{
  "schema": "yarn-pack/2",
  "id": "ai-maturity",
  "version": "2.0.0",
  "name": "AI Maturity (Agile Yarn)",
  "engagement": "AISG — AI maturity pre-read / front-door",
  "intro": "A short, guided conversation — not a form. Answer in your own words; attach a document if it helps. Takes 15–25 minutes.",
  "tone_default": "professional",
  "prefill_fields": {
    "department": [
      "Executive",
      "Finance",
      "Operations",
      "Customer / Sales",
      "Technology / IT",
      "Data & Analytics",
      "People & Culture",
      "Risk & Compliance",
      "Marketing",
      "Product"
    ]
  },
  "scales": [
    {
      "id": "maturity5",
      "name": "Maturity (distilled model)",
      "levels": [
        {
          "value": 1,
          "label": "Does not exist",
          "gloss": "No capability. Absent, or purely ad hoc / accidental."
        },
        {
          "value": 2,
          "label": "Partially exists",
          "gloss": "Emerging and inconsistent. Pockets of activity, not joined up."
        },
        {
          "value": 3,
          "label": "Fully exists",
          "gloss": "Defined, documented and operating across the organisation."
        },
        {
          "value": 4,
          "label": "Fully exists & optimised",
          "gloss": "Measured, refined and improving against targets."
        },
        {
          "value": 5,
          "label": "Fully exists & adaptive",
          "gloss": "Continuously self-adjusting; a source of advantage."
        }
      ],
      "signals": {
        "1": [
          "no ",
          "not ",
          "none",
          "never",
          "don't",
          "do not",
          "nothing",
          "absent",
          "unaware",
          "haven't",
          "ad hoc",
          "ad-hoc",
          "nonexistent",
          "no idea",
          "not really"
        ],
        "2": [
          "some ",
          "starting",
          "beginning",
          "emerging",
          "pilot",
          "trial",
          "informal",
          "inconsistent",
          "pockets",
          "a bit",
          "occasionally",
          "early",
          "experiment",
          "trying",
          "patchy"
        ],
        "3": [
          "documented",
          "defined",
          "standard",
          "standardised",
          "established",
          "policy",
          "framework",
          "process",
          "consistent",
          "across the",
          "in place",
          "formal",
          "governed",
          "rolled out"
        ],
        "4": [
          "measured",
          "metrics",
          "optimis",
          "improving",
          "kpi",
          "monitored",
          "reviewed",
          "refined",
          "benchmarked",
          "targets",
          "tracked",
          "mature",
          "regularly review"
        ],
        "5": [
          "continuous",
          "adaptive",
          "self-",
          "automated end",
          "best in class",
          "best-in-class",
          "competitive advantage",
          "industry leading",
          "always",
          "real-time monitoring",
          "feedback loop"
        ]
      }
    }
  ],
  "categories": [
    {
      "id": "strategy",
      "name": "AI Strategy",
      "order": 1,
      "target_default": 3
    },
    {
      "id": "value",
      "name": "AI Value",
      "order": 2,
      "target_default": 3
    },
    {
      "id": "org",
      "name": "AI Organisation",
      "order": 3,
      "target_default": 3
    },
    {
      "id": "people",
      "name": "AI People & Culture",
      "order": 4,
      "target_default": 3
    },
    {
      "id": "gov",
      "name": "AI Governance",
      "order": 5,
      "target_default": 3
    },
    {
      "id": "eng",
      "name": "AI Engineering",
      "order": 6,
      "target_default": 3
    },
    {
      "id": "data",
      "name": "AI Data",
      "order": 7,
      "target_default": 3
    }
  ],
  "audiences": [
    {
      "id": "exec",
      "name": "Executive / Strategy",
      "desc": "Leadership, strategy, investment",
      "deep_dive_sections": [
        "strategy_dd"
      ]
    },
    {
      "id": "data",
      "name": "Data / Engineering",
      "desc": "Builds & runs data and AI systems",
      "deep_dive_sections": [
        "data_dd",
        "eng_dd"
      ]
    },
    {
      "id": "gov",
      "name": "Risk / Governance / Legal",
      "desc": "Risk, compliance, responsible AI",
      "deep_dive_sections": [
        "gov_dd"
      ]
    },
    {
      "id": "people",
      "name": "HR / Change / People",
      "desc": "Workforce, skills, adoption",
      "deep_dive_sections": [
        "people_dd"
      ]
    },
    {
      "id": "biz",
      "name": "Business / Product",
      "desc": "Operates a business unit or product",
      "deep_dive_sections": []
    }
  ],
  "sections": [
    {
      "id": "core",
      "title": "Core capabilities",
      "blurb": "Everyone answers these.",
      "optional": false,
      "questions": [
        {
          "id": "vision",
          "type": "scored_text",
          "category": "strategy",
          "name": "AI vision & ambition",
          "text": "How clear is your organisation's vision and ambition for AI? Is there a documented AI strategy, and who owns it?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "ai_drafted": false
