Skip to main content

From AI ambition to dependable operations

A good model is only part of the answer.

AI adoption can stall—or expose the business to data breaches, manipulated decisions and unauthorized actions. Start with the business problem, then examine the complete AI–Data system.

START WITH THE FAILURE PATTERN

Three problems to resolve before scaling AI

A AI capability

A demo is not an evaluated operational service A demo screen points toward a service checklist, but a break in the connection marks an evidence gap. Plausible output alone does not establish accuracy or operational value. Demo Service Evidence gap

A demo is mistaken for a service

Plausible output is not proof of accuracy or operational value.

Test the task in its real workflow.

D + I Data + Integration

Untrusted facts and conflicting meaning weaken a decision Two source records converge on a broken connection before reaching a decision. Missing facts and incompatible definitions interrupt the path from information to a reliable result. Records Decision Facts or meaning missing

Untrusted facts weaken the result

Missing records and conflicting definitions turn decisions into rework.

Name the source. Align the meaning.

S + I Assurance + Integration

AI and data failures can cause breaches and loss Three separate illustrative risk paths. Failed access controls can disclose sensitive records, even through a read-only AI answer. Malicious instructions in a document can redirect a generative AI task through prompt injection and corrupt decisions. Excessive tool permissions without valid action approval can cause unauthorized changes, financial loss or service disruption. The broken links mean failed controls, not inevitable incidents. Data breach Records exposed AI manipulation Decisions redirected Unauthorized action Financial loss · disruption

AI security failures can expose the business

Failed access rules can leak records. Malicious content can redirect AI. Unchecked tools can cause loss or disruption.

Who can detect, contain, stop and recover?

Failure patterns to investigate—not a diagnosis of every organization. Domain labels show where to look, not the only responsibilities involved.

THE DAIS PHILOSOPHY

Readiness belongs to the complete use case.

Start with one business decision. Assess the whole use case, then agree what must improve.

  1. 01 Bound the decision

    Scope one use case

    One outcome with an explicit use-case boundary A single boundary contains the intended outcome, accountable owner, users, workflow and allowed effects. Keep this scope consistent throughout assessment and review. One outcome Owner Users Workflow Effects Explicitly permitted actions

    Name the problem, consequence and next decision.

  2. 02 Locate the gap

    Assess four capabilities

    Four domains assessed within the same use case Data: trusted facts. AI: an evaluated task. Integration: shared meaning and exchange. Assurance: control and evidence throughout. These are complementary domains, not sequential stages or scores. D Data Trusted facts A AI Tested task I Integration Meaning + flow S Assurance Control

    Use all 21 practices in the same boundary; identify gaps against the target.

  3. 03 Act and review

    Prioritize improvement

    A prioritized, owned improvement followed by evidence-based review A priority action names an owner, target and test. An arrow leads to review; a return arrow shows reassessment of the same use case with appropriate evidence. Priority action Named owner Target Test + evidence Review

    Agree the action and review date. Reassess with appropriate evidence.

No company average. Compare bounded profiles to find shared gaps; never average them into a company score.

No deployment authority. Readiness informs the decision. Named enterprise authorities still decide whether to proceed.

PEOPLE · CAPABILITIES · OPERATIONS · VALUE

DAIS as a business architecture

Teams own and operate the capabilities. Business modules use them in repeatable workflows. Value must be demonstrated in the resulting service—not assumed from the presence of AI.

  • Customer serviceCase → assist → resolve
  • OperationsPlan → decide → execute
  • FinanceRequest → review → reconcile
Choose one module and one bounded workflowExpand business architecture ↗

Read the relationships, not a maturity sequence. D supplies trusted data; I connects mandatory ontology, interfaces and confirmed effects; A supplies an evaluated, operated service. S applies across all modules: identity, protection, human control, release, evidence and recovery.

Text description and assessment boundary

The Data team stewards data products. AI/service owners evaluate and operate AI services. The Business team owns the task, decisions and outcome target. The Governance team sets policy and challenges evidence through Assurance controls. These are interacting roles, not a required organization chart or exclusive ownership of a DAIS domain.

Within a selected business module, frame the work, review and decide with AI assistance, then deliver and reconcile the permitted effect. Integration governs both incoming context and action/receipt contracts. Compare service, quality, cost and risk outcomes with the baseline; use outcome and control evidence for governed improvement. Rejected or unsafe work must be held or stopped; the main path does not show every exception.

Assess all 21 practices: five each for D, A and I, and six for S. Report the full profile and limiting conditions for the same bounded use case. Unknown remains unknown; neither the architecture nor a readiness score grants deployment approval or guarantees value. There is no automatic retraining or company-wide average.

