI audit is also a cyber audit: the two operate in different frameworks, but must share the same evidence.

To be confirmed by Damien: the exact list of NIST/IIA subcategories we retain in our internal grid is an audit deliverable — it varies by scope, sector and system criticality. What follows gives the tooled-up structure (5 dimensions, 4 stages, required evidence), not a closed proprietary grid.

Audit Scope: What to Audit (and What to Exclude)

The first tooled-up act of the audit is to bound the scope. Without a framework, the audit drifts toward a full inventory ("audit every model") and never completes. The scoping rule is two questions:

  • Risk question: does the system take a decision that touches a person (hiring, credit, critical maintenance, safety quality)? If yes, it enters the "high-risk" perimeter under Annex III of the AI Act (Timelex, 7 steps to identify high-risk AI systems). If no, it can leave the perimeter or be audited lightly.

  • Materiality question: does the system have a measurable impact on revenue, compliance, safety or reputation? If not, it can be audited by exception, not in the annual plan.

Once the list of critical systems is set, you classify each system on two axes:

Axis Tooled question Audit output
AI Act risk Is the system "high-risk" under Annex III? Category: high / limited / minimal
Maturity Is the system documented, tested, supervised? Grid score (see § below)
Business criticality What is the impact of an error on revenue / compliance? Level 1/2/3

This triplet (regulatory risk, maturity, criticality) becomes the arbitration matrix: a high-risk + high-criticality system = priority audit; a minimal-risk + low-criticality system = light or deferred audit.

The AI Maturity Grid: 4 Stages × 5 Dimensions

A maturity grid turns an opinion ("this system is half-controlled") into a reproducible score — comparable over time, between peers, defensible to a third party. Several frameworks coexist. Three are particularly actionable for an industrial mid-cap.

The BCG AI Maturity Matrix (Boston Consulting Group, AI Maturity Matrix, Nov 2024) segments organisations into 4 stages — Aspiring, Emerging, Engaged, Champion — and assesses maturity across 5 dimensions: Data, Technology, Process, People, Strategy (BCG, AI Maturity Matrix, 11/2024). The move from Emerging to Engaged marks the threshold where use cases go into production; Champion designates organisations that capture value at scale and reinvest in data and people (BCG, Build for the Future 2025).

The MIT CISR Enterprise AI Maturity Model segments into 4 stages (Stage 1 AI Capability, 0-49 %; Stage 2, 50-74 %; Stage 3, 75-99 %; Stage 4, 100 %), on a measure of Total AI Effectiveness that aggregates three dimensions: effectiveness at improving operations, customer experience, and ecosystem (MIT CISR, Building Enterprise AI Maturity, 12/2024).

The Forrester AI Maturity Assessment segments into 6 core competencies — strategy, governance, operating model, talent, technology, activation — scored on 5 levels (Forrester, Assess Your AI Maturity, 09/2025).

For an industrial mid-cap audit, we use a synthetic 5 × 4 grid — a tooled-up adaptation of the BCG AI Maturity Matrix — with the following 5 dimensions and a Champion target on each:

Dimension What we assess Typical stages observed (industrial mid-cap)
Data Availability, quality, governance, traceability Emerging on average; Champion rare
Technology Stack, MLOps, supervision, performance Engaged on MLOps-mature sites
Process Mapping, audit cycles, incident management Emerging; Engaged after 2-3 iterations
People AI skills, culture, human oversight Often lagging — first workstream
Governance Responsibilities, AI Act compliance, register Most often Aspiring or Emerging

The typical gap for a French industrial mid-cap, per the latest Deloitte State of AI in the Enterprise survey (2026 report): only 30 % of organisations say they are highly prepared on AI risk and governance, against 42 % on strategy (Deloitte, State of AI in the Enterprise, 2026). The tooled-up grid makes that gap visible — that is its first value.

To be confirmed by Damien: the weighting of the 5 dimensions depends on context (safety-first vs. production vs. customer-facing). For a manufacturing industrial mid-cap, Governance and Data are typically weighted 1.3-1.5× the other axes. This choice is an audit deliverable, not a generic parameter.

Audit Evidence: What Must Be Documented

A grid without evidence is still an opinion. The toolkit requires four minimal evidence types, verifiable by a third party.

1. The System Card / Model Card

For each system in scope: purpose, input data, training data, business owner, technical owner, production date, version, upstream dependencies (third-party models), measured performance indicators, incident history. The structure draws on the model cards proposed by the NIST AI RMF in its Map function (NIST AI RMF Core).