        },
        {
          "id": "roadmap",
          "type": "scored_text",
          "category": "strategy",
          "name": "AI roadmap & investment",
          "text": "Is there a roadmap for AI with short- and long-term priorities? How are AI investments decided and sequenced?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "ai_drafted": false
        },
        {
          "id": "prioritise",
          "type": "scored_text",
          "category": "value",
          "name": "Use-case prioritisation",
          "text": "How do AI use cases get identified, evaluated and prioritised? Walk me through how a new idea becomes a funded project.",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "ai_drafted": false
        },
        {
          "id": "businesscase",
          "type": "scored_text",
          "category": "value",
          "name": "Business cases & value tracking",
          "text": "How do you build the business case for an AI initiative, and how is value actually measured after it ships?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "ai_drafted": false
        },
        {
          "id": "operatingmodel",
          "type": "scored_text",
          "category": "org",
          "name": "AI operating model",
          "text": "How is AI organised — central team, embedded, federated? Is there a defined operating model, or is it improvised per project?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "ai_drafted": false
        },
        {
          "id": "culture",
          "type": "scored_text",
          "category": "people",
          "name": "AI culture & change",
          "text": "How would you describe the organisation's appetite for AI? How is adoption and change managed?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "ai_drafted": false
        },
        {
          "id": "skills",
          "type": "scored_text",
          "category": "people",
          "name": "AI skills & gaps",
          "text": "How well do you understand the AI skills you have versus what you need? Is there a plan to close the gaps?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "ai_drafted": false
        },
        {
          "id": "training",
          "type": "scored_text",
          "category": "people",
          "name": "AI training & literacy",
          "text": "What AI training, upskilling or literacy programs exist, and who actually has access to them?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "ai_drafted": false
        },
        {
          "id": "ethics",
          "type": "scored_text",
          "category": "gov",
          "name": "Responsible AI policy",
          "text": "What policies or principles govern responsible and ethical use of AI? Are they actually enforced, or shelfware?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "ai_drafted": false
        },
        {
          "id": "risk",
          "type": "scored_text",
          "category": "gov",
          "name": "AI risk framework",
          "text": "How are AI-specific risks identified and managed? Is there a risk framework or register for AI?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "ai_drafted": false
        },
        {
          "id": "compliance",
          "type": "scored_text",
          "category": "gov",
          "name": "Compliance monitoring",
          "text": "How do you monitor and enforce compliance with AI policies and legal/regulatory obligations?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "ai_drafted": false
        },
        {
          "id": "architecture",
          "type": "scored_text",
          "category": "eng",
          "name": "AI architecture & platform",
          "text": "Describe the platforms and infrastructure you use to build and run AI. How standardised is it across teams?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "ai_drafted": false
        },
        {
          "id": "deploy",
          "type": "scored_text",
          "category": "eng",
          "name": "Deploy & operate AI",
          "text": "Once an AI solution is built, how does it get deployed, monitored and supported in production?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "ai_drafted": false
        },
        {
          "id": "dataacquire",
          "type": "scored_text",
          "category": "data",
          "name": "Acquire & prepare data",
          "text": "How easily can teams get the data they need for AI? Walk me through sourcing and preparing it.",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "ai_drafted": false
        },
        {
          "id": "dataquality",
          "type": "scored_text",
          "category": "data",
          "name": "Data quality & integrity",
          "text": "How confident are you in the quality, completeness and consistency of data used for AI?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "ai_drafted": false
        },
        {
          "id": "datagov",
          "type": "scored_text",
          "category": "data",
          "name": "Data governance for AI",
          "text": "What governance exists over data used in AI — ownership, access controls, lineage?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "ai_drafted": false
        },
        {
          "id": "datasec",
          "type": "scored_text",