Explore the technical architecture and enforcement boundaries →

FROM THE SYSTEM PICTURE TO ASSESSMENT

R = min(D, A, I, S)

R means overall readiness for this use case. It is the lowest of the four domain levels. Strength in one domain does not compensate for a missing condition in another; inspect the full profile, below-target items and blockers.

D

Data Readiness

Owned, fit, traceable, accessible, and recoverable data.

A

AI Capability

Bounded value, evaluated behaviour, controlled lifecycle, adoption, and service ownership.

I

Integration Readiness

Governed interfaces, context, timeliness, actions, effects, and reconciliation.

S

Assurance Readiness

Identity, protection, human control, release, evidence, incident response, and recovery.

HOW THE RESULT IS CALCULATED

One scale from evidence to readiness.

The unit of assessment is one bounded AI-enabled use case. Use the same boundary and reporting period across all domains, and label the assessment depth. Public claims use optional evidence notes; controlled conclusions require the full evidence procedure.

01ITEM LEVEL

Assess each DAIS item

Select the highest cumulative Level 0–4 anchor whose complete conditions are supported. Unknown remains unknown.

02DOMAIN LEVEL

Take each domain minimum

D, A, I, and S are each set by the lowest applicable item in that domain.

03READINESS

Take the DAIS minimum

R is the minimum of the four domain levels. The limiting domain defines the next capability gap.

ONE SHARED MATURITY SCALE

Level 0–4 applies across all DAIS domains.

Select a column to see the Data, AI, Integration, and Assurance conditions at that level. These summaries orient the reader; the 21-item survey contains the binding criteria. Files, batch jobs, APIs and agents are design choices, not maturity levels.

DAIS LEVELSELECT A COLUMN
DDataGoverned facts
AAIBounded intelligence
IIntegrationContracts and effects
SAssuranceControl and recovery

READINESS LEVEL 0

R0 · Not established

Capability is absent, informal, or cannot be bounded to accountable ownership.

All four domains must reach this level for R to reach it. One lower domain keeps R at the lower level.

DDATA AT LEVEL 0

Unowned extracts

Data meaning, fitness, provenance, access, or recovery depends on local knowledge.

AAI AT LEVEL 0

Unbounded experiment

Intended outcome, behaviour, evaluation, lifecycle, or service ownership is unclear.

IINTEGRATION AT LEVEL 0

Undefined exchanges

People carry context and results; interface, meaning, action, and effect contracts are absent.

SASSURANCE AT LEVEL 0

Informal control

Identity, approval, evidence, intervention, and recovery depend on individuals.

READINESS LEVEL 1

R1 · Defined

The minimum practice, owner, and basic record exist for the bounded use case.

All four domains must reach this level for R to reach it. One lower domain keeps R at the lower level.

DDATA AT LEVEL 1

Defined data source

Required data and a business contact are identified; basic fitness and recovery are described.

AAI AT LEVEL 1

Defined AI use case

Outcome, intended behaviour, basic evaluation, versions, and human role are recorded.

IINTEGRATION AT LEVEL 1

Defined exchanges

Exchange, context, timing, permitted outputs and result checks have defined owners and basic records.

SASSURANCE AT LEVEL 1

Defined controls

Named roles, approval, logging, stop, and incident paths exist for the use case.

READINESS LEVEL 2

R2 · Governed

Approved responsibilities, criteria, controls, and repeatable records are in use.

All four domains must reach this level for R to reach it. One lower domain keeps R at the lower level.

DDATA AT LEVEL 2

Governed data product

Ownership, meaning, fitness, lineage, access, change, service levels, and recovery are contracted.

AAI AT LEVEL 2

Governed AI capability

Outcome, evaluation, versions, deployment control, workflow roles, cost, and support are governed.

IINTEGRATION AT LEVEL 2

Governed contracts

Governed interfaces version meaning, quality, compatibility, timing, errors, and change.

SASSURANCE AT LEVEL 2

Governed assurance

Identity, privacy, human control, release, evidence, and recovery controls are approved and testable.

READINESS LEVEL 3

R3 · Operational

The governed practice operates under representative or live conditions and is observed.

All four domains must reach this level for R to reach it. One lower domain keeps R at the lower level.

DDATA AT LEVEL 3

AI-consumable product

Quality, access, lineage, monitoring, and recovery operate against service expectations.

AAI AT LEVEL 3

Operational AI workflow

Evaluated behaviour, controlled releases, workflow adoption, monitoring, and service ownership operate live.

