Capability 04 of 04 · Delivery Management

Governance & Compliance

Controls around AI-generated code - licensing, security scanning, and audit trails.

5
maturity levels
15
practices
15
guides
L2 · Stage 02Delegated
Criteria - what to measure
  1. 01Official AI tool policy exists and is communicated to all developers
  2. 02The organization can list which developers use which AI tools
  3. 03The regulatory obligations that apply to this organisation's jurisdiction and sector are written down, with a named owner
  4. 04AI tool policy is reviewed at least annually
  5. 05Approved tool list is maintained and accessible
L3 · Stage 03Systematic
Criteria - what to measure
  1. 01Minimum viable audit trail is captured per AI-assisted change: model identifier, timestamp, context description, human approver
  2. 02Policy-as-code enforces compliance rules in CI (OPA or equivalent)
  3. 03Compliance gates run on every PR to in-scope repositories
  4. 04Audit trail fields are validated by CI (missing fields fail the build)
  5. 05Policy exceptions are logged and require follow-up within 48 hours
L4 · Stage 04GovernedMost teams aim here
Criteria - what to measure
  1. 01Full provenance tracking per change: model version, prompt context, agent session ID, iteration count
  2. 02Automated compliance checks run without manual intervention on every merge
  3. 03AI-generated code is distinguishable from human-written code in version control (metadata, labels, or attribution)
  4. 04Provenance data is queryable (e.g., "show all changes made by model X in the last 30 days")
  5. 05Compliance check results are aggregated into a governance dashboard
L5 · Stage 05Self-improving
Criteria - what to measure
  1. 01Continuous compliance: agent monitors regulatory changes (EU AI Act updates, SOC2 changes) and proposes policy updates
  2. 02Audit trail is self-documenting (agent decisions include reasoning, not just outcomes)
  3. 03Enterprise-grade RBAC is enforced per agent (each agent has scoped permissions for specific tools and repositories)
  4. 04Policy update proposals from compliance agent are auto-tested against existing codebase before rollout
  5. 05Agent RBAC permissions are audited automatically for least-privilege compliance

Which level is your team at in Governance & Compliance?

The criteria above are what we check in a facilitated assessment. Run it yourself to place this capability, see which gates you have passed, and compare it against the other 3 in Delivery Management.

Start the assessment →

Other capabilities in Delivery Management