          "category": "data",
          "name": "Security & privacy for AI data",
          "text": "How is sensitive data protected when used in AI? Any privacy controls specific to AI?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "ai_drafted": false
        }
      ]
    },
    {
      "id": "strategy_dd",
      "title": "Strategy deep-dive",
      "blurb": "Extra depth for the areas you know best.",
      "audience": [
        "exec"
      ],
      "optional": false,
      "questions": [
        {
          "id": "trendscan",
          "type": "scored_text",
          "category": "strategy",
          "name": "Trend scanning",
          "text": "How do you monitor and interpret emerging AI trends and assess their impact on your business?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "ai_drafted": false
        },
        {
          "id": "readiness",
          "type": "scored_text",
          "category": "strategy",
          "name": "Readiness measurement",
          "text": "Do you formally assess organisational readiness for AI? How?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "ai_drafted": false
        },
        {
          "id": "innovation",
          "type": "scored_text",
          "category": "value",
          "name": "Innovation & experimentation",
          "text": "How are new AI ideas and experiments fostered, captured and scaled?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "ai_drafted": false
        },
        {
          "id": "ecosystem",
          "type": "scored_text",
          "category": "org",
          "name": "Ecosystem & partnerships",
          "text": "How do you use external partners, vendors and alliances in your AI strategy?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "ai_drafted": false
        }
      ]
    },
    {
      "id": "data_dd",
      "title": "Data deep-dive",
      "blurb": "Extra depth for the areas you know best.",
      "audience": [
        "data"
      ],
      "optional": false,
      "questions": [
        {
          "id": "dataprep",
          "type": "scored_text",
          "category": "data",
          "name": "Data prep & feature engineering",
          "text": "How mature are your data preparation and feature-engineering practices for AI?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "ai_drafted": false
        },
        {
          "id": "dataintegration",
          "type": "scored_text",
          "category": "data",
          "name": "Data integration",
          "text": "How well integrated are your data sources for AI use, internal and external?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "ai_drafted": false
        },
        {
          "id": "lineage",
          "type": "scored_text",
          "category": "data",
          "name": "Data lineage & traceability",
          "text": "Can you trace the origin and transformation of data feeding AI models?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "ai_drafted": false
        },
        {
          "id": "metadata",
          "type": "scored_text",
          "category": "data",
          "name": "Metadata & semantics",
          "text": "What metadata, cataloguing or semantic-layer capabilities support AI?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "ai_drafted": false
        },
        {
          "id": "observability",
          "type": "scored_text",
          "category": "data",
          "name": "Data observability",
          "text": "How do you monitor the health and behaviour of data over time?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "ai_drafted": false
        },
        {
          "id": "analytics",
          "type": "scored_text",
          "category": "data",
          "name": "Analytics & visualisation",
          "text": "How are analytics and visualisation used to support AI insight?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "ai_drafted": false
        }
      ]
    },
    {
      "id": "eng_dd",
      "title": "Engineering deep-dive",
      "blurb": "Extra depth for the areas you know best.",
      "audience": [
        "data"
      ],
      "optional": false,
      "questions": [
        {
          "id": "buildvsbuy",
          "type": "scored_text",
          "category": "eng",
          "name": "Build vs buy",
          "text": "How do you decide build vs buy for AI capabilities? Is there a rule or is it case-by-case?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "ai_drafted": false
        },
        {
          "id": "buildapps",
          "type": "scored_text",
          "category": "eng",
          "name": "Building AI applications",
          "text": "Describe how AI applications and models actually get built and trained here.",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "ai_drafted": false
        },
        {
          "id": "testing",
          "type": "scored_text",
          "category": "eng",
          "name": "Testing AI systems",
          "text": "How are AI models and applications tested before and after release?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "ai_drafted": false
        },
        {
          "id": "techdebt",
          "type": "scored_text",
          "category": "eng",
          "name": "AI technical debt",
          "text": "How do you track and manage technical debt in AI systems?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "ai_drafted": false