IINTEGRATION AT LEVEL 3

Operating contracts

Identity-aware interfaces enforce contracts for context, permissions, actions, errors, and effects.

SASSURANCE AT LEVEL 3

Operational assurance

Teams trace decisions and effects, exercise intervention and recovery, and manage incidents.

READINESS LEVEL 4

R4 · Adaptive

Observed outcomes and failures drive controlled improvement across the bounded system.

All four domains must reach this level for R to reach it. One lower domain keeps R at the lower level.

DDATA AT LEVEL 4

Feedback-enabled products

Observed demand, quality, effects, and incidents improve products, policies, capacity, and recovery.

AAI AT LEVEL 4

Adaptive AI capability

Outcome and failure evidence improves evaluation, behaviour, workflow, controls, and lifecycle decisions.

IINTEGRATION AT LEVEL 4

Improved contracts

Interfaces verify effects, reconcile ambiguity, recover safely, and improve contracts from evidence.

SASSURANCE AT LEVEL 4

Continuous assurance

Evidence improves authority, protection, release, observability, recovery, and retirement decisions.

REFERENCE DEFINITIONS

Every term has one job.

The framework separates capability, evidence, target, gap, and authority without creating another maturity number.

RREADINESS RESULT

DAIS bottleneck level

The minimum of D, A, I, and S for one bounded use case.

0–4SHARED LEVEL SCALE

Not established → Adaptive

The common cumulative scale used for every DAIS item and domain.

BasisEVIDENCE BASIS

Support for a claim

Public notes are optional respondent declarations, from Not noted to Independently checked. They neither verify nor change a self-reported level.

TargetREQUIRED CONDITION

Minimum level for the next decision

A target is defined from the use case, risk, obligations, and intended transition—not by automatically adding one to R.

GapMISSING CAPABILITY

Current condition below target

The result identifies the missing item, owner, evidence, and action without averaging it away.

GateHUMAN AUTHORITY

Proceed · Refine · Hold · Stop

R informs the decision. It never replaces risk, legal, architecture, or release authority.

INTERPRETATION RULES

A single number remains bounded by evidence and authority.

01Unknown is not zero

If a required item cannot be defensibly assessed, its domain and R are Not determined until the missing information is resolved.

02No compensation

A stronger Data or AI level cannot cancel a lower Integration or Assurance level. The minimum preserves the limiting condition.

03R is not authorization

Public readiness describes claimed capability; controlled attainment requires evidence for the bounded use case. Named enterprise authorities still decide whether to proceed.

NEXT VIEW

See how the DAIS capabilities are realized through enterprise architecture.

Open architecture →

The framework in six publication figures

DAIS v3.7 design baseline · Experimental. These publication illustrations explain the proposed method and its boundaries; they are not empirical validation results.

Governed data products, mandatory context and ontology, AI tasks and workflows connect within one use case. Assurance spans every boundary; trustworthiness review and named decision authority remain separate.
Framework anatomy

Governed data products, mandatory context and ontology, AI tasks and workflows connect within one use case. Assurance spans every boundary; trustworthiness review and named decision authority remain separate.

Public, facilitated and full evidence assessments share the 21-item v3.7 scale and minimum rule. Their evidence burden and claim authority differ. Self-report never becomes verification by changing its label.
One measurement, three evidence depths

Public, facilitated and full evidence assessments share the 21-item v3.7 scale and minimum rule. Their evidence burden and claim authority differ. Self-report never becomes verification by changing its label.

The synthetic D3/A3/I1/S2 profile gives R1. The exchange-contract gap leads to an owner-led evidence check and a separately agreed action. Ordinal levels are not averaged or converted to percentages.
From a limiting item to an evidence question

The synthetic D3/A3/I1/S2 profile gives R1. The exchange-contract gap leads to an owner-led evidence check and a separately agreed action. Ordinal levels are not averaged or converted to percentages.

Prohibited conditions lead to Stop, unresolved authority or evidence to Hold, and remediable critical gaps to Refine before Proceed becomes eligible. The named authority makes the actual decision.
Decision precedence

Prohibited conditions lead to Stop, unresolved authority or evidence to Hold, and remediable critical gaps to Refine before Proceed becomes eligible. The named authority makes the actual decision.

Assess, Prove, Build, Activate, Operate and Expand require explicit stage decisions. Retire can begin from any stage. Evidence supports a transition; it does not authorize exposure automatically.
Seven-stage lifecycle

Assess, Prove, Build, Activate, Operate and Expand require explicit stage decisions. Retire can begin from any stage. Evidence supports a transition; it does not authorize exposure automatically.

