The axes an organisation's maturity is measured against.
D1
Strategy & governance
Alignment of agentic AI usage with the business strategy, dedicated governance, executive sponsorship.
Practices: AI committee constituted. Documented agentic strategy. Identified executive sponsor. Ring-fenced annual budget. Usage metrics tracked at exec level.
D2
Doctrine & framework
Adoption of a reference framework (ACF® or equivalent), publication of an internal doctrine, team training.
Practices: Formalised reference framework. Published and accessible internal doctrine. Training plan deployed. Methodological cards in operational use.
D3
Design & technical control
Secure agent design (mandates, kill switches, observability), mastery of the foundation models in use.
Practices: Formal mandate for every N2+ agent. Documented and tested kill switch. End-to-end observability. Inventory of models in use.
D4
Accountability & roles
Explicit role definitions (DDAO, DPO, CISO, Compliance Officer, Business Owner) with a clear RACI on agentic decisions.
Practices: DDAO appointed per N2+ agent. Published RACI. Documented sign-off process by criticality. Formal delegations.
D5
Regulatory compliance
Mastery of AI Act, GDPR, DORA, NIS2, ISO 42001 obligations according to sector and jurisdiction.
Practices: Up-to-date AI inventory. System-level qualification (provider/deployer, controller/processor). DPIA for high-risk systems. Article 49 register if high-risk. Digital Omnibus compliance roadmap.
D6
Audit & continuous improvement
Periodic internal audit of agents in production, incident review, doctrine updates.
Practices: Annual audit minimum. Quarterly incident review. Documented doctrine updates. Post-mortems published internally.