        },
        {
          "id": "scale",
          "type": "scored_text",
          "category": "eng",
          "name": "Scaling AI systems",
          "text": "How do you scale AI systems that prove valuable?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "ai_drafted": false
        },
        {
          "id": "mlops",
          "type": "scored_text",
          "category": "eng",
          "name": "Operationalisation / MLOps",
          "text": "What MLOps practices keep AI running in line with service levels?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "ai_drafted": false
        }
      ]
    },
    {
      "id": "gov_dd",
      "title": "Governance deep-dive",
      "blurb": "Extra depth for the areas you know best.",
      "audience": [
        "gov"
      ],
      "optional": false,
      "questions": [
        {
          "id": "security",
          "type": "scored_text",
          "category": "gov",
          "name": "AI security & safety",
          "text": "What frameworks address AI-specific security and safety threats?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "ai_drafted": false
        },
        {
          "id": "legal",
          "type": "scored_text",
          "category": "gov",
          "name": "Legal & regulatory",
          "text": "How do you track and respond to AI legal and regulatory requirements?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "ai_drafted": false
        },
        {
          "id": "sustainable",
          "type": "scored_text",
          "category": "gov",
          "name": "Sustainable / cost governance",
          "text": "Are sustainability and cost-of-AI considerations governed at all?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "ai_drafted": false
        },
        {
          "id": "govteams",
          "type": "scored_text",
          "category": "gov",
          "name": "Governance teams & decision rights",
          "text": "Who governs AI? Are there cross-functional teams and clear decision rights?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "ai_drafted": false
        },
        {
          "id": "oversight",
          "type": "scored_text",
          "category": "gov",
          "name": "Oversight & assurance",
          "text": "What systems provide continuous oversight and assurance of AI in production?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "ai_drafted": false
        }
      ]
    },
    {
      "id": "people_dd",
      "title": "People deep-dive",
      "blurb": "Extra depth for the areas you know best.",
      "audience": [
        "people"
      ],
      "optional": false,
      "questions": [
        {
          "id": "workforce",
          "type": "scored_text",
          "category": "people",
          "name": "Workforce planning",
          "text": "How do you forecast and plan for AI's impact on roles and staffing?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "ai_drafted": false
        },
        {
          "id": "recruit",
          "type": "scored_text",
          "category": "people",
          "name": "AI talent acquisition",
          "text": "How do you attract and recruit AI talent?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "ai_drafted": false
        },
        {
          "id": "trainingeff",
          "type": "scored_text",
          "category": "people",
          "name": "Training effectiveness",
          "text": "How do you measure whether AI training actually changes anything?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "ai_drafted": false
        },
        {
          "id": "changemgmt",
          "type": "scored_text",
          "category": "people",
          "name": "Change management",
          "text": "How are AI-driven change initiatives executed and monitored?",
          "scale": "maturity5",
          "scored": true,
          "star": false,
          "ai_drafted": false
        }
      ]
    }
  ],
  "grids": {},
  "outputs": [
    "Overall maturity picture + by-area",
    "Contested-capability view",
    "Coverage check",
    "Confidence ramp",
    "Executive summary + priority gaps",
    "Printable client report"
  ],
  "report_defaults": [
    "rpt-maturity-standard"
  ],
  "playbook": {
    "sequence": [
      "strategy",
      "gov",
      "data",
      "org",
      "people",
      "eng",
      "value"
    ],
    "sequence_note": "Foundations first: strategy and governance decisions shape everything downstream; data and operating model make delivery repeatable; engineering and value work then compound instead of stalling.",
    "actions": {
      "strategy": {
        "to_2": [
          "Name an executive owner for AI and write down the ambition in one page: where AI matters to the business and where it does not.",
          "Inventory what is already happening with AI across the organisation, sanctioned or not."
        ],
        "to_3": [
          "Publish an AI strategy tied to business goals, with a 12–24 month roadmap and a decision forum that meets.",
          "Agree the handful of priority domains and say no to the rest for now."
        ],
        "to_4": [
          "Set measurable targets per priority domain and review progress against them each quarter.",
          "Fund the roadmap as a portfolio, not project by project."