Leadership can inspect use-case distributions, recurring blockers, evidence age, reusable capabilities and operating capacity. Each use case retains its own boundary, version and authority.
Portfolio visibility without a company score

Leadership can inspect use-case distributions, recurring blockers, evidence age, reusable capabilities and operating capacity. Each use case retains its own boundary, version and authority.

More DAIS tools and reading guidance
01 · The DAIS framework

Read AI readiness through four separate views.

Stronger conditions in one view never compensate for a necessary missing condition in another.

Evidence lenses

Four views. One operating picture.

Each view asks for observable current conditions without calculating a score on this page.

D

Data readiness

Examines whether trusted data can be understood, governed, accessed, and recovered.

Evidence themeOwnership, quality, lineage, access, context, recoveryAssess this view
A

AI capability

Examines whether an AI-enabled outcome can be evaluated, released, adopted, and operated.

Evidence themeOutcomes, evaluation, release control, adoption, operationsAssess this view
I

Integration readiness

Examines whether systems can exchange shared meaning through controlled interfaces and tools.

Evidence themeInterfaces, shared meaning, freshness, tools, correction loopsAssess this view
S

Assurance readiness

Examines whether identity, human authority, traceability, and response controls bound the work.

Evidence themeIdentity, privacy, human control, traceability, incident responseAssess this view
How a result is read

Necessary conditions stay visible.

Level 0 is a classified declaration about current practice. Not sure records uncertainty and leaves the view unclassified.

  1. 01

    Cumulative declarations

    A selected level declares that level and every earlier level in the same view.

  2. 02

    No averaging

    The lowest classified D/A/I/S view limits the overall classified level. Strength in another view does not compensate.

  3. 03

    Unknown stays unknown

    Any Not sure answer keeps that view and the overall result explicitly unclassified. It is never translated to zero.

The guided assessment

Record the current state, then carry it forward.

Data and AI current-condition and declared-impact signals remain unscored. They add context to the guided assessment without changing the D/A/I/S result.

  1. 01
    Set scope

    Name one bounded AI-enabled use case, its outcome, workflow, owner and permitted effects.

  2. 02
    Declare current practice

    Choose only the cumulative statements the available evidence can support.

  3. 03
    Review constraints and unknowns

    Keep missing conditions and uncertainty visible beside the profile.

  4. 04
    Export

    Carry the completed result forward as PDF and Markdown.

Method, sources, and boundariesInspect rubric identity, published references, counts, hashes, and the limits of a self-reported result.
Framework references

Published sources. Stated boundaries.

DAIS is experimental. Its broader method references established standards and public guidance. The public assessment is narrower: 21 self-reported DAIS anchors exposing 296 underlying clauses.

Browse the source rubric
Public method version pinned. External references scoped.Rubric 3.2 · rubric only · review status not reviewed
Voluntary framework

NIST AI RMF 1.0

The broader DAIS method references Govern, Map, Measure and Manage outcomes through its separate trustworthiness overlay.

That overlay is not part of the public score and its cross-reference is not yet reviewed. Alignment is not certification.
Normative standard

ISO/IEC 42001:2023

The broader DAIS roadmap references AI management responsibilities and continual improvement for governance and controlled artifacts.

The public assessment does not test conformity to ISO/IEC 42001 or support a certification decision.
Applicability specific

ISO 27001, SOC 2 and sector controls

The broader DAIS strategy and architecture point to security and control obligations where scope, contracts and jurisdiction make them applicable.

DAIS does not determine applicability and does not provide an audit opinion.
Vendor guidance

AWS CAF and Well-Architected / Generative AI Lens

The broader DAIS strategy and architecture draw on transformation, operating-planning and workload architecture review guidance.

This is not AWS endorsement, readiness evidence or production qualification.
21cumulative anchors

A level is reached only when its lower-level declarations hold.

296canonical clauses

The 21 anchors expose the underlying versioned DAIS clauses.

v3.2rubric identity

Completed snapshots preserve method versions and content hashes.

Not surestays unclassified

A Not sure answer is never treated as zero or a partial pass.

What a DAIS result is not

It is not certification, conformity, a compliance determination, an audit opinion, accreditation, independent verification, an industry benchmark, legal or regulatory advice, a security assessment, or permission to deploy. The method is experimental and has not completed a controlled v3.2 validation pilot. Its rubric import is marked not reviewed; source fidelity is not Method Owner approval.