2. The Decision Log

For systems that assist or replace a human decision: trace of each automated decision, validated or challenged by a human, with timestamp and identifier. This log is required by European AI regulation — Article 12 of the AI Act (Regulation (EU) 2024/1689) requires high-risk AI systems to have "capabilities to automatically record events (logs) over the lifetime of the system," with a level of traceability appropriate to the intended purpose (AI Act Service Desk, European Commission, Article 12). For deployers, Article 26(6) requires retention of logs for at least six months, unless a longer period is provided by national or sectoral law (EUR-Lex, Regulation (EU) 2024/1689, Article 26).

3. Test and Surveillance Evidence

Documented bias tests (groups tested, metrics, results), adversarial tests where applicable, out-of-sample performance tests, in-production surveillance (data drift, concept drift). The NIST AI RMF, Measure function, insists: "analyze, assess, benchmark, and monitor AI risk and related impacts" (NIST AI RMF Core). Without surveillance evidence, the maturity score cannot exceed Engaged — moving to Champion requires continuous documented surveillance.

4. Governance Evidence

Minutes of governance reviews, appointment of responsible parties (AI owner, data owner, risk owner), register of production go-live and decommission decisions, incident escalation. The IIA, in its 2024 framework, insists on documentation of roles and responsibilities as a basic internal audit requirement (IIA, AI Auditing Framework, 2024).

To be confirmed by Damien: retention duration for logs and system cards depends on sector, sectoral regulatory framework (health, energy, transport) and "high-risk" status under the AI Act. Six months is a legal minimum for AI Act deployers; internal audit practice commonly uses 12 to 24 months, and up to 10 years for providers' technical documentation under AI Act Article 18. No single duration fits all cases.

Board-Ready Output: Turning the Snapshot into a Decision

A tooled-up audit produces three distinct deliverables — not one. The board gets the right one; operations get the right one; internal audit keeps the right one. Conflating the three is the main cause of audits that trigger nothing.

Deliverable 1 — Board Synthesis (2 pages, ≤ 5 minutes of reading)

Four sections, no technical discussion:

  1. Scope: how many systems audited out of how many total; how many AI Act high-risk systems.
  2. Maturity score: overall score per dimension, gap to the Champion target, one number per dimension.
  3. Top 5 risks: those that block production go-live, not those that polish documentation.
  4. Decision submitted to the board: 3 to 5 go / no-go / conditional decisions, costed.

This deliverable triggers the budget arbitration. Everything else is appendix.

Deliverable 2 — 90-Day Action Plan (operational teams)

List of corrective actions, with one named owner per action, a deadline (≤ 90 days), an acceptance criterion. The IIA recommends that each audit finding carries an action owner, target date and acceptance criteria (IIA, AI Auditing Framework, 2024). Without these three fields, the action cannot be measured.

Deliverable 3 — Evidence Dossier (internal audit / regulator)

The set of system cards, decision logs, test evidence, governance evidence, and the maturity grid scored system by system. This is the dossier that answers the technical documentation obligation of the AI Act (Article 11 for providers) and lets a third-party auditor challenge the 1st line without having to investigate.

The Quantified Link: ROI and Risks in the Same Format

The decisive link between the three deliverables is quantification. Each identified risk is qualified (probability × impact, or equivalent NIST score) and each corrective action carries a quantified expected gain or risk avoided. That is what lets the board arbitrate in 5 minutes across 10 corrective actions: total cost, total gain, risk coverage.

Tooled-Up Framework vs Internal Audit Only: When to Bring in the Grid

A tooled-up framework is not a substitute for internal audit: it is a tool in service of internal audit, aligned with the IIA framework. The external grid is deployed in three cases.

Case 1 — Independence. When the team that designed or deployed the system is also auditing it. The tooled-up grid, applied by a third party, breaks confirmation bias.

Case 2 — AI Act high-risk system. For systems listed in Annex III, internal audit covers the basics (governance, documentation, surveillance) but regulatory compliance (conformity assessment, CE marking, EU database) requires an external qualified view. The tooled-up grid becomes the pre-audit that prepares the notified body's mission.

Case 3 — Investment decision > €100k. When a board must arbitrate a structuring AI investment, the tooled-up grid and quantified reporting give the arbitration basis. Without a framework, arbitration happens on the vendor's slide-deck — an audit that ends as a sales brochure.

The "Once-and-for-All" Audit Trap

Audit is not an event, it is a cycle. The NIST AI RMF is explicit: AI risk management is "continuous, timely, and performed throughout the AI system lifecycle" (NIST AI RMF Core). A snapshot grid has a 6-12 month lifetime at a mid-cap that deploys regularly — less at one that iterates fast.

Tooled-up practice retains three cadences:

  • Weekly: continuous surveillance of systems in production (drift, performance, incidents).
  • Quarterly: maturity grid review, current scoring, Top 5 risks update.
  • Annual: full audit, board output, 90-day action plan.

Without this cadence, the latest snapshot is obsolete before it is presented — and the board knows it.

What a Tooled-Up Audit Changes, in One Decision

A tooled-up audit does not promise AI Act compliance, ISO 42001 certification, or risk elimination. It produces three decisions that an audit without a framework does not:

  1. Stop / continue / condition each system in scope, with an explicit reason.
  2. Invest / defer / retire each use case, with an expected gain and a quantified risk.
  3. Allocate / transfer / assume responsibility for each system, with a named role.

This triple arbitration distinguishes an audit from a report. The 4-step method provides the motion; the tooled-up framework provides the memory and language that make decisions comparable, traceable and defensible.

FAQ — AI Audit Toolkit for Industrial Mid-Caps

What is a tooled-up AI audit framework? A tooled-up framework combines three elements: a standardised maturity grid (5 dimensions × 4 stages), documented audit evidence (model cards, logs, test and governance evidence), and board-ready quantified output with three formats (2-page synthesis, 90-day action plan, evidence dossier). It is opposed to a descriptive method without tooling, which produces findings but not comparable decisions.

Which AI maturity grid to use for an industrial mid-cap? Three frameworks are actionable: the BCG AI Maturity Matrix (4 stages × 5 dimensions: Data, Technology, Process, People, Strategy), the MIT CISR Enterprise AI Maturity Model (4 stages, Total AI Effectiveness measure), and the Forrester AI Maturity Assessment (6 competencies × 5 levels). For an industrial mid-cap, a 5 × 4 grid adapted from BCG is the right balance of granularity and operability.

What evidence must an AI audit contain? Four minimal evidence families: the system card (purpose, data, owners, lifecycle), the decision log of human and automated decisions (AI Act Article 12 logs for high-risk systems), test and surveillance evidence (bias, performance, drift), and governance evidence (roles, responsibilities, decision register). Without these four families, the maturity score cannot exceed Engaged.

What should a board-ready AI audit output contain? Three distinct deliverables: a 2-page synthesis (scope, maturity score, Top 5 risks, 3-5 decisions submitted to the board), a 90-day action plan (each action with named owner, deadline, acceptance criterion), and a complete evidence dossier for internal audit or notified body.

How often should an AI audit be repeated? Three overlapping cadences: weekly for continuous surveillance of systems in production, quarterly for the maturity grid review and Top 5 risks, annual for the full audit and board output. A mid-cap that iterates fast (< 6 months per cycle) shortens the annual cadence.

Conclusion: A Toolkit, Not Another Method

The AI audit for an industrial mid-cap cannot rely on a method alone. The 4-step method provides the motion; the tooled-up framework provides the common language, the verifiable evidence and the reporting format that turn the snapshot into a board decision. That framework — maturity grid across 5 dimensions, required evidence, three-format reporting — is what distinguishes an audit that leads to arbitration from one that ends as a PDF.

The key is not to reinvent everything. The frameworks exist: NIST AI RMF, IIA AI Auditing Framework 2024, BCG AI Maturity Matrix, Forrester AI Maturity Assessment, MIT CISR, ENISA Multilayer Framework. The challenge is to apply them with the same grid, the same evidence, the same reporting format — system to system, year to year, site to site. That consistency is what makes the audit defensible, comparable and useful.

👉 Request a tooled-up AI audit — We bound your scope, score maturity system by system on the 5 × 4 grid, build the evidence dossier (model cards, logs, governance) and deliver a costed roadmap to the board.


Article published 5 October 2026 by Damien Godard. Frameworks cited: NIST AI Risk Management Framework (AI RMF 1.0, January 2023), IIA Artificial Intelligence Auditing Framework (2024 update), BCG AI Maturity Matrix (November 2024), MIT CISR Build Enterprise AI Maturity (December 2024), Forrester AI Maturity Assessment (September 2025), ENISA Multilayer Framework for Good Cybersecurity Practices for AI (2024), Deloitte State of AI in the Enterprise (2026 report), European Commission AI Act Service Desk (Article 12 and Article 26). "AI audit" volume: DataForSEO, France, collected 28/09/2026 (320 monthly searches). "Audit intelligence artificielle" search: Google AI Overview confirmed.