        ],
        "to_5": [
          "Refresh the strategy on a cadence driven by results and market shifts, with scenario planning for model and regulatory change."
        ]
      },
      "value": {
        "to_2": [
          "Keep one shared list of AI use cases with an owner and a one-line value hypothesis each.",
          "Stop funding ideas that bypass the list."
        ],
        "to_3": [
          "Adopt a single intake and prioritisation method (value × feasibility × risk) and apply it to every candidate.",
          "Define what 'done' means for a pilot: a decision to scale, hold or stop, with the evidence required."
        ],
        "to_4": [
          "Track realised value against the hypothesis for every scaled use case and report it alongside cost.",
          "Retire or rework use cases that are not paying back."
        ],
        "to_5": [
          "Run the portfolio as a continuous funnel with stage gates, benchmarks and reinvestment of returns."
        ]
      },
      "org": {
        "to_2": [
          "Assign clear accountability for AI delivery, even if it sits in an existing team for now.",
          "Write down how an AI idea gets resourced today so the gaps are visible."
        ],
        "to_3": [
          "Choose an operating model (central, hub-and-spoke or federated) and staff the core roles: product, data, engineering, risk.",
          "Define the interfaces with IT, data and the business units."
        ],
        "to_4": [
          "Measure delivery throughput and cycle time and remove the recurring blockers.",
          "Formalise a community of practice that shares patterns and reusable components."
        ],
        "to_5": [
          "Let the model flex by domain with shared platforms and standards, and review it against outcomes annually."
        ]
      },
      "people": {
        "to_2": [
          "Run a skills stocktake: who can do what today, and who wants to learn.",
          "Give leaders a shared, plain-language briefing on what AI can and cannot do."
        ],
        "to_3": [
          "Put an AI literacy programme in place by role type, with a small number of deep specialists.",
          "Set expectations for how staff should and should not use AI tools, and support the change explicitly."
        ],
        "to_4": [
          "Tie AI skills to career paths and performance goals; measure adoption and confidence, not just attendance.",
          "Build change management into every AI rollout by default."
        ],
        "to_5": [
          "Sustain a learning culture where teams experiment safely and share what they learn across the organisation."
        ]
      },
      "gov": {
        "to_2": [
          "Adopt a short, enforceable responsible-AI policy covering acceptable use, data and human oversight.",
          "Create a register of AI systems in use and who owns each."
        ],
        "to_3": [
          "Stand up an AI risk assessment that every use case passes before build and before scale, proportionate to impact.",
          "Assign a governance forum with the authority to stop a deployment."
        ],
        "to_4": [
          "Monitor deployed systems for drift, bias and incidents, with defined response paths.",
          "Audit against the policy and the emerging regulatory obligations at least annually."
        ],
        "to_5": [
          "Embed governance into the delivery platform so compliance is largely automatic, and adapt controls as regulation and models change."
        ]
      },
      "eng": {
        "to_2": [
          "Pick one sanctioned path to build and run an AI solution, even if minimal, and route new work through it.",
          "Get the current pilots under source control and basic monitoring."
        ],
        "to_3": [
          "Standardise the platform: environments, model access, deployment pipeline, logging and cost controls.",
          "Define engineering standards for prompts, evaluation and testing of AI components."
        ],
        "to_4": [
          "Instrument quality, latency, cost and usage for every production system and act on the trends.",
          "Reuse components (retrieval, guardrails, evaluation) across use cases rather than rebuilding."
        ],
        "to_5": [
          "Run a self-service platform with automated evaluation and rollback, evolving as model capabilities shift."
        ]
      },
      "data": {
        "to_2": [
          "Identify the data the priority use cases depend on and who owns it.",
          "Fix the most damaging quality issues in that data first, not everywhere."
        ],
        "to_3": [
          "Put data governance in place for AI workloads: ownership, quality rules, classification, access controls and lineage.",
          "Make the priority data discoverable and reliably available to delivery teams."
        ],
        "to_4": [
          "Measure data quality and availability as a service level and report against it.",
          "Extend governance to unstructured content and model inputs and outputs."
        ],
        "to_5": [
          "Treat data as a managed product with automated quality, privacy-preserving access and continuous fitness-for-AI checks."
        ]
      }
    }
  }
}