Jul 23 / Aray Kaken

A Practical Map for AI Governance: Six Capabilities, Four Perspectives, Five Levels

When people ask me where to start with AI governance, they usually expect a long list of policies. What actually helped me was something simpler: a mental map. Three connected ideas that turn a vague sense of "we should govern AI" into questions you can actually answer. What is the AI doing, what should we be looking at, and how good are we at looking. Here is the map I keep coming back to, drawn from the ITIL AI Governance framework.

Start with behaviour, not technology - ITIL AI Capability Model 6C

The first mistake most teams make is governing AI as a category. "We use AI" tells you almost nothing about the risk involved. A tool that summarizes meeting notes and a tool that approves loan applications are both "AI," and treating them the same is how governance either strangles the harmless one or overlooks the dangerous one.
ITIL AI Capability Model 6C
Figure: The ITIL AI Capability Model (6C). PeopleCert

The ITIL AI Capability Model fixes this by describing what AI does through six behaviours.
  • Creation generates net new outputs, such as drafting a contract, writing a marketing email, or producing a meeting summary.
  • Curation improves the quality and organization of existing information, flagging duplicates, outdated articles, or content that no longer matches policy.
  • Clarification helps people understand existing content by summarizing, rephrasing, restructuring, or translating it.
  • Cognition finds patterns, anomalies, and hidden insights, which is what powers forecasting and fraud detection.
  • Communication acts as the interface between people and systems, like a chatbot or a voice assistant.
  • Coordination takes action across systems within defined boundaries, routing claims, assigning work, or scheduling maintenance.

The value of the model is that each behaviour carries its own risk profile. Creation raises concerns about hallucination, intellectual property, and inappropriate content. Cognition raises concerns about explainability and model drift. Coordination, because it acts on its own within boundaries, raises concerns about autonomy and accountability.

And most real products combine several behaviours at once. An AI support assistant might use Creation to draft a reply, Curation to pull the right knowledge article, Clarification to summarize the problem, Cognition to predict the likely cause, Communication to talk to the customer, and Coordination to route the case. Governing only the visible feature misses most of the risk. You have to assess the combined profile.

Then look through four perspectives

Once you know what the AI is doing, the next question is what you should be examining. It is tempting to reduce this to one lens, usually either "is it compliant" or "does it work." The framework argues for four perspectives instead, used together, because narrow governance is how organizations get blindsided.

  • Decision Authority and Risk Management asks who has the authority to make or approve decisions involving AI, and how AI related risks are identified, escalated, and managed. This matters most when AI recommends actions or operates with some autonomy, because it defines where human oversight is required and who is accountable for the outcome.
  • Ethical Principles and Responsible AI asks whether AI is being used in ways that are fair, transparent, and aligned with human values. It connects principles like fairness, explainability, and human agency to real decisions, so that ethics is reflected in oversight and monitoring rather than living in a values statement nobody reads.
  • Data Governance and Performance Management focuses on the data AI depends on and how the system performs over time. AI outcomes are shaped by data quality, availability, lineage, and access rights, and by whether performance stays reliable and fair as conditions change.
  • Regulatory Compliance and Operational Standards covers external obligations and internal standards: legal, regulatory, contractual, security, privacy, and supplier requirements, and the evidence needed to demonstrate them.

These are not separate workstreams to hand off. They are interdependent lenses. A decision about AI authority can create an ethical concern. That ethical concern may hinge on data quality. A data issue can create regulatory exposure. Looking through all four at once is what keeps governance from being merely technical.

Then be honest about maturity

The last piece of the map is a mirror. Knowing what to do is not the same as being good at doing it, and the ITIL AI Governance Maturity Model gives you an honest way to place yourself. It borrows five levels from the broader ITIL Maturity Model.

At Level 1, Initial, leaders evaluate and direct on an ad hoc basis and governance is mostly reactive.
At Level 2,
Managed, directives are defined, communicated, and repeated, with resources and accountability in place.
At Level 3,
Defined, governance ensures that measures supporting objectives are implemented and analyzed, and capabilities align with those objectives.
At Level 4,
Quantitative, decisions become data driven, outcomes are systematically measured, and deviations are addressed.
At Level 5,
Optimizing, governance is continually reviewed and evolves to support the organization's vision and stakeholder needs.

The point of the ladder is not to sprint to Level 5. Most organizations do not need to, and forcing it creates bureaucracy that outweighs the benefit. The point is to know honestly where you stand, so you can improve deliberately rather than pretending you are more mature than you are.

Putting the map to work

Used together, these three ideas form a simple loop. Name what the AI is actually doing through the six capabilities. Examine it through the four perspectives so nothing important slips past a single lens. Then locate your governance on the five level ladder so you know what "better" looks like from here.

None of this requires a giant program to begin. It requires better questions. What is this AI really doing? What are we not looking at? And how good are we, honestly, at looking?

Answer those well and the policies tend to write themselves.

Where to learn more about it? 


 👉 Check out our ITIL AI Governance Version 5 Certification page below